Cayuse Holdings logo

Network Security Analyst 1

Cayuse Holdings

Austin, TXFull-time$67–92K/yrSeen todaySeen in employer's feed today

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
$67–92K/yr
Location
Austin, TX
Schedule
Full-time
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Requirements

Credentials this posting asks for.

Security clearance

Job overview

The Network Security Analyst I performs advanced cybersecurity analysis and threat triage within the Cybersecurity Operations Center, continuously monitoring, evaluating, and prioritizing alerts, investigating suspicious activity, and coordinating incident response to protect agency information systems and data.

Skills & qualifications

RequiredNice to have

Skills

SIEM PlatformsNetWitnessMicrosoft SentinelSplunkQRadarArcSightLogRhythmMicrosoft 365 Defender XDREDRCrowdStrikeSentinelOneIDS/IPSTrellix/FireEyeCorelightThreat Intelligence PlatformsVirusTotalGoogle Threat IntelligenceCisco TalosRecorded FutureMISPVulnerability ManagementTenableQualysRapid7Email SecurityIronPort ESAProofpointCloud Security MonitoringGoogle WizMDCACortex CloudSysdigSASEZscalerPrismaNetskopeKQLLuceneSPLESQL

Qualifications

Minimum Three Years ExperienceBachelor's Degree in Cybersecurity or EquivalentCompTIA Security+ or Equivalent CertificationGIAC Certified Incident Handler (GCIH)GIAC Certified Intrusion Analyst (GCIA)Certified SOC Analyst (CSA)Microsoft Cybersecurity Analyst (SC-200)

Benefits

Medical Insurance
Dental Insurance
Vision Insurance
401(k) Match
Paid Time Off

Full job description

Overview

JOB TITLE:

Network Security Analyst I

CAYUSE COMPANY:

Cayuse Civil Services, LLC

LOCATION

Austin, TX

SALARY:

$66,560.00-$91,520.00

EMPLOYEE TYPE:

Full-Time Salary Exempt

TRAVEL

No

RELOCATION

No

Employment in this role is conditional upon successful execution of the contract by the client.

The current period of performance is scheduled to end on August 31, 2027 ; however, the client retains the unilateral right to extend the contract beyond this date by exercising one or more option periods, subject to the terms, conditions, and funding provisions of the awarded contract

The Work

The Network Security Analyst I performs advanced cybersecurity analysis and threat triage activities within the Cybersecurity Operations Center (CSOC). This position involves continuous monitoring, evaluating, and prioritizing cybersecurity alerts, investigating suspicious activities, identifying potential threats, and coordinating incident response activities. This role protects [Agency Name]’s information systems, networks, and data by serving as the primary point of contact for security event analysis, threat identification, and incident escalation.

This position aligns with Cayuse’s core values of Innovation, Excellence, Collaboration, Adaptability, and Integrity by fostering technical solutions that meet customer needs, promoting teamwork, and prioritizing quality in deliverables.

Responsibilities

  • Cybersecurity Monitoring & Triage: Continuously monitor, analyze, and triage cybersecurity alerts from various platforms, including Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), cloud security tools, email security tools, identity protection systems, and network security platforms.

  • Security Event Investigation: Conduct initial investigations to assess the severity, scope, and impact of cybersecurity alerts to determine potential risks to agency operations.

  • Incident Escalation: Identify, validate, and prioritize security incidents based on established protocols. Escalate confirmed threats to appropriate teams such as Incident Response, Threat Hunting, and SOC Engineering.

  • Threat Correlation: Correlate security events from multiple sources, such as firewalls, intrusion detection/prevention systems (IDS/IPS), cloud services, authentication systems, and external threat intelligence feeds.

  • IOC/IOA Analysis: Review and analyze indicators of compromise (IOCs), suspicious network activities, malware, phishing emails, and anomalous user behaviors to identify potential security threats.

  • Documentation: Document all investigative actions, findings, incidents, and response activities using ticketing and case management systems to maintain accurate tracking and reporting.

  • Incident Containment and Coordination: Assist in incident containment, eradication, and recovery by consulting with technical teams and stakeholders to implement mitigations.

  • Operational Improvement: Continuously improve threat detection by performing alert tuning, refining incident response processes, and integrating threat intelligence.

  • Research & Development: Stay updated on cybersecurity technologies, new attack vectors, and evolving Tactics, Techniques, and Procedures (TTPs) to enhance cybersecurity operations.

  • Vulnerability Assessment: Conduct vulnerability assessments and evaluate remediation efforts in relation to identified risks.

  • Team Collaboration & Reporting: Collaborate with internal teams, communicate findings to CISO leadership, and report key activities to CSOC's leadership.

  • Policy Adherence: Ensure compliance with internal policies, state, and federal cybersecurity regulations.

  • Other duties as assigned.

Qualifications

Here’s What You Need

  • Minimum three (3) years of experience in the following areas:

  • Triaging security alerts.

  • Analyzing cybersecurity events.

  • Documenting findings and incident response actions.

  • Utilizing cybersecurity frameworks.

  • Managing incident response and threat detection activities.

  • Conducting security investigations in relevant cybersecurity disciplines.

  • Strong technical expertise with one or more of the following:

  • SIEM Platforms: NetWitness, Microsoft Sentinel, Splunk, QRadar, ArcSight, LogRhythm, etc.

  • Microsoft Security Tools: Microsoft 365 Defender XDR, Microsoft Sentinel.

  • Endpoint Detection and Response (EDR): Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, etc.

  • IDS/IPS technologies: Trellix/FireEye, Corelight.

  • Threat Intelligence Platforms: VirusTotal, Google Threat Intelligence, Cisco Talos, Recorded Future, MISP.

  • Vulnerability Management: Tenable, Qualys, Rapid7.

  • Email Security: IronPort ESA, Abnormal.ai, Proofpoint.

  • Cloud Security Monitoring: Google Wiz, MDCA, Cortex Cloud, Sysdig.

  • Secure Access Service Edge (SASE): Zscaler, Prisma, Netskope.

  • Knowledge of:

  • Cybersecurity Operations Center (CSOC/SOC) processes and best practices.

  • Incident response lifecycle and cybersecurity frameworks, such as NIST Cybersecurity Framework and NIST Incident Response Guidance (PICERL).

  • Security monitoring technologies and tools (e.g., SIEM, EDR/XDR, IDS/IPS, firewalls).

  • Common cyber threats, including phishing, malware, insider threats, and Advanced Persistent Threats (APTs).

  • Threat intelligence topics (e.g., Indicators of Compromise [IOCs], Mitre ATT&CK Matrix).

  • Operating systems (Windows/Linux), networking protocols, and enterprise security controls.

Minimum Skills:

  • Exceptional interpersonal skills with the ability to communicate in a clear, professional, and articulate manner.

  • Exceptional verbal and written communication skills.

  • Excellent organizational, analytical, and problem-solving skills with high-level attention to detail.

  • Ability to analyze systems and procedures

  • Strong multitasking skills with the ability to manage multiple design streams across concurrent work effort.

  • Must be self-motivated and able to work well independently as well as on a multi-functional team.

  • Ability to handle sensitive and confidential information appropriately.

  • Skilled in:

  • Analyzing and triaging cybersecurity incidents and threats.

  • Investigating suspicious activities (e.g., identified IOCs and IOAs, suspicious emails, network anomalies).

  • Query languages (e.g., KQL, Lucene, SPL, ESQL).

  • Scripting and automation using languages (e.g., PowerShell, Python, Bash).

  • Producing high-quality reports and investigation summaries for technical and non-technical stakeholders.

Preferred Qualifications:

  • Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Management Information Systems, or a related field (equivalent experience may substitute).

  • One or more relevant certifications, including but not limited to:

  • CompTIA Security+ GIAC Certified Incident Handler (GCIH)

  • GIAC Certified Intrusion Analyst (GCIA)

  • Certified SOC Analyst (CSA)

  • Microsoft Cybersecurity Analyst (SC-200)

  • Other GIAC or SOC-specific certifications.

  • Five (5) years of experience in the following areas is strongly preferred:

  • Advanced cybersecurity operations and monitoring.

  • Coordinating with SOC teams during threat detection and escalations.

  • Experience supporting systems that handle sensitive enterprise information.

Our Commitment to you / overview of benefits

  • Medical, Dental and Vision Insurance; Wellness Program

  • Flexible Spending Accounts (Healthcare, Dependent Care, Commuter)

  • Short-Term and Long-Term Disability options

  • Basic Life and AD&D Insurance (Company Provided)

  • Voluntary Life and AD&D options

  • 401(k) Retirement Savings Plan with matching after one year

  • Paid Time Off

Reports to: Program Manager

Working Conditions

  • Professional office environment, with the ability to work onsite in the main office.

  • Must reside in the Austin area.

  • Must be physically and mentally able to perform duties extended periods of time.

  • Ability to use a computer and other office productivity tools with sufficient speed to meet the demands of this position.

  • Must be able to establish a productive and professional workspace.

  • Must be able to sit for long periods of time looking at computer screen.

  • May be asked to work a flexible schedule which may include holidays.

  • May be asked to travel for business or professional development purposes.

  • May be asked to work hours outside of normal business hours.

  • Travel costs, per diem, and other related expenses must be pre-approved in compliance with State of Texas travel guidelines.

Other Duties: Please note this job description is not designed to cover or contain a comprehensive list of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.

Cayuse is an Equal Opportunity Employer. All employment decisions are based on merit, qualifications, skills, and abilities. All qualified applicants will receive consideration for employment in accordance with any applicable federal, state, or local law.

Pay Range

USD $66,560.00 - USD $91,520.00 /Yr.

Submit a Referral (https://careers-cayuseholdings.icims.com/jobs/4450/network-security-analyst-1/job?mode=apply&apply=yes&in\_iframe=1&hashed=-1834356743)

Can't find the right opportunity?

Join ourTalent Community (https://join.cayuseholdings.com/join/talentcommunity/form) orLanguage Services Talent Community (https://join.cayuseholdings.com/ls/talentcommunity/form) and be among the first to discover exciting new possibilities!

Software Powered by ICIMS (https://icims.help/candidate-faq)

Location US-TX-Austin

ID 105093

Category Information Technology

Position Type Full-Time Salary Exempt

Remote No

Clearance Required None

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.