Network Security Analyst II Location: Austin, TX
Work Arrangement: Onsite
Schedule: Monday Friday, 8:00 AM 5:00 PM
Contract Duration: October 12, 2026 August 31, 2027
Employment Type: Contract
Job Summary
We are seeking an experienced Network Security Analyst II to support enterprise cybersecurity and network security operations. The ideal candidate will have strong hands-on experience in security operations, SIEM, SOAR, EDR, NDR, threat detection, incident response, and security monitoring across on-premises, cloud, and endpoint environments.
This position requires strong analytical and investigative skills, sound technical judgment, attention to detail, and the ability to work independently in a fast-paced security operations environment.
Note: Candidates selected for this position may be subject to a pre-employment security/background review to determine employment eligibility.
Key Responsibilities
- Monitor security alerts, logs, network events, endpoint telemetry, and threat intelligence feeds.
- Analyze suspicious activity, anomalous network behavior, malware indicators, endpoint detections, and SIEM correlation events.
- Perform incident triage, investigation, escalation, containment coordination, and documentation.
- Develop, tune, and maintain detection rules, dashboards, alerts, playbooks, and security queries.
- Improve security visibility across network, endpoint, identity, and cloud environments.
- Conduct threat hunting using KQL, SPL, packet/session analysis, endpoint telemetry, and other investigative techniques.
- Support vulnerability, risk, and security control assessments.
- Investigate security incidents and document findings, impact, remediation, and recommended corrective actions.
- Collaborate with network, infrastructure, cloud, endpoint, and application teams to investigate and mitigate security risks.
- Monitor emerging cyber threats, attack techniques, indicators of compromise, and security best practices.
- Support compliance, audit, metrics, and security reporting activities.
- Participate in incident response, escalation, and after-action review activities as required.
- Maintain accurate investigation notes, operational documentation, metrics, and leadership-ready reports.
- Provide occasional support outside standard business hours for high-priority security incidents or planned maintenance.
Required Qualifications
- 7+ years of experience in cybersecurity, network security, security operations, incident response, or a closely related information security field.
- Strong knowledge of SIEM, SOAR, EDR, XDR, and NDR technologies.
- Hands-on experience with Microsoft Sentinel, including:
- Incident management
- Analytics rules
- Workbooks
- Automation
- Data connectors
- Kusto Query Language (KQL)
- Experience with SIEM platforms for:
- Log analysis
- Alert investigation
- Dashboarding
- Correlation searches
- Security monitoring
- Experience with NDR/network security monitoring tools for network traffic analysis, packet/session investigation, and threat detection.
- Experience with EDR platforms, including endpoint alert triage, device investigation, advanced hunting, and response actions.
- Strong understanding of:
- Firewalls
- IDS/IPS
- Proxy logs
- DNS
- VPN
- TCP/IP
- Network segmentation
- Secure network architecture
- Strong experience with security log collection and management.
- Knowledge of threat intelligence concepts and methodologies.
- Experience with detection engineering methodology and implementation.
- Ability to write and interpret KQL, SPL, and security queries.
- Ability to correlate security data from multiple sources and determine scope, impact, and appropriate response.
- Strong written and verbal communication skills.
- Ability to work independently while collaborating effectively with cross-functional technical teams.
Preferred Qualifications
- 10+ years of relevant cybersecurity/security operations experience.
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Technology, or a related field.
- Relevant professional experience may be considered in lieu of formal education where applicable.
- Experience supporting security environments within healthcare, government, or other highly regulated industries.
Preferred Certifications
Microsoft security certifications are strongly preferred, including:
- Microsoft Certified: Security Operations Analyst Associate
- Microsoft Certified: Cybersecurity Architect Expert
- Microsoft Certified: Azure Security Engineer Associate
- Microsoft 365 Defender-related certifications
Additional preferred certifications include:
- CompTIA Security+
- CompTIA CySA+
- CISSP
- CISM
- CISA
- GIAC certifications
- Splunk Core Certified Power User
- Splunk Enterprise Security Certified Admin
- SentinelOne certifications
Knowledge, Skills & Abilities
- Strong knowledge of SIEM, SOAR, EDR, XDR, NDR, log management, and threat intelligence.
- Strong KQL, SPL, and security query-writing skills.
- Ability to identify indicators of compromise, attacker tactics, suspicious network behavior, and endpoint threats.
- Strong incident investigation and root-cause analysis skills.
- Ability to prioritize security alerts based on severity, risk, and business impact.
- Ability to clearly document investigation steps, findings, and remediation recommendations.
- Strong understanding of cybersecurity frameworks and standards, including NIST and CIS Controls.
- Familiarity with regulatory and compliance requirements such as HIPAA and applicable state information security requirements.
- Strong problem-solving, analytical, communication, and collaboration skills.
- Ability to communicate cybersecurity risks and technical findings to both technical and non-technical stakeholders.
Work Environment & Expectations
- This is a full-time onsite position in Austin, TX.
- Standard working hours are Monday through Friday, 8:00 AM 5:00 PM, excluding applicable holidays.
- Occasional evening, weekend, or holiday support may be required for critical security incidents, escalations, or planned maintenance.
- Candidates must be comfortable working in an enterprise security operations environment with changing priorities and time-sensitive incidents.
- The position involves supporting security monitoring and protection of systems that process, store, or transmit sensitive information.
Ideal Candidate
The ideal candidate is a hands-on cybersecurity professional with strong experience in SIEM/SOAR/EDR/NDR, Microsoft Sentinel, KQL, SPL, detection engineering, threat hunting, network security, and incident response. The candidate should be able to independently investigate complex security events, correlate information across multiple security platforms, and communicate clear remediation recommendations.