Network Security Analyst 2

NexivaAustin, TX
$70Onsite

About The Position

Texas Health and Human Services Commission (HHSC) is seeking an experienced Network Security Analyst 2 to support enterprise cybersecurity and network security operations. The successful candidate will be responsible for monitoring, detecting, investigating, and responding to security events across network, endpoint, cloud, and enterprise environments. The role requires hands-on experience with SIEM, SOAR, EDR, XDR, NDR, threat detection, incident response, and security analytics. The candidate should be capable of independently analyzing complex security events, identifying threats and vulnerabilities, supporting incident response, and developing or tuning security detections and monitoring capabilities.

Requirements

  • Minimum 7 years of experience in cybersecurity, network security, security operations, incident response, or a closely related information security field.
  • Strong knowledge of SIEM, SOAR, EDR, XDR, and NDR technologies.
  • Hands-on experience with Microsoft Sentinel, including: Incident management, Analytics rules, Workbooks, Automation, Data connectors, Kusto Query Language (KQL).
  • Experience with SIEM platforms for: Log analysis, Alert investigation, Dashboarding, Correlation searches, Security monitoring.
  • Experience with NDR technologies for network traffic analysis, packet/session investigation, threat detection, and incident response.
  • Experience with EDR platforms, including endpoint alert triage, device investigation, advanced hunting, and response actions.
  • Strong understanding of: Firewalls, IDS/IPS, Proxy logs, DNS, VPN, TCP/IP, Network segmentation, Secure network architecture.
  • Ability to correlate security data from multiple sources and determine scope, impact, and appropriate response.
  • Knowledge of security frameworks and regulatory requirements, including NIST, CIS Controls, HIPAA, and Texas state information security requirements.
  • Strong analytical, problem-solving, communication, and documentation skills.
  • Approximately 7 years of experience with: SIEM / SOAR / EDR / XDR / NDR, Security log collection and management, Threat intelligence concepts, KQL, SPL, and security queries, SIEM platform and architecture support, Detection engineering methodologies and implementation.

Nice To Haves

  • Approximately 10 years of experience in the above areas.
  • Bachelor's degree in: Cybersecurity, Computer Science, Information Systems, Information Technology, Or a related field.
  • Microsoft security certifications are strongly preferred, including: Microsoft Certified: Security Operations Analyst Associate, Microsoft Certified: Cybersecurity Architect Expert, Microsoft Certified: Azure Security Engineer Associate, Microsoft 365 Defender-related certifications.
  • Additional desirable certifications include: CompTIA Security+, CompTIA CySA+, GIAC certifications, CISSP, CISM, CISA, Splunk Core Certified Power User, Splunk Enterprise Security Certified Admin, SentinelOne certifications.
  • The ideal candidate is a hands-on cybersecurity professional who can: Investigate complex security incidents independently. Work extensively with Microsoft Sentinel and KQL. Perform SIEM-based security monitoring and detection engineering. Analyze network and endpoint threats using NDR and EDR technologies. Conduct threat hunting and identify indicators of compromise. Correlate network, endpoint, cloud, identity, and security-log data. Communicate technical findings clearly to both technical and non-technical stakeholders. Work effectively in a fast-paced security operations environment.

Responsibilities

  • Monitor security alerts, network events, endpoint telemetry, security logs, and threat intelligence feeds.
  • Investigate suspicious activity, anomalous network behavior, malware indicators, endpoint detections, and SIEM correlation events.
  • Perform incident triage, investigation, escalation, containment coordination, and incident documentation.
  • Develop, tune, and maintain security detection rules, dashboards, alerts, queries, and automated playbooks.
  • Support threat-hunting activities using KQL, SPL, packet/session analysis, endpoint telemetry, and other investigative techniques.
  • Analyze network traffic and security events to identify potential threats and indicators of compromise.
  • Support vulnerability, risk, and security control assessments.
  • Document investigation findings, incident reports, corrective actions, and security recommendations.
  • Collaborate with network, infrastructure, cloud, endpoint, and application teams to investigate and mitigate security risks.
  • Monitor emerging cyber threats, attacker techniques, indicators of compromise, and security best practices.
  • Support security audits, compliance activities, reporting, and evidence collection.
  • Participate in incident response, escalation, and after-action reviews when required.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service