Security Operations Analysts
Austin, TX - USA
Job Summary
Our Austin Texas client is integrating applications from two different divisions into Google SecOps (SIEM/SOAR) and we are seeking Security Operations Analysts for W2 positions working on-site monitoring investigating and responding to security events across their network endpoint identity and cloud environments.
Key Responsibilities
* Monitor alerts logs network events endpoint telemetry and threat intelligence feeds
* Triage and investigate suspicious activity; determine scope and impact and lead escalation and containment coordination
* Build and tune detection rules dashboards alerts playbooks and automation workflows
* Conduct threat hunting using KQL SPL packet/session analysis and endpoint telemetry
* Support vulnerability risk and control assessments
* Write incident reports track corrective actions and brief security leadership and business stakeholders
* Work with network infrastructure cloud and application teams to validate events and reduce risk
* Provide evidence and metrics for compliance and audit requests
* Be available occasionally outside business hours for high-priority incidents or planned maintenance
Requirements
* 7 years in cybersecurity network security security operations or incident response
* Hands-on Microsoft Sentinel experience (incident management analytics rules workbooks automation data connectors KQL)
* SIEM experience: log analysis alert investigation correlation searches dashboarding
* Experience with NDR (network traffic and packet/session analysis) and EDR (alert triage device investigation advanced hunting response actions)
* Solid understanding of firewalls IDS/IPS proxy logs DNS VPN TCP/IP and network segmentation
* Familiarity with NIST CIS Controls HIPAA and state information security requirements
* Strong analytical written and verbal communication skills with the ability to explain risk to technical and non-technical audiences
* Google SecOps or Wiz experience
Preferred
* Bachelors degree in cybersecurity computer science IT or a related field (relevant experience may substitute)
* Google SecOps or Wiz certification
* Microsoft certifications (e.g. SC-200 AZ-500 SC-100)
* Other certifications: Security CySA GIAC CISSP CISM CISA Splunk Core Certified Power User or ES Admin SentinelOne
* Splunk (SPL) experience
* Experience mentoring junior analysts
* Healthcare or public-sector background
Required Experience:
IC
About Company
Are you looking to hire? At eStaff LLC, we take all of the stress out of the search, with our experienced job recruiters able to staff all types of technical positions with highly skilled professionals. 24 hour on call.