Network Security Analyst 1770

Sistema Technologies
  • Austin, Texas
    5 days ago

    Job Description

    Sistema Technologies is a Texas-based IT staffing and IT delivery firm that has proudly served Texas state and local government agencies since 2002. As one of the top 10 Texas DIR ITSAC vendors, we specialize in providing highly qualified IT professionals and comprehensive, full-lifecycle technology delivery services. We offer competitive compensation and benefits, while making our consultants our highest priority by supporting their professional growth, career success, and overall well-being. 


    Sistema is looking for a Network Security Analyst with our government client based in Austin, TX for a 1-year position.  

    Job Description
    The Network Security Analyst II performs advanced cybersecurity and network security analysis work in support of HHSC’s enterprise security operations. This role is responsible for monitoring, detecting, investigating, and responding to security events across on-premises, cloud, and endpoint environments. The ideal candidate is a hands-on security operations professional with strong experience across SIEM, SOAR, EDR, network detection, and incident response platforms. This role requires sound judgment, technical depth, attention to detail, and a strong commitment to protecting HHSC systems, data, and services that support the health and well-being of Texans.
    Essential Job Functions
    • Monitor security alerts, logs, network events, endpoint telemetry, and threat intelligence feeds.
    • Analyze suspicious activity, anomalous network behavior, malware indicators, endpoint detections, and SIEM correlation events to determine scope, impact, and required response actions.
    • Perform incident triage, investigation, escalation, containment coordination, and documentation in alignment with HHSC security operations procedures.
    • Develop, tune, and maintain detection rules, dashboards, alerts, playbooks, and queries to improve visibility across network, endpoint, identity, and cloud environments.
    • Support threat hunting activities using KQL, SPL, packet/session analysis, endpoint telemetry, and other investigative techniques.
    • Assist with vulnerability, risk, and control assessments for network security infrastructure and enterprise information systems.
    • Document findings, prepare incident reports, track corrective actions, and communicate technical information to security leadership and business stakeholders.
    • Collaborate with network, infrastructure, cloud, endpoint, and application teams to validate security events and implement risk mitigation measures.
    • Maintain awareness of emerging cyber threats, attack techniques, indicators of compromise, and security best practices relevant to healthcare and public-sector environments.
    • Support compliance, audit, and reporting activities by providing evidence, metrics, and security operations documentation as requested.

    Required Qualifications
    • Minimum of seven years of experience in cybersecurity, network security, security operations, incident response, or a closely related information security role.
    • Hands-on experience with Microsoft Sentinel, including incident management, analytics rules, workbooks, automation, data connectors, and Kusto Query Language.
    • Experience using SIEM for log analysis, alert investigation, dashboarding, correlation searches, and security monitoring.
    • Experience with NDR for network traffic analysis, packet/session investigation, threat detection, and incident support.
    • Experience with EDR tools, including endpoint alert triage, device investigation, advanced hunting, and response actions.
    • Working knowledge of network security concepts, including firewalls, IDS/IPS, proxy logs, DNS, VPN, TCP/IP, segmentation, and secure network architecture.
    • Ability to analyze complex security events, correlate data across multiple sources, and produce clear written documentation and recommendations.
    • Knowledge of security frameworks, standards, and regulatory considerations such as NIST, CIS Controls, HIPAA, and state information security requirements.
    • Strong communication, collaboration, problem-solving, and analytical skills.

    Preferred Education and Certifications
    • Bachelor’s degree in cybersecurity, computer science, information systems, information technology, or a related field. Relevant experience may be considered in place of education where applicable.
    • Microsoft security certifications are strongly preferred, such as Microsoft Certified: Security Operations Analyst Associate, Microsoft Certified: Cybersecurity Architect Expert, Microsoft Certified: Azure Security Engineer Associate, or Microsoft 365 Defender-related certifications.
    • Additional preferred certifications include CompTIA Security+, CySA+, GIAC security certifications, CISSP, CISM, CISA, Splunk Core Certified Power User, Splunk Enterprise Security Certified Admin, or SentinelOne product certifications.

    Knowledge, Skills, and Abilities
    • Knowledge of SIEM, SOAR, EDR, XDR, network detection and response, log management, and threat intelligence concepts.
    • Skill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting.
    • Skill in identifying indicators of compromise, attacker tactics, suspicious network patterns, and endpoint-based threats.
    • Ability to prioritize alerts, document investigative steps, and escalate incidents based on severity and business impact.
    • Ability to work independently and collaboratively in a security operations environment with shifting priorities and time-sensitive incidents.
    • Ability to communicate cybersecurity risks, findings, and recommended actions to both technical and non-technical audiences.

    Work Expectations
    • Participate in incident response, escalation, and after-action review activities as needed.
    • Support enterprise security monitoring for systems that process, store, or transmit sensitive information.
    • Follow HHSC policies, procedures, standards, and applicable state and federal security requirements.
    • Maintain accurate operational documentation, investigation notes, metrics, and leadership-ready summaries.
    • May be required to provide support outside normal business hours during high-priority security incidents or planned maintenance activities.

    The position is expected to work onsite at HHSC in Austin, TX full-time, Monday - Friday during agency business hours.

     
    Minimum Requirements: Candidates that do not meet or exceed the minimum stated requirements (skills/experience) will be displayed to customers but may not be chosen for this opportunity.
    Actual
    Years
    Experience
    Years
    Experience
    Needed
    Required/
    Preferred
    Skills/Experience
     7Knowledge of SIEM, SOAR, EDR, XDR, NDR
     7Experience with security log collection and management
     7Experience with threat intelligence concepts
     7Skill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting
     7Experience in SIEM platform/architecture support
     7Experience in detection engineering methodology and implementation
     10PreferredKnowledge of SIEM, SOAR, EDR, XDR, NDR
     10PreferredExperience with security log collection and management
     10PreferredExperience with threat intelligence concepts
     10PreferredSkill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting
     10PreferredExperience in SIEM platform/architecture support
     10PreferredExperience in detection engineering methodology and implementation

     

    Numbers & Facts

    LocationAustin, Texas

    Skills

    • Analysis Skillsunmatched
    • Automationunmatched
    • Best Practicesunmatched
    • CISA - Certified Information Systems Auditorunmatched
    • CISM - Certified Information Security Managerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Cloud Computingunmatched
    • Communication Skillsunmatched
    • CompTIA - Computing Technology Industry Associationunmatched
    • CompTIA Security+unmatched
    • Compensation and Benefitsunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Corrective Actionunmatched
    • DNS (Domain Name System)unmatched
    • Database Programming Languagesunmatched
    • Detail Orientedunmatched
    • Documentationunmatched
    • Enterprise Protectionunmatched
    • Establish Prioritiesunmatched
    • Event Correlationunmatched
    • Firewallsunmatched
    • GIAC - Global Information Assurance Certificationunmatched
    • Governmentunmatched
    • HIPAA (Health Insurance Portability and Accountability Act)unmatched
    • Huntingunmatched
    • Incident Managementunmatched
    • Incident Responseunmatched
    • Information Technology & Information Systemsunmatched
    • Information/Data Security (InfoSec)unmatched
    • Internet Securityunmatched
    • Intrusion Detection Systemsunmatched
    • Intrusion Prevention Systemsunmatched
    • Investigative Reportsunmatched
    • Leadershipunmatched
    • Local Governmentunmatched
    • Malwareunmatched
    • Metricsunmatched
    • Microsoft Certificationsunmatched
    • Microsoft Product Familyunmatched
    • Microsoft Windows Azureunmatched
    • Network Architecture/Engineeringunmatched
    • Network Performance/Analysisunmatched
    • Network Securityunmatched
    • Network Traffic Analysisunmatched
    • Operational Auditunmatched
    • Operations Processesunmatched
    • Patient Assessmentunmatched
    • Problem Solving Skillsunmatched
    • Public Healthunmatched
    • Regulationsunmatched
    • Reporting Dashboardsunmatched
    • Reporting Skillsunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Security Analysisunmatched
    • Security Attacksunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Security Infrastructureunmatched
    • Security Monitoringunmatched
    • Splunkunmatched
    • State Governmentunmatched
    • TCP/IP (Transmission Control Protocol/Internet Protocol)unmatched
    • Technical Deliveryunmatched
    • Technical Recruitingunmatched
    • Telemetryunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • VPN (Virtual Private Network)unmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder