Job Requirements
Austin, TX
Clearance Unspecified Polygraph Unspecified
Career Level not specified
$66,560 - $91,520
Job Description
Overview
JOB TITLE:
Network Security Analyst I
CAYUSE COMPANY:
Cayuse Civil Services, LLC
LOCATION
Austin, TX
SALARY:
$66,560.00-$91,520.00
EMPLOYEE TYPE:
Full-Time Salary Exempt
TRAVEL
No
RELOCATION
No
Employment in this role is conditional upon successful execution of the contract by the client.
The current period of performance is scheduled to end on August 31, 2027 ; however, the client retains the unilateral right to extend the contract beyond this date by exercising one or more option periods, subject to the terms, conditions, and funding provisions of the awarded contract
The Work
The Network Security Analyst I performs advanced cybersecurity analysis and threat triage activities within the Cybersecurity Operations Center (CSOC). This position involves continuous monitoring, evaluating, and prioritizing cybersecurity alerts, investigating suspicious activities, identifying potential threats, and coordinating incident response activities. This role protects [Agency Name]'s information systems, networks, and data by serving as the primary point of contact for security event analysis, threat identification, and incident escalation.
This position aligns with Cayuse's core values of Innovation, Excellence, Collaboration, Adaptability, and Integrity by fostering technical solutions that meet customer needs, promoting teamwork, and prioritizing quality in deliverables.
Responsibilities
Qualifications
Here's What You Need
Minimum Skills:
Preferred Qualifications:
Our Commitment to you / overview of benefits
Reports to: Program Manager
Working Conditions
Other Duties: Please note this job description is not designed to cover or contain a comprehensive list of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.
Cayuse is an Equal Opportunity Employer. All employment decisions are based on merit, qualifications, skills, and abilities. All qualified applicants will receive consideration for employment in accordance with any applicable federal, state, or local law.
Pay Range
USD $66,560.00 - USD $91,520.00 /Yr.
JOB TITLE:
Network Security Analyst I
CAYUSE COMPANY:
Cayuse Civil Services, LLC
LOCATION
Austin, TX
SALARY:
$66,560.00-$91,520.00
EMPLOYEE TYPE:
Full-Time Salary Exempt
TRAVEL
No
RELOCATION
No
Employment in this role is conditional upon successful execution of the contract by the client.
The current period of performance is scheduled to end on August 31, 2027 ; however, the client retains the unilateral right to extend the contract beyond this date by exercising one or more option periods, subject to the terms, conditions, and funding provisions of the awarded contract
The Work
The Network Security Analyst I performs advanced cybersecurity analysis and threat triage activities within the Cybersecurity Operations Center (CSOC). This position involves continuous monitoring, evaluating, and prioritizing cybersecurity alerts, investigating suspicious activities, identifying potential threats, and coordinating incident response activities. This role protects [Agency Name]'s information systems, networks, and data by serving as the primary point of contact for security event analysis, threat identification, and incident escalation.
This position aligns with Cayuse's core values of Innovation, Excellence, Collaboration, Adaptability, and Integrity by fostering technical solutions that meet customer needs, promoting teamwork, and prioritizing quality in deliverables.
Responsibilities
- Cybersecurity Monitoring & Triage: Continuously monitor, analyze, and triage cybersecurity alerts from various platforms, including Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), cloud security tools, email security tools, identity protection systems, and network security platforms.
- Security Event Investigation: Conduct initial investigations to assess the severity, scope, and impact of cybersecurity alerts to determine potential risks to agency operations.
- Incident Escalation: Identify, validate, and prioritize security incidents based on established protocols. Escalate confirmed threats to appropriate teams such as Incident Response, Threat Hunting, and SOC Engineering.
- Threat Correlation: Correlate security events from multiple sources, such as firewalls, intrusion detection/prevention systems (IDS/IPS), cloud services, authentication systems, and external threat intelligence feeds.
- IOC/IOA Analysis: Review and analyze indicators of compromise (IOCs), suspicious network activities, malware, phishing emails, and anomalous user behaviors to identify potential security threats.
- Documentation: Document all investigative actions, findings, incidents, and response activities using ticketing and case management systems to maintain accurate tracking and reporting.
- Incident Containment and Coordination: Assist in incident containment, eradication, and recovery by consulting with technical teams and stakeholders to implement mitigations.
- Operational Improvement: Continuously improve threat detection by performing alert tuning, refining incident response processes, and integrating threat intelligence.
- Research & Development: Stay updated on cybersecurity technologies, new attack vectors, and evolving Tactics, Techniques, and Procedures (TTPs) to enhance cybersecurity operations.
- Vulnerability Assessment: Conduct vulnerability assessments and evaluate remediation efforts in relation to identified risks.
- Team Collaboration & Reporting: Collaborate with internal teams, communicate findings to CISO leadership, and report key activities to CSOC's leadership.
- Policy Adherence: Ensure compliance with internal policies, state, and federal cybersecurity regulations.
- Other duties as assigned .
Qualifications
Here's What You Need
- Minimum three (3) years of experience in the following areas:
- Triaging security alerts.
- Analyzing cybersecurity events.
- Documenting findings and incident response actions.
- Utilizing cybersecurity frameworks.
- Managing incident response and threat detection activities.
- Conducting security investigations in relevant cybersecurity disciplines.
- Strong technical expertise with one or more of the following:
- SIEM Platforms: NetWitness, Microsoft Sentinel, Splunk, QRadar, ArcSight, LogRhythm, etc.
- Microsoft Security Tools: Microsoft 365 Defender XDR, Microsoft Sentinel.
- Endpoint Detection and Response (EDR): Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, etc.
- IDS/IPS technologies: Trellix/FireEye, Corelight.
- Threat Intelligence Platforms: VirusTotal, Google Threat Intelligence, Cisco Talos, Recorded Future, MISP.
- Vulnerability Management: Tenable, Qualys, Rapid7.
- Email Security: IronPort ESA, Abnormal.ai, Proofpoint.
- Cloud Security Monitoring: Google Wiz, MDCA, Cortex Cloud, Sysdig.
- Secure Access Service Edge (SASE): Zscaler, Prisma, Netskope.
- Knowledge of:
- Cybersecurity Operations Center (CSOC/SOC) processes and best practices.
- Incident response lifecycle and cybersecurity frameworks, such as NIST Cybersecurity Framework and NIST Incident Response Guidance (PICERL).
- Security monitoring technologies and tools (e.g., SIEM, EDR/XDR, IDS/IPS, firewalls).
- Common cyber threats, including phishing, malware, insider threats, and Advanced Persistent Threats (APTs).
- Threat intelligence topics (e.g., Indicators of Compromise [IOCs], Mitre ATT&CK Matrix).
- Operating systems (Windows/Linux), networking protocols, and enterprise security controls.
Minimum Skills:
- Exceptional interpersonal skills with the ability to communicate in a clear, professional, and articulate manner.
- Exceptional verbal and written communication skills.
- Excellent organizational, analytical, and problem-solving skills with high-level attention to detail.
- Ability to analyze systems and procedures
- Strong multitasking skills with the ability to manage multiple design streams across concurrent work effort.
- Must be self-motivated and able to work well independently as well as on a multi-functional team.
- Ability to handle sensitive and confidential information appropriately.
- Skilled in:
- Analyzing and triaging cybersecurity incidents and threats.
- Investigating suspicious activities (e.g., identified IOCs and IOAs, suspicious emails, network anomalies).
- Query languages (e.g., KQL, Lucene, SPL, ESQL).
- Scripting and automation using languages (e.g., PowerShell, Python, Bash).
- Producing high-quality reports and investigation summaries for technical and non-technical stakeholders.
Preferred Qualifications:
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Management Information Systems, or a related field (equivalent experience may substitute).
- One or more relevant certifications, including but not limited to:
- CompTIA Security+
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Intrusion Analyst (GCIA)
- Certified SOC Analyst (CSA)
- Microsoft Cybersecurity Analyst (SC-200)
- Other GIAC or SOC-specific certifications.
- Five (5) years of experience in the following areas is strongly preferred:
- Advanced cybersecurity operations and monitoring.
- Coordinating with SOC teams during threat detection and escalations.
- Experience supporting systems that handle sensitive enterprise information.
Our Commitment to you / overview of benefits
- Medical, Dental and Vision Insurance; Wellness Program
- Flexible Spending Accounts (Healthcare, Dependent Care, Commuter)
- Short-Term and Long-Term Disability options
- Basic Life and AD&D Insurance (Company Provided)
- Voluntary Life and AD&D options
- 401(k) Retirement Savings Plan with matching after one year
- Paid Time Off
Reports to: Program Manager
Working Conditions
- Professional office environment, with the ability to work onsite in the main office.
- Must reside in the Austin area.
- Must be physically and mentally able to perform duties extended periods of time.
- Ability to use a computer and other office productivity tools with sufficient speed to meet the demands of this position.
- Must be able to establish a productive and professional workspace.
- Must be able to sit for long periods of time looking at computer screen.
- May be asked to work a flexible schedule which may include holidays.
- May be asked to travel for business or professional development purposes.
- May be asked to work hours outside of normal business hours.
- Travel costs, per diem, and other related expenses must be pre-approved in compliance with State of Texas travel guidelines.
Other Duties: Please note this job description is not designed to cover or contain a comprehensive list of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.
Cayuse is an Equal Opportunity Employer. All employment decisions are based on merit, qualifications, skills, and abilities. All qualified applicants will receive consideration for employment in accordance with any applicable federal, state, or local law.
Pay Range
USD $66,560.00 - USD $91,520.00 /Yr.
group id: 10323520