Network Security Analyst 1, Cybersecurity Operations

the OpportunityAustin, TX
Onsite

About The Position

Our client is seeking a Network Security Analyst 1 to support enterprise cybersecurity monitoring, threat detection, security investigations, and incident response activities. This is a hands-on security operations role responsible for monitoring and triaging cybersecurity alerts, investigating suspicious activity, identifying potential threats, and coordinating appropriate escalation and response activities. The ideal candidate will have strong experience within a Security Operations Center, SOC, environment and hands-on exposure to technologies including SIEM, EDR/XDR, IDS/IPS, threat intelligence, vulnerability management, cloud security, and endpoint security platforms.

Requirements

  • Strong professional experience in: Cybersecurity operations
  • Security monitoring
  • Incident response
  • Threat detection
  • Security investigations
  • Security alert triage
  • Security event analysis
  • Incident investigation documentation
  • Cybersecurity frameworks
  • Threat detection methodologies
  • 5 years of cybersecurity operations or related experience
  • 3 years of experience across core security disciplines
  • Strong knowledge of: Security Operations Center, SOC, environments
  • Security incident triage and investigation
  • Incident escalation procedures
  • Security event correlation
  • Threat intelligence
  • Indicators of Compromise, IOCs
  • Indicators of Attack, IOAs
  • Malware analysis concepts
  • Phishing investigations
  • Insider threats
  • Advanced Persistent Threats, APTs
  • MITRE ATT&CK
  • Incident response lifecycle
  • NIST Cybersecurity Framework
  • NIST incident response guidance
  • PICERL
  • Experience with one or more technologies within the following categories is desired: SIEM Microsoft Sentinel Splunk QRadar ArcSight LogRhythm NetWitness
  • Endpoint Security & EDR/XDR Microsoft Defender XDR Microsoft Defender for Endpoint CrowdStrike SentinelOne
  • Network Security & IDS/IPS Firewalls IDS/IPS technologies Corelight Trellix/FireEye
  • Threat Intelligence VirusTotal Google Threat Intelligence Cisco Talos Recorded Future MISP
  • Vulnerability Management Tenable Qualys Rapid7
  • Email Security Proofpoint Abnormal Security Secure email gateway technologies
  • Cloud & Enterprise Security Wiz Microsoft Defender for Cloud Apps Cortex Cloud Sysdig Zscaler Prisma Netskope
  • Knowledge or experience with security query languages such as: KQL SPL Lucene ESQL
  • Knowledge or experience with scripting languages such as: PowerShell Python Bash
  • Familiarity with: Windows and Linux environments
  • TCP/IP and networking protocols
  • Active Directory
  • Microsoft Entra ID
  • Cloud environments
  • Enterprise security controls
  • Endpoint security
  • Network traffic analysis
  • Authentication and identity security
  • Vulnerability management
  • Case management and incident tracking systems
  • Strong analytical and investigative skills.
  • Ability to distinguish legitimate cybersecurity threats from false positives.
  • Ability to make risk-based decisions during security investigations.
  • Strong documentation and technical writing skills.
  • Ability to prioritize multiple security investigations in a fast-paced enterprise environment.
  • Strong written and verbal communication skills.
  • Ability to communicate cybersecurity issues to both technical and non-technical audiences.
  • Ability to follow established incident response and escalation procedures.
  • Strong teamwork and collaboration skills.
  • Ability to work independently while contributing effectively within a cybersecurity operations team.

Nice To Haves

  • 5+ years of directly relevant experience are preferred.
  • Bachelor's degree in: Cybersecurity Information Security Computer Science Computer Information Systems Management Information Systems A related technical discipline
  • CompTIA Security+
  • GIAC Certified Incident Handler, GCIH
  • GIAC Certified Intrusion Analyst, GCIA
  • Certified SOC Analyst, CSA
  • Microsoft Security Operations Analyst, SC-200
  • Other GIAC or SOC-related cybersecurity certifications
  • Hands-on SOC or cybersecurity operations experience
  • Solid background in security alert triage, SIEM, EDR/XDR, threat detection, incident response, security investigations, and event correlation.
  • Experience with Microsoft Sentinel, Microsoft Defender, KQL, threat intelligence platforms, vulnerability management tools, and security scripting will be particularly valuable.

Responsibilities

  • Monitor, analyze, and triage cybersecurity alerts generated by SIEM, EDR/XDR, cloud security, email security, identity protection, and network security platforms.
  • Conduct initial investigations of security events to determine severity, scope, potential impact, and risk.
  • Identify, validate, and prioritize potential cybersecurity incidents.
  • Escalate confirmed threats to appropriate incident response, threat hunting, or security engineering teams.
  • Correlate security events across multiple data sources, including endpoints, firewalls, IDS/IPS, cloud services, authentication systems, and threat intelligence feeds.
  • Review and analyze Indicators of Compromise, IOCs, suspicious network activity, phishing attempts, malware detections, and anomalous user behavior.
  • Investigate potential security breaches and suspicious activity.
  • Document investigations, findings, response actions, and escalation activities in ticketing and case management systems.
  • Assist with incident containment, eradication, and recovery activities.
  • Support vulnerability assessment reviews and evaluate identified vulnerabilities for risk and remediation priority.
  • Assist with improving threat detection capabilities through alert tuning, process refinement, threat intelligence integration, and identification of false-positive trends.
  • Support the development and maintenance of security procedures, playbooks, workflows, and knowledge-base documentation.
  • Research emerging cybersecurity threats, attack techniques, tactics, and procedures.
  • Maintain accurate operational documentation, investigation notes, metrics, and incident summaries.
  • Participate in incident response, escalation, and post-incident review activities.
  • Collaborate with security engineers, incident responders, system administrators, technical teams, and business stakeholders.

Benefits

  • Medical, dental, and vision coverage
  • Life and disability insurance
  • Additional voluntary benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service