Network Security Analyst I

NexivaAustin, TX
Onsite

About The Position

HHSC is seeking a Network Security Analyst I to support its Cybersecurity Operations Center (CSOC). The consultant will monitor and investigate cybersecurity alerts, identify potential threats, document security incidents, and coordinate escalation and response activities. This position supports the protection of agency systems, networks, applications, and sensitive data.

Requirements

  • At least three years of experience in cybersecurity operations
  • At least three years of experience in security monitoring
  • At least three years of experience in security-alert triage
  • At least three years of experience in security-event analysis
  • At least three years of experience in incident response
  • At least three years of experience in threat detection
  • At least three years of experience in security investigations
  • At least three years of experience in documentation of incident investigations
  • At least three years of experience in cybersecurity frameworks
  • At least three years of experience in incident-response processes
  • At least three years of experience in threat-detection methodologies
  • Experience with SIEM: Microsoft Sentinel, Splunk, NetWitness, QRadar, ArcSight, or LogRhythm
  • Experience with Microsoft Security: Microsoft 365 Defender XDR and Microsoft Sentinel
  • Experience with EDR/XDR: Microsoft Defender for Endpoint, CrowdStrike, or SentinelOne
  • Experience with IDS/IPS: Trellix/FireEye or Corelight
  • Experience with Threat Intelligence: VirusTotal, Google Threat Intelligence, Cisco Talos, Recorded Future, or MISP
  • Experience with Vulnerability Management: Tenable, Qualys, or Rapid7
  • Experience with Email Security: Cisco IronPort ESA, Abnormal AI, or Proofpoint
  • Experience with Cloud Security: Wiz, Microsoft Defender for Cloud Apps, Cortex Cloud, or Sysdig
  • Experience with SASE: Zscaler, Prisma Access, or Netskope
  • Knowledge of Security Operations Center practices and operating procedures
  • Knowledge of Security-event analysis, investigation, triage, and escalation
  • Knowledge of SIEM, EDR/XDR, IDS/IPS, firewall, endpoint, cloud, and network-security technologies
  • Knowledge of Malware, phishing, insider threats, common attack vectors, and advanced persistent threats
  • Knowledge of Indicators of compromise and indicators of attack
  • Knowledge of MITRE ATT&CK framework
  • Knowledge of Windows and Linux operating systems
  • Knowledge of Active Directory and Microsoft Entra ID
  • Knowledge of Networking protocols and enterprise security controls
  • Knowledge of Cloud environments and cloud-security monitoring
  • Knowledge of NIST Cybersecurity Framework
  • Knowledge of NIST incident-response guidance
  • Knowledge of PICERL incident-response lifecycle
  • Candidates must already reside in Texas.
  • Candidates planning to relocate from another state should not be submitted.

Nice To Haves

  • Five or more years of relevant cybersecurity experience
  • Experience with query languages such as KQL, SPL, Lucene, or ES|QL
  • Experience with PowerShell, Python, Bash, or similar scripting languages
  • Ability to correlate and interpret information from multiple security platforms
  • Ability to distinguish legitimate security threats from false positives
  • Strong technical documentation and incident-reporting skills
  • Ability to manage multiple investigations in a fast-paced enterprise environment
  • Ability to communicate technical findings to technical and nontechnical stakeholders
  • A bachelor's degree in cybersecurity, information security, computer science, information systems, management information systems, or a related discipline is preferred.
  • Relevant professional experience may substitute for formal education.
  • CompTIA Security+ certification is preferred.
  • GIAC Certified Incident Handler (GCIH) certification is preferred.
  • GIAC Certified Intrusion Analyst (GCIA) certification is preferred.
  • Certified SOC Analyst (CSA) certification is preferred.
  • Microsoft Certified: Security Operations Analyst Associate (SC-200) certification is preferred.
  • Other relevant GIAC or SOC certifications are preferred.

Responsibilities

  • Monitor, analyze, and prioritize alerts from SIEM, EDR/XDR, cloud security, email security, identity protection, and network security platforms.
  • Investigate security events to determine their severity, scope, operational impact, and potential risk.
  • Identify and validate cybersecurity incidents and escalate confirmed threats to the appropriate incident response, threat-hunting, or SOC engineering teams.
  • Correlate events from endpoints, firewalls, IDS/IPS platforms, cloud environments, authentication systems, and threat-intelligence feeds.
  • Analyze indicators of compromise, malware detections, phishing emails, suspicious network traffic, and anomalous user behavior.
  • Document investigations, findings, and response activities in ticketing and case-management systems.
  • Assist technical teams with incident containment, eradication, recovery, and after-action reviews.
  • Report significant events and findings to the CSOC Team Lead and SOC Manager.
  • Improve threat-detection capabilities through alert tuning, process improvements, threat-intelligence integration, and false-positive analysis.
  • Review vulnerability-assessment findings and help prioritize remediation based on risk.
  • Develop and maintain incident-response procedures, playbooks, workflows, and knowledge-base articles.
  • Research emerging threats, attack techniques, and threat-actor tactics, techniques, and procedures.
  • Maintain accurate investigation notes, operational metrics, and leadership-ready reports.

Benefits

  • Travel, parking, living, and relocation expenses are the responsibility of the consultant or vendor.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service