← Back to jobs

Technocraft Solutions Logo
Network Security Analyst

Technocraft Solutions

 

Austin, TX, USA

Posted On: 13 days ago
Experience: 10+ years
Availability: Hybrid
Openings: 1
Category: Network Security Analyst
Tenure: Contract - Corp-to-Corp
Related Jobs

No related jobs found

Description

Key Responsibilities

  • Monitor security alerts, server and network logs, endpoint telemetry, threat-intelligence feeds, and security events.
  • Investigate suspicious activity, malware indicators, anomalous network behavior, endpoint detections, and SIEM correlation events.
  • Determine the scope, impact, severity, and appropriate response to cybersecurity incidents.
  • Perform incident triage, investigation, escalation, containment coordination, and documentation.
  • Develop, tune, and maintain SIEM detection rules, alerts, dashboards, workbooks, queries, automation, and response playbooks.
  • Support threat-hunting activities using KQL, SPL, packet and session analysis, endpoint telemetry, and other investigative techniques.
  • Analyze network traffic using NDR tools to identify threats and support incident investigations.
  • Perform endpoint alert triage, device investigations, advanced hunting, and response actions using EDR tools.
  • Support vulnerability, risk, and control assessments for network infrastructure and enterprise information systems.
  • Identify indicators of compromise, suspicious network patterns, attacker tactics, and endpoint-based threats.
  • Prepare incident reports, document findings, track corrective actions, and communicate recommendations.
  • Collaborate with network, infrastructure, cloud, endpoint, identity, and application teams to validate events and mitigate risks.
  • Support compliance, audit, and security-reporting activities by providing evidence, metrics, and operational documentation.
  • Maintain awareness of emerging threats, attack techniques, and cybersecurity best practices relevant to healthcare and public-sector environments.
  • Participate in incident-response escalation and after-action review activities.

Required Qualifications

  • At least seven years of experience in cybersecurity, network security, security operations, incident response, or a closely related information-security role.
  • Seven years of experience with SIEM, SOAR, EDR, XDR, and NDR technologies.
  • Seven years of experience with security-log collection, management, analysis, and monitoring.
  • Seven years of experience applying threat-intelligence concepts.
  • Seven years of experience writing and interpreting KQL, SPL, or similar security queries.
  • Seven years of experience supporting SIEM platforms and architecture.
  • Seven years of experience with detection-engineering methodologies and implementation.
  • Hands-on Microsoft Sentinel experience, including:
    • Incident management
    • Analytics rules
    • Workbooks and dashboards
    • Automation
    • Data connectors
    • Kusto Query Language
  • Experience using SIEM platforms for log analysis, alert investigation, correlation searches, security monitoring, and reporting.
  • Experience with NDR tools for network-traffic analysis, packet or session investigation, threat detection, and incident support.
  • Experience with EDR tools for endpoint-alert triage, advanced hunting, device investigation, and response.
  • Strong knowledge of firewalls, IDS/IPS, proxy logs, DNS, VPN, TCP/IP, network segmentation, and secure network architecture.
  • Ability to correlate complex security data across multiple sources and produce clear findings and recommendations.
  • Familiarity with NIST, CIS Controls, HIPAA, and applicable state information-security requirements.
  • Strong analytical, problem-solving, communication, and collaboration skills.

Preferred Qualifications

  • Ten or more years of experience with:
    • SIEM, SOAR, EDR, XDR, and NDR
    • Security-log collection and management
    • Threat intelligence
    • KQL, SPL, and security-query development
    • SIEM platform and architecture support
    • Detection-engineering methodology and implementation
  • Bachelor’s degree in cybersecurity, computer science, information systems, information technology, or a related discipline. Relevant experience may be considered in place of education.
  • Previous cybersecurity experience in healthcare, government, or another regulated environment.

Preferred Certifications

Microsoft security certifications are strongly preferred, including:

  • Microsoft Certified: Security Operations Analyst Associate
  • Microsoft Certified: Cybersecurity Architect Expert
  • Microsoft Certified: Azure Security Engineer Associate
  • Microsoft 365 Defender-related certifications

Additional preferred certifications include:

  • CISSP
  • CISM
  • CISA
  • CompTIA Security+
  • CompTIA CySA+
  • GIAC security certifications
  • Splunk Core Certified Power User
  • Splunk Enterprise Security Certified Admin
  • SentinelOne product certifications

Skills Matrix

ExperienceRequirementSkill
7 yearsRequiredSIEM, SOAR, EDR, XDR, and NDR
7 yearsRequiredSecurity-log collection and management
7 yearsRequiredThreat-intelligence concepts
7 yearsRequiredWriting and interpreting KQL, SPL, and security queries
7 yearsRequiredSIEM platform and architecture support
7 yearsRequiredDetection-engineering methodology and implementation
10 yearsPreferredSIEM, SOAR, EDR, XDR, and NDR
10 yearsPreferredSecurity-log collection and management
10 yearsPreferredThreat-intelligence concepts
10 yearsPreferredWriting and interpreting KQL, SPL, and security queries
10 yearsPreferredSIEM platform and architecture support
10 yearsPreferredDetection-engineering methodology and implementation

Education

Bachelor's degree

Related Jobs

No related jobs found

← Back to jobs