Job Description:The Network Security Analyst I performs advanced cybersecurity analysis and threat triage activities within the Cybersecurity Operations Center (CSOC). Work involves continuously monitoring, triaging, analyzing, and prioritizing cybersecurity alerts; investigating suspicious activity; identifying potential threats; and coordinating incident response activities to protect agency information systems, networks, and data. Serves as a primary point of contact for security event analysis, threat identification, and incident escalation.
Required Qualifications:- Minimum of five (5) years of experience in cybersecurity operations, security monitoring, incident response, threat detection, security investigations, or related cybersecurity disciplines.
- Experience working with one or more of the following technologies:
- SIEM platforms (NetWitness, Microsoft Sentinel, Splunk, QRadar, ArcSight, LogRhythm, etc.)
- Microsoft Security (Microsoft 365 Defender XDR, Microsoft Sentinel)
- Endpoint Detection and Response (Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, etc.)
- IDS/IPS technologies (Trellix/FireEye, Corelight)
- Threat intelligence platforms (VirusTotal, Google Threat Intelligence, Cisco Talos, Recorded Future, MISP)
- Vulnerability management tools (Tenable, Qualys, Rapid7)
- Email security platforms (IronPort ESA, Abnormal.ai, Proofpoint)
- Cloud security monitoring solutions (Google Wiz, MDCA, Cortex Cloud, Sysdig)
- Secure Access Service Edge (Zscaler, Prisma, Netskope)
- Experience triaging security alerts, analyzing security events, and documenting incident investigations.
- Experience with cybersecurity frameworks, incident response processes, and threat detection methodologies.
Required Skills:Experience triaging security alerts
Experience analyzing security events
Experience documenting incident investigations
Experience with cybersecurity frameworks
Experience with incident response processes
Experience with threat detection methodologies
Experience in cybersecurity operations
Experience in security monitoring
Experience in incident response
Experience in threat detection
Experience in security investigations