SOC/Cybersecurity Analyst

Air InfoSec

$95K — $115K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Minimum of 5 years' experience in triaging security alerts.
  • 5 years' experience in analyzing security events.
  • 5 years' experience in documenting incident investigations.
  • Familiarity with cybersecurity frameworks and incident response processes.
  • Proven ability in threat detection methodologies and security monitoring.

Responsibilities

  • Monitor and analyze cybersecurity alerts from various platforms.
  • Conduct initial investigations on security events to assess severity and impact.
  • Identify and escalate confirmed cybersecurity incidents according to procedures.
  • Correlate data from multiple security tools for comprehensive threat analysis.
  • Document findings and investigations in ticketing systems.
  • Coordinate incident containment and recovery efforts with technical teams.
  • Support enhancement of threat detection capabilities through process improvements.

Benefits

  • Work in a critical role supporting state agency cybersecurity operations.
  • Contribute to continuous improvements in security incident responses.
  • Engage in a dynamic and collaborative 24x7 cybersecurity operations environment.
Full Job Description
Job Description
The SOC/Cybersecurity Analyst will support the Texas Health and Human Services Commission on the Cybersecurity Operations Center (CSOC). This role performs advanced cybersecurity analysis and threat triage within the CSOC, monitoring and investigating security alerts across enterprise platforms to protect agency information systems, networks, and data. The analyst serves as a primary point of contact for security event analysis, threat identification, and incident escalation. Work includes correlating data from multiple security tools, validating potential incidents, and coordinating response activities with technical teams. The analyst also documents investigations, supports continuous improvement of detection capabilities, and contributes to operational procedures and playbooks. This position requires the ability to work independently and as part of a 24x7 cybersecurity operations team.

Responsibilities:

  • Monitor, analyze, and triage cybersecurity alerts generated by SIEM, EDR, cloud security, email security, identity protection, and network security platforms.
  • Conduct initial investigations of detected and reported security events to determine severity, scope, and impact.
  • Identify, validate, and prioritize potential cybersecurity incidents, escalating confirmed threats according to established procedures.
  • Correlate security events from multiple data sources, including endpoints, firewalls, intrusion detection and prevention systems, cloud services, and threat intelligence feeds.
  • Review and analyze indicators of compromise, suspicious network activity, phishing emails, malware detections, and anomalous user behavior.
  • Document investigations, findings, and response actions in ticketing and case management systems.
  • Assist with incident containment, eradication, and recovery efforts by coordinating with technical teams and stakeholders.
  • Report and escalate findings to the CSOC Team Lead and/or SOC Manager.
  • Support continuous improvement of threat detection capabilities through alert tuning, process refinement, and threat intelligence integration.
  • Perform vulnerability assessment reviews and support development of operational procedures, playbooks, and knowledge base articles.

Requirements

Minimum Qualifications:

  • 5 years of experience triaging security alerts.
  • 5 years of experience analyzing security events.
  • 5 years of experience documenting incident investigations.
  • 5 years of experience with cybersecurity frameworks.
  • 5 years of experience with incident response processes.
  • 5 years of experience with threat detection methodologies.
  • 5 years of experience in cybersecurity operations.
  • 5 years of experience in security monitoring.
  • 5 years of experience in incident response.
  • 5 years of experience in threat detection.
  • 5 years of experience in security investigations.
  • 5 years of experience in related cybersecurity disciplines.

Preferred Qualifications:

  • Experience with one or more Texas state agencies.
  • Bachelor's degree in cybersecurity, information security, computer science, computer information systems, management information systems, or a related field (relevant education and experience may be substituted).
  • A security certification such as CompTIA Security+, GIAC Certified Incident Handler (GCIH), GIAC Certified Intrusion Analyst (GCIA), Certified SOC Analyst (CSA), Microsoft Cybersecurity Analyst (SC-200), or another GIAC or SOC-related certification.
  • Experience with enterprise SOC tools and technologies such as Microsoft Sentinel, Splunk, CrowdStrike, Tenable, Qualys, Zscaler, or Prisma.

Additional Requirements:

  • Candidates are subject to a pre-employment security review and criminal background check to determine employment eligibility.
  • Candidates must currently reside in Texas and be local to the Austin area. Candidates who reside out of state, including those planning to relocate, will not be accepted.
  • May be required to work outside normal business hours, including weekends, evenings, and holidays, during high-priority security incidents, as approved by the SOC Manager.

Work Location and Schedule:

  • Location: 701 W 51st Street, Austin, TX 78751.
  • Schedule: Monday through Friday, 8:00 a.m. to 5:00 p.m., excluding Texas state holidays. May require work outside normal business hours during high-priority incidents.
  • Work Arrangement: Onsite.

Similar Jobs

More Jobs at Air InfoSec

More Information Technology Jobs

Find similar SOC/Cybersecurity Analyst jobs: