Network Security Analyst

AgreeYa

$95K — $115K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in cybersecurity operations or related fields
  • Proficient in triaging and analyzing security alerts
  • Experienced in documenting incident investigations
  • Knowledgeable about cybersecurity frameworks
  • Familiar with incident response processes and methodologies
  • Experienced in security monitoring and threat detection
  • Relevant degrees or certifications preferred (e.g., Security+, GCIH, GCIA)

Responsibilities

  • Monitor and analyze cybersecurity alerts from various platforms
  • Conduct initial investigations into reported security events
  • Identify and validate potential cybersecurity incidents
  • Correlate security events from multiple data sources
  • Document findings and response actions meticulously
  • Assist in incident containment and recovery efforts
  • Research emerging cyber threats and attack techniques

Benefits

  • Opportunity to work in a fast-paced Cybersecurity Operations Center
  • Engagement with cutting-edge security technologies
  • Support for continuous professional development
  • Collaboration with cross-functional technical teams
  • Direct impact on improving agency information security
Full Job Description
Job Title: Network Security Analyst
Locations: Austin TX - Onsite

Description:
AgreeYa is a global Systems Integrator and is seeking an experienced Network Security Analyst to perform advanced cybersecurity analysis and threat triage activities. Strong SIEM & EDR experience is required

Job Summary:
The Network Security Analyst performs advanced cybersecurity analysis and threat triage activities within the Cybersecurity Operations Center (CSOC). Work involves continuously monitoring, triaging, analysing, and prioritizing cybersecurity alerts; investigating suspicious activity; identifying potential threats; and coordinating incident response activities to protect agency information systems, networks, and data. Serves as a primary point of contact for security event analysis, threat identification, and incident escalation.

Requirements:
  • Experience triaging security alerts - Required
  • Experience analyzing security events - Required
  • Experience documenting incident investigations - Required
  • Experience with cybersecurity frameworks - Required
  • Experience with incident response processes - Required
  • Experience with threat detection methodologies - Required
  • Experience in cybersecurity operations - Required
  • Experience in security monitoring - Required
  • Experience in incident response - Required
  • Experience in threat detection - Required
  • Experience in security investigations - Required
  • Experience in related cybersecurity disciplines - Required
Essential Job Functions
  • Monitors, analyzes, and triages cybersecurity alerts generated by Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), cloud security, email security, identity protection, and network security platforms.
  • Conducts initial investigations of detected and reported security events to determine severity, scope, impact, and potential risk to agency operations.
  • Identifies, validates, and prioritizes potential cybersecurity incidents, escalating confirmed threats to Incident Response, Threat Hunting, or SOC Engineering teams according to established procedures.
  • Correlates security events from multiple data sources, including endpoints (EDR), firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), cloud services, authentication systems, and threat intelligence feeds.
  • Reviews and analyzes indicators of compromise (IOCs), suspicious network activity, phishing emails, malware detections, and anomalous user behavior.
  • Documents investigations, findings, and response actions in ticketing and case management systems to ensure accurate tracking and reporting.
  • Assists with incident containment, eradication, and recovery efforts by coordinating with technical teams and stakeholders.
  • Reports and escalates to the CSOC Team Lead and/or SOC Manager.
  • Supports the continuous improvement of threat detection capabilities through alert tuning, process refinement, threat intelligence integration, and identification of false-positive trends.
  • Performs vulnerability assessment reviews and evaluates identified vulnerabilities for potential risk and remediation prioritization.
  • Supports development and maintenance of operational procedures, playbooks, workflows, and knowledge base articles related to threat detection and incident response.
  • Researches emerging cyber threats, attack techniques, tactics, and procedures (TTPs) to improve detection and response effectiveness.

Education and Certifications
  • Graduation from an accredited four-year college or university with major coursework in cybersecurity, information security, computer science, computer information systems, management information systems, or a related field is preferred. Relevant education and experience may be substituted for one another.
  • One or more of the following certifications are preferred:
    • CompTIA Security+
    • GIAC Certified Incident Handler (GCIH)
    • GIAC Certified Intrusion Analyst (GCIA)
    • Certified SOC Analyst (CSA)
    • Microsoft Cybersecurity Analyst (SC-200)
    • Other GIAC or SOC-related certifications

Required Qualifications
  • Minimum of five (5) years of experience in cybersecurity operations, security monitoring, incident response, threat detection, security investigations, or related cybersecurity disciplines.
Experience working with one or more of the following technologies:
  • SIEM platforms (NetWitness, Microsoft Sentinel, Splunk, QRadar, ArcSight, LogRhythm, etc.)
  • Microsoft Security (Microsoft 365 Defender XDR, Microsoft Sentinel)
  • Endpoint Detection and Response (Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, etc.)
  • IDS/IPS technologies (Trellix/FireEye, Corelight)
  • Threat intelligence platforms (VirusTotal, Google Threat Intelligence, Cisco Talos, Recorded Future, MISP)
  • Vulnerability management tools (Tenable, Qualys, Rapid7)
  • Email security platforms (IronPort ESA, Abnormal.ai, Proofpoint)
  • Cloud security monitoring solutions (Google Wiz, MDCA, Cortex Cloud, Sysdig)
  • Secure Access Service Edge (Zscaler, Prisma, Netskope)
  • Experience triaging security alerts, analyzing security events, and documenting incident investigations.
  • Experience with cybersecurity frameworks, incident response processes, and threat detection methodologies.

Similar Jobs

More Jobs at AgreeYa

More Information Technology Jobs

Find similar Network Security Analyst jobs: