Network Security Analyst II

Nexiva Inc

  • Austin, TX
  • 7 days ago

    Highlights

    The ideal candidate will have strong hands-on experience with Microsoft Sentinel, SIEM, SOAR, EDR, XDR, NDR, threat intelligence, detection engineering, incident response, and security-query languages such as KQL and SPL. Strong knowledge of firewalls, IDS/IPS, proxy logs, DNS, VPN, TCP/IP, network segmentation, and secure network architecture.

    Numbers & Facts

    LocationAustin, TX

    Description

    Title: Network Security Analyst II
    Location: Austin TX- Onsite
    Duration: 12 Months Contract
    Position Summary:
    An experienced Network Security Analyst II to support enterprise cybersecurity and security operations. The selected professional will monitor, detect, investigate, and respond to security events across network, endpoint, identity, cloud, and on-premises environments.
    The ideal candidate will have strong hands-on experience with Microsoft Sentinel, SIEM, SOAR, EDR, XDR, NDR, threat intelligence, detection engineering, incident response, and security-query languages such as KQL and SPL.
    Required Qualifications:
    At least seven years of experience in cybersecurity, network security, security operations, incident response, or a closely related information-security role.
    Seven years of experience with SIEM, SOAR, EDR, XDR, and NDR technologies.
    Seven years of experience with security-log collection, management, analysis, and monitoring.
    Seven years of experience applying threat-intelligence concepts.
    Seven years of experience writing and interpreting KQL, SPL, or similar security queries.
    Seven years of experience supporting SIEM platforms and architecture.
    Seven years of experience with detection-engineering methodologies and implementation.
    Key Responsibilities:
    Monitor security alerts, server and network logs, endpoint telemetry, threat-intelligence feeds, and security events.
    Investigate suspicious activity, malware indicators, anomalous network behavior, endpoint detections, and SIEM correlation events.
    Determine the scope, impact, severity, and appropriate response to cybersecurity incidents.
    Perform incident triage, investigation, escalation, containment coordination, and documentation.
    Develop, tune, and maintain SIEM detection rules, alerts, dashboards, workbooks, queries, automation, and response playbooks.
    Support threat-hunting activities using KQL, SPL, packet and session analysis, endpoint telemetry, and other investigative techniques.
    Analyze network traffic using NDR tools to identify threats and support incident investigations.
    Perform endpoint alert triage, device investigations, advanced hunting, and response actions using EDR tools.
    Support vulnerability, risk, and control assessments for network infrastructure and enterprise information systems.
    Identify indicators of compromise, suspicious network patterns, attacker tactics, and endpoint-based threats.
    Prepare incident reports, document findings, track corrective actions, and communicate recommendations.
    Collaborate with network, infrastructure, cloud, endpoint, identity, and application teams to validate events and mitigate risks.
    Support compliance, audit, and security-reporting activities by providing evidence, metrics, and operational documentation.
    Maintain awareness of emerging threats, attack techniques, and cybersecurity best practices relevant to healthcare and public-sector environments.
    Participate in incident-response escalation and after-action review activities.
    Hands-on Microsoft Sentinel experience, including:
    Incident management
    Analytics rules
    Workbooks and dashboards
    Automation
    Data connectors
    Kusto Query Language
    Experience using SIEM platforms for log analysis, alert investigation, correlation searches, security monitoring, and reporting.
    Experience with NDR tools for network-traffic analysis, packet or session investigation, threat detection, and incident support.
    Experience with EDR tools for endpoint-alert triage, advanced hunting, device investigation, and response.
    Strong knowledge of firewalls, IDS/IPS, proxy logs, DNS, VPN, TCP/IP, network segmentation, and secure network architecture.
    Ability to correlate complex security data across multiple sources and produce clear findings and recommendations.
    Familiarity with NIST, CIS Controls, HIPAA, and applicable state information-security requirements.
    Strong analytical, problem-solving, communication, and collaboration skills.
    Additional preferred certifications include:
    CISSP
    CISM
    CISA
    CompTIA Security+
    CompTIA CySA+
    GIAC security certifications
    Splunk Core Certified Power User
    Splunk Enterprise Security Certified Admin
    SentinelOne product certifications

    Similar Jobs

    See more jobs