We use essential cookies

Please Accept our Privacy Policy

Network Security Analyst

Siritech Solutions Corp

Job Description

Job Description
Network Security Analyst (SOC Operations, SIEM & Incident Response):Required Experience in Years:10+ Years

Mode of Work:100% Onsite Austin, TX Metropolitan Area Locals Only


The Network Security Analyst will perform advanced cybersecurity monitoring, threat analysis, security-event triage, and incident investigation within a Cybersecurity Operations Center (CSOC). The analyst will continuously monitor security alerts, investigate suspicious activities, identify potential threats, distinguish legitimate incidents from false positives, and coordinate incident-response activities.

The position requires strong SOC operations expertise across SIEM, EDR/XDR, network security, cloud security, identity protection, email security, vulnerability management, and threat-intelligence technologies.

Key Responsibilities:
  • Continuously monitor, triage, analyze, and prioritize cybersecurity alerts.

  • Investigate suspicious network, endpoint, cloud, email, and user activity.

  • Determine incident severity, scope, impact, and risk.

  • Validate potential security incidents and distinguish threats from false positives.

  • Escalate confirmed threats to Incident Response, Threat Hunting, or SOC Engineering teams.

  • Correlate security events across:

    • Endpoints

    • Firewalls

    • IDS/IPS

    • Cloud Services

    • Authentication Systems

    • Threat Intelligence Feeds

  • Analyze Indicators of Compromise (IOCs) and Indicators of Attack (IOAs).

  • Investigate phishing emails, malware detections, suspicious network traffic, and anomalous user behavior.

  • Document investigations, findings, and response activities in case-management systems.

  • Assist with containment, eradication, and recovery activities.

  • Escalate critical findings to SOC/CSOC leadership.

Additional Responsibilities:
  • Tune security alerts and improve threat-detection capabilities.

  • Identify and reduce false-positive trends.

  • Integrate threat intelligence into SOC monitoring and investigations.

  • Review vulnerability-assessment results and remediation priorities.

  • Maintain incident-response procedures, playbooks, workflows, and knowledge-base documentation.

  • Research emerging cyber threats, attack techniques, and TTPs.

  • Support 24x7 cybersecurity operations when required.

  • Participate in high-priority incident response outside normal business hours.

  • Communicate security findings to technical and non-technical stakeholders.

Required Skills:
  • Minimum 5+ years of overall experience in cybersecurity operations, security monitoring, incident response, threat detection, security investigations, or related cybersecurity disciplines.

  • Minimum 3+ years of security alert triage experience.

  • Minimum 3+ years analyzing cybersecurity events.

  • Minimum 3+ years documenting security incident investigations.

  • Minimum 3+ years working with cybersecurity frameworks.

  • Minimum 3+ years with incident-response processes.

  • Minimum 3+ years with threat-detection methodologies.

  • Minimum 3+ years in cybersecurity/SOC operations.

  • Minimum 3+ years of security-monitoring experience.

  • Minimum 3+ years of incident-response experience.

  • Minimum 3+ years of threat-detection experience.

  • Minimum 3+ years conducting security investigations.

  • Strong understanding of SIEM, EDR/XDR, IDS/IPS, firewalls, endpoint security, and cloud-security platforms.

  • Strong understanding of malware, phishing, insider threats, and APTs.

  • Knowledge of MITRE ATT&CK methodologies.

  • Knowledge of IOCs, IOAs, and threat intelligence.

  • Knowledge of the incident-response lifecycle, NIST Cybersecurity Framework, NIST Incident Response guidance, and PICERL.

  • Understanding of Windows, Linux, Active Directory, Microsoft Entra ID, and networking protocols.

  • Experience correlating data across multiple cybersecurity platforms.

  • Experience with query languages including KQL, SPL, Lucene, and ESQL.

  • Experience with scripting languages including PowerShell, Python, and Bash.

Preferred Skills:
  • SIEM platforms:

    • Microsoft Sentinel

    • Splunk

    • NetWitness

    • QRadar

    • ArcSight

    • LogRhythm

  • EDR/XDR:

    • Microsoft 365 Defender XDR

    • Microsoft Defender for Endpoint

    • CrowdStrike

    • SentinelOne

  • IDS/IPS:

    • Trellix / FireEye

    • Corelight

  • Threat Intelligence:

    • VirusTotal

    • Google Threat Intelligence

    • Cisco Talos

    • Recorded Future

    • MISP

  • Vulnerability Management:

    • Tenable

    • Qualys

    • Rapid7

  • Email Security:

    • IronPort ESA

    • Abnormal.ai

    • Proofpoint

  • Cloud Security:

    • Wiz

    • Microsoft Defender for Cloud Apps (MDCA)

    • Cortex Cloud

    • Sysdig

  • SASE:

    • Zscaler

    • Prisma

    • Netskope

  • Experience operating within a 24x7 SOC/CSOC environment.

Qualifications:
  • Must currently reside in the Austin metropolitan area.

  • Must be willing to work 100% onsite in Austin, TX.

  • Strong analytical and cybersecurity investigation capabilities.

  • Ability to distinguish genuine threats from false positives.

  • Strong risk-based decision-making skills.

  • Ability to follow incident-response and escalation procedures.

  • Ability to work independently and within a 24x7 cybersecurity team.

  • Strong written and verbal communication skills.

  • Ability to communicate with security engineers, incident responders, system administrators, leadership, and business stakeholders.

  • Must be available for occasional evening, weekend, and holiday support during critical security incidents.

Education:
  • Four-year degree in Cybersecurity, Information Security, Computer Science, Computer Information Systems, Management Information Systems, or related field Preferred.

  • Relevant education and professional experience may substitute where permitted.

Certifications:
  • CompTIA Security+ Preferred

  • GIAC Certified Incident Handler (GCIH) Preferred

  • GIAC Certified Intrusion Analyst (GCIA) Preferred

  • Certified SOC Analyst (CSA) Preferred

  • Microsoft Certified: Security Operations Analyst Associate (SC-200) Preferred

  • Other GIAC/SOC-related cybersecurity certifications Preferred