Cybersecurity Operations Center Analyst

TX-HHSC-DSHS-DFPSAustin, TX
$7,015 - $11,865Onsite

About The Position

This position is open to U.S. Citizens and permanent residents. This onsite role requires the selected candidate to work from an HHS office in Austin, Texas. The Cybersecurity Analyst III performs senior-level cybersecurity operations work with emphasis on threat detection, incident investigation, security monitoring, cyber defense, and operational response activities. The role supports agency on-premises and cloud environments by identifying, analyzing, investigating, and responding to cybersecurity threats impacting agency systems, applications, hosts, networks, cloud services, and data. The Cybersecurity Operations Center (CSOC) Analyst is responsible for monitoring enterprise security operations and coordinating the detection and response of cybersecurity incidents. This position provides senior-level expertise in threat analysis, incident triage, threat intelligence, security monitoring, and cyber defense operations. The analyst leverages advanced security technologies and investigative methodologies to identify malicious activity, assess risk, and coordinate containment and remediation activities. The CSOC Analyst develops and maintains awareness of the agency's cybersecurity threat landscape, evaluates emerging threats and attack techniques, and supports the implementation of strategies that strengthen the agency's security posture. This position serves as a critical operational resource in protecting agency systems and data while ensuring that cybersecurity monitoring, detection, and response activities align with agency security objectives, State of Texas requirements, and industry best practices. This position performs highly complex information security and cybersecurity analysis work. The Analyst works under limited supervision with considerable latitude for the use of initiative and independent judgment. The Analyst will research and implement new threat detection methodologies, monitoring capabilities, investigative techniques, and response strategies for the prevention, detection, containment, and remediation of cybersecurity incidents. The Analyst provides expert guidance regarding cybersecurity threats, incident response procedures, threat intelligence findings, and emerging risks. This role partners closely with security engineering, vulnerability management, system administration, cloud operations, and application support teams to strengthen organizational cyber resilience.

Requirements

  • Graduation from an accredited four-year college or university with major coursework in information technology security, computer information systems, computer science, management information systems, or a related field is strongly preferred. Education and experience may be substituted for one another on a year for year basis.
  • At least 5+ years of experience in information technology, cybersecurity, security operations, detection engineering, systems/network administration, or related disciplines.
  • Experience working in a Security Operations Center (SOC).
  • Knowledge of Security Operations Center methodologies, operations, and best practices.
  • Knowledge of Incident response concepts, procedures, and investigation techniques.
  • Knowledge of Enterprise cybersecurity technologies including SIEM, EDR/XDR, IDS/IPS, NDR, NGFW, SOAR, cloud security, email security, identity protection, and vulnerability management solutions.
  • Knowledge of Threat intelligence frameworks, MITRE ATT&CK, cyber threat actor behaviors, and attack methodologies.
  • Knowledge of Operating systems, networking protocols, Active Directory, Microsoft Entra ID, cloud computing platforms, and enterprise security architectures.
  • Knowledge of Security and risk management frameworks such as NIST Cybersecurity Framework, NIST 800-61, CIS Controls, and State of Texas cybersecurity requirements (including TAC Chapter 202).
  • Skill in written and verbal communication.
  • Skill in analyzing and solving complex cybersecurity problems.
  • Skill in conducting threat investigations and incident analysis.
  • Skill in correlating security data from diverse sources and technologies.
  • Skill in identifying risk and recommending appropriate response actions.
  • Skill in producing operational reports, technical documentation, and executive summaries.
  • Ability to analyze large volumes of security telemetry and rapidly identify threats.
  • Ability to make sound decisions during cybersecurity investigations and incident response activities.
  • Ability to communicate technical information to both technical and non-technical audiences.
  • Ability to work collaboratively with diverse teams and provide operational cybersecurity guidance.
  • Ability to manage multiple concurrent investigations and priorities in a fast-paced environment.

Nice To Haves

  • Certified Information Systems Security Professional (CISSP)
  • CompTIA CySA+
  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Intrusion Analyst (GCIA)
  • GIAC Continuous Monitoring Certification (GMON)
  • Certified SOC Analyst (CSA)

Responsibilities

  • Monitors security events and alerts generated through Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR/XDR), identity security, cloud security, email security, vulnerability management, and network security platforms.
  • Performs initial triage and analysis of cybersecurity alerts to determine severity, scope, impact, and potential organizational risk.
  • Reviews indicators of compromise (IOCs), indicators of attack (IOAs), anomalous user activity, threat intelligence information, phishing campaigns, malware activity, and suspicious network behavior.
  • Correlates events from multiple security technologies to identify attack patterns and potential cybersecurity incidents.
  • Evaluates detection effectiveness and recommends improvements to monitoring capabilities and alert fidelity.
  • Leads and conducts investigations of cybersecurity events and incidents.
  • Coordinates response activities with Incident Response, Security Engineering, Infrastructure Services, Cloud Operations, and other support teams.
  • Assists with incident containment, eradication, recovery, and post-incident review activities.
  • Documents investigations, findings, recommendations, lessons learned, and response actions.
  • Supports forensic investigations and evidence preservation activities as appropriate.
  • Researches emerging cyber threats, adversary tactics, techniques, and procedures (TTPs), and industry threat trends.
  • Performs threat hunting activities across enterprise systems and cloud environments to identify previously undetected threats.
  • Leverages commercial, industry, government, and open-source threat intelligence to enhance detection and response capabilities.
  • Develops recommendations for improving agency visibility into emerging threats.
  • Supports development and tuning of detection use cases, analytics, dashboards, workflows, reports, and operational procedures.
  • Collaborates with security engineering teams to improve monitoring coverage and telemetry collection.
  • Assists with tabletop exercises, incident simulations, adversary emulation, operational readiness activities, and continuous improvement initiatives.
  • Provides input into cybersecurity strategy and operational enhancements.
  • Performs additional cybersecurity operations activities as assigned, including special projects, process improvement initiatives, operational readiness efforts, reporting activities, audit support, and agency cybersecurity initiatives.

Benefits

  • 100% paid employee health insurance for full-time eligible employees
  • A defined benefit pension plan
  • Generous time off benefits
  • Numerous opportunities for career advancement
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service