Network Security Analyst 1

Cayuse HoldingsCedar Park, TX
$66,560 - $91,520Onsite

About The Position

The Network Security Analyst I performs advanced cybersecurity analysis and threat triage activities within the Cybersecurity Operations Center (CSOC). This position involves continuous monitoring, evaluating, and prioritizing cybersecurity alerts, investigating suspicious activities, identifying potential threats, and coordinating incident response activities. This role protects [Agency Name]’s information systems, networks, and data by serving as the primary point of contact for security event analysis, threat identification, and incident escalation. This position aligns with Cayuse’s core values of Innovation, Excellence, Collaboration, Adaptability, and Integrity by fostering technical solutions that meet customer needs, promoting teamwork, and prioritizing quality in deliverables.

Requirements

  • Minimum three (3) years of experience in the following areas: Triaging security alerts.
  • Analyzing cybersecurity events.
  • Documenting findings and incident response actions.
  • Utilizing cybersecurity frameworks.
  • Managing incident response and threat detection activities.
  • Conducting security investigations in relevant cybersecurity disciplines.
  • Strong technical expertise with one or more of the following: SIEM Platforms: NetWitness, Microsoft Sentinel, Splunk, QRadar, ArcSight, LogRhythm, etc.
  • Microsoft Security Tools: Microsoft 365 Defender XDR, Microsoft Sentinel.
  • Endpoint Detection and Response (EDR): Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, etc.
  • IDS/IPS technologies: Trellix/FireEye, Corelight.
  • Threat Intelligence Platforms: VirusTotal, Google Threat Intelligence, Cisco Talos, Recorded Future, MISP.
  • Vulnerability Management: Tenable, Qualys, Rapid7.
  • Email Security: IronPort ESA, Abnormal.ai, Proofpoint.
  • Cloud Security Monitoring: Google Wiz, MDCA, Cortex Cloud, Sysdig.
  • Secure Access Service Edge (SASE): Zscaler, Prisma, Netskope.
  • Knowledge of: Cybersecurity Operations Center (CSOC/SOC) processes and best practices.
  • Incident response lifecycle and cybersecurity frameworks, such as NIST Cybersecurity Framework and NIST Incident Response Guidance (PICERL).
  • Security monitoring technologies and tools (e.g., SIEM, EDR/XDR, IDS/IPS, firewalls).
  • Common cyber threats, including phishing, malware, insider threats, and Advanced Persistent Threats (APTs).
  • Threat intelligence topics (e.g., Indicators of Compromise [IOCs], Mitre ATT&CK Matrix).
  • Operating systems (Windows/Linux), networking protocols, and enterprise security controls.
  • Exceptional interpersonal skills with the ability to communicate in a clear, professional, and articulate manner.
  • Exceptional verbal and written communication skills.
  • Excellent organizational, analytical, and problem-solving skills with high-level attention to detail.
  • Ability to analyze systems and procedures
  • Strong multitasking skills with the ability to manage multiple design streams across concurrent work effort.
  • Must be self-motivated and able to work well independently as well as on a multi-functional team.
  • Ability to handle sensitive and confidential information appropriately.
  • Skilled in: Analyzing and triaging cybersecurity incidents and threats.
  • Investigating suspicious activities (e.g., identified IOCs and IOAs, suspicious emails, network anomalies).
  • Query languages (e.g., KQL, Lucene, SPL, ESQL).
  • Scripting and automation using languages (e.g., PowerShell, Python, Bash).
  • Producing high-quality reports and investigation summaries for technical and non-technical stakeholders.

Nice To Haves

  • Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Management Information Systems, or a related field (equivalent experience may substitute).
  • One or more relevant certifications, including but not limited to: CompTIA Security+
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Intrusion Analyst (GCIA)
  • Certified SOC Analyst (CSA)
  • Microsoft Cybersecurity Analyst (SC-200)
  • Other GIAC or SOC-specific certifications.
  • Five (5) years of experience in the following areas is strongly preferred: Advanced cybersecurity operations and monitoring.
  • Coordinating with SOC teams during threat detection and escalations.
  • Experience supporting systems that handle sensitive enterprise information.

Responsibilities

  • Continuously monitor, analyze, and triage cybersecurity alerts from various platforms, including Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), cloud security tools, email security tools, identity protection systems, and network security platforms.
  • Conduct initial investigations to assess the severity, scope, and impact of cybersecurity alerts to determine potential risks to agency operations.
  • Identify, validate, and prioritize security incidents based on established protocols. Escalate confirmed threats to appropriate teams such as Incident Response, Threat Hunting, and SOC Engineering.
  • Correlate security events from multiple sources, such as firewalls, intrusion detection/prevention systems (IDS/IPS), cloud services, authentication systems, and external threat intelligence feeds.
  • Review and analyze indicators of compromise (IOCs), suspicious network activities, malware, phishing emails, and anomalous user behaviors to identify potential security threats.
  • Document all investigative actions, findings, incidents, and response activities using ticketing and case management systems to maintain accurate tracking and reporting.
  • Assist in incident containment, eradication, and recovery by consulting with technical teams and stakeholders to implement mitigations.
  • Continuously improve threat detection by performing alert tuning, refining incident response processes, and integrating threat intelligence.
  • Stay updated on cybersecurity technologies, new attack vectors, and evolving Tactics, Techniques, and Procedures (TTPs) to enhance cybersecurity operations.
  • Conduct vulnerability assessments and evaluate remediation efforts in relation to identified risks.
  • Collaborate with internal teams, communicate findings to CISO leadership, and report key activities to CSOC's leadership.
  • Ensure compliance with internal policies, state, and federal cybersecurity regulations.
  • Other duties as assigned.

Benefits

  • Medical, Dental and Vision Insurance
  • Wellness Program
  • Flexible Spending Accounts (Healthcare, Dependent Care, Commuter)
  • Short-Term and Long-Term Disability options
  • Basic Life and AD&D Insurance (Company Provided)
  • Voluntary Life and AD&D options
  • 401(k) Retirement Savings Plan with matching after one year
  • Paid Time Off
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service