Security Operations / Detection Engineering Analyst.
Assyst, Inc.
Austin
Assyst is seeking an experienced Network Security Analyst II to support the client’s enterprise security operations. The role is responsible for monitoring, detecting, investigating, and responding to security events across network, endpoint, cloud, and on-premises environments.
The ideal candidate will have strong hands-on experience with SIEM, SOAR, EDR/XDR, NDR, threat intelligence, detection engineering, and incident response, with the ability to independently analyze complex security events and recommend appropriate mitigation actions.
Roles & Responsibilities:
- Monitor and analyze security alerts, logs, network traffic, endpoint telemetry, and threat intelligence feeds.
- Perform incident triage, investigation, escalation, containment, and documentation.
- Investigate suspicious activity, malware indicators, anomalous network behavior, and security breaches.
- Develop and tune SIEM detection rules, alerts, dashboards, queries, and playbooks.
- Conduct threat hunting using KQL, SPL, packet/session analysis, and endpoint telemetry.
- Support vulnerability, risk, and security control assessments.
- Analyze and correlate security events across network, endpoint, identity, and cloud environments.
- Work with network, infrastructure, cloud, endpoint, and application teams to validate incidents and implement risk mitigation.
- Identify IOCs, attacker tactics, suspicious network patterns, and endpoint threats.
- Prepare incident reports, investigation documentation, metrics, and security recommendations.
- Support security compliance, audit, reporting, and after-action review activities.
- Stay current with emerging threats, attack techniques, and security best practices.
- Provide after-hours support for high-priority security incidents or planned maintenance when required.
Required Skills:
- 7+ years of experience in cybersecurity, network security, security operations, incident response, or related information security roles.
- 7+ years of experience with SIEM, SOAR, EDR, XDR, and NDR technologies.
- Strong experience with security log collection and management and SIEM platform/architecture support.
- Strong experience with threat intelligence and detection engineering methodologies.
- Hands-on experience with Microsoft Sentinel, including analytics rules, workbooks, automation, data connectors, incident management, and KQL.
- Strong ability to write and interpret KQL, SPL, and security queries for investigations and reporting.
- Experience with NDR/network traffic analysis, packet/session investigation, and threat detection.
- Experience with EDR alert triage, endpoint investigation, advanced hunting, and response actions.
- Strong knowledge of firewalls, IDS/IPS, DNS, VPN, TCP/IP, proxy logs, network segmentation, and secure network architecture.
- Knowledge of NIST, CIS Controls, HIPAA, and applicable information security requirements.
- Strong analytical, problem-solving, communication, documentation, and incident-prioritization skills.
- Ability to work independently in a fast-paced security operations environment.
- 10+ years of relevant experience is preferred.
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, IT, or a related field is preferred.
Preferred Certifications: Microsoft Security certifications, including Security Operations Analyst Associate, Cybersecurity Architect Expert, Azure Security Engineer Associate, or Microsoft 365 Defender certifications are preferred.
Additional preferred certifications include Security+, CySA+, GIAC, CISSP, CISM, CISA, Splunk certifications, and SentinelOne certifications.
ASSYST is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, disability, military status, national origin or any other characteristic protected under federal, state, or applicable local law.
Similar jobs
Software Engineer, Mobile Sdk
About UsAt Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks th...
Sr. Technical Program Manager - Security Compliance
About UsAt Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks th...
Vulnerability Defense Software Engineer, Cloudforce One
About UsAt Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks th...
Senior Electrical Engineer
Hexium is modernizing Atomic Vapor Laser Isotope Separation (AVLIS) into a scalable industrial technology for domestic isotope production...
Clinical Field Specialist
TERRITORY: Austin NorthThe CFS will drive revenue growth and market expansion through direct engagement with individual MFMs and OB/GYNs....
Sales Development Representative - Austin, Tx
Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale — unleashing ...