Our Austin, Texas client is integrating applications from two different divisions into Google SecOps (SIEM/SOAR) and we are seeking Security Operations Analysts for W2 positions working on-site monitoring, investigating, and responding to security events across their network, endpoint, identity, and cloud environments.
Key Responsibilities
• Monitor alerts, logs, network events, endpoint telemetry, and threat intelligence feeds
• Triage and investigate suspicious activity; determine scope and impact and lead escalation and containment coordination
• Build and tune detection rules, dashboards, alerts, playbooks, and automation workflows
• Conduct threat hunting using KQL, SPL, packet/session analysis, and endpoint telemetry
• Support vulnerability, risk, and control assessments
• Write incident reports, track corrective actions, and brief security leadership and business stakeholders
• Work with network, infrastructure, cloud, and application teams to validate events and reduce risk
• Provide evidence and metrics for compliance and audit requests
• Be available occasionally outside business hours for high-priority incidents or planned maintenance
Requirements
• 7 years in cybersecurity, network security, security operations, or incident response
• Hands-on Microsoft Sentinel experience (incident management, analytics rules, workbooks, automation, data connectors, KQL)
• SIEM experience: log analysis, alert investigation, correlation searches, dashboarding
• Experience with NDR (network traffic and packet/session analysis) and EDR (alert triage, device investigation, advanced hunting, response actions)
• Solid understanding of firewalls, IDS/IPS, proxy logs, DNS, VPN, TCP/IP, and network segmentation
• Familiarity with NIST, CIS Controls, HIPAA, and state information security requirements
• Strong analytical, written, and verbal communication skills, with the ability to explain risk to technical and non-technical audiences
• Google SecOps or Wiz experience
Preferred
• Bachelor's degree in cybersecurity, computer science, IT, or a related field (relevant experience may substitute)
• Google SecOps or Wiz certification
• Microsoft certifications (e.g., SC-200, AZ-500, SC-100)
• Other certifications: Security , CySA , GIAC, CISSP, CISM, CISA, Splunk Core Certified Power User or ES Admin, SentinelOne
• Splunk (SPL) experience
• Experience mentoring junior analysts
• Healthcare or public-sector background