Network Security Analyst
Listed on 2026-09-15
-
IT/Tech
Cybersecurity, Network Security, Security Management & Operations
The primary work location(s) will be at Austin, TX 78751. The working position is On Site.
Job SummaryThe Network Security Analyst II performs advanced cybersecurity and network security analysis work in support of HHSC’s enterprise security operations. This role is responsible for monitoring, detecting, investigating, and responding to security events across on-premises, cloud, and endpoint environments. The ideal candidate is a hands‑on security operations professional with strong experience across SIEM, SOAR, EDR, network detection, and incident response platforms.
This role requires sound judgment, technical depth, attention to detail, and a strong commitment to protecting HHSC systems, data, and services that support the health and well‑being of Texans.
- Monitor security alerts, logs, network events, endpoint telemetry, and threat intelligence feeds.
- Analyze suspicious activity, anomalous network behavior, malware indicators, endpoint detections, and SIEM correlation events to determine scope, impact, and required response actions.
- Perform incident triage, investigation, escalation, containment coordination, and documentation in alignment with HHSC security operations procedures.
- Develop, tune, and maintain detection rules, dashboards, alerts, playbooks, and queries to improve visibility across network, endpoint, identity, and cloud environments.
- Support threat hunting activities using KQL, SPL, packet/session analysis, endpoint telemetry, and other investigative techniques.
- Assist with vulnerability, risk, and control assessments for network security infrastructure and enterprise information systems.
- Document findings, prepare incident reports, track corrective actions, and communicate technical information to security leadership and business stakeholders.
- Collaborate with network, infrastructure, cloud, endpoint, and application teams to validate security events and implement risk mitigation measures.
- Maintain awareness of emerging cyber threats, attack techniques, indicators of compromise, and security best practices relevant to healthcare and public-sector environments.
- Support compliance, audit, and reporting activities by providing evidence, metrics, and security operations documentation as requested.
- Minimum of seven years of experience in cybersecurity, network security, security operations, incident response, or a closely related information security role.
- Hands‑on experience with Microsoft Sentinel, including incident management, analytics rules, workbooks, automation, data connectors, and Kusto Query Language.
- Experience using SIEM for log analysis, alert investigation, dashboarding, correlation searches, and security monitoring.
- Experience with NDR for network traffic analysis, packet/session investigation, threat detection, and incident support.
- Experience with EDR tools, including endpoint alert triage, device investigation, advanced hunting, and response actions.
- Working knowledge of network security concepts, including firewalls, IDS/IPS, proxy logs, DNS, VPN, TCP/IP, segmentation, and secure network architecture.
- Ability to analyze complex security events, correlate data across multiple sources, and produce clear written documentation and recommendations.
- Knowledge of security frameworks, standards, and regulatory considerations such as NIST, CIS Controls, HIPAA, and state information security requirements.
- Strong communication, collaboration, problem‑solving, and analytical skills.
- Bachelor’s degree in cybersecurity, computer science, information systems, information technology, or a related field. Relevant experience may be considered in place of education where applicable.
- Microsoft security…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).