Security Operations / Detection Engineering analyst.
About the role
Assyst is seeking an experienced Network Security Analyst II to support the client’s enterprise security operations. The role is responsible for monitoring, detecting, investigating, and responding to security events across network, endpoint, cloud, and on-premises environments.
The ideal candidate will have strong hands-on experience with SIEM, SOAR, EDR/XDR, NDR, threat intelligence, detection engineering, and incident response, with the ability to independently analyze complex security events and recommend appropriate mitigation actions.
Roles & Responsibilities:
- Monitor and analyze security alerts, logs, network traffic, endpoint telemetry, and threat intelligence feeds.
- Perform incident triage, investigation, escalation, containment, and documentation.
- Investigate suspicious activity, malware indicators, anomalous network behavior, and security breaches.
- Develop and tune SIEM detection rules, alerts, dashboards, queries, and playbooks.
- Conduct threat hunting using KQL, SPL, packet/session analysis, and endpoint telemetry.
- Support vulnerability, risk, and security control assessments.
- Analyze and correlate security events across network, endpoint, identity, and cloud environments.
- Work with network, infrastructure, cloud, endpoint, and application teams to validate incidents and implement risk mitigation.
- Identify IOCs, attacker tactics, suspicious network patterns, and endpoint threats.
- Prepare incident reports, investigation documentation, metrics, and security recommendations.
- Support security compliance, audit, reporting, and after-action review activities.
- Stay current with emerging threats, attack techniques, and security best practices.
- Provide after-hours support for high-priority security incidents or planned maintenance when required.
Required Skills:
- 7+ years of experience in cybersecurity, network security, security operations, incident response, or related information security roles.
- 7+ years of experience with SIEM, SOAR, EDR, XDR, and NDR technologies.
- Strong experience with security log collection and management and SIEM platform/architecture support.
- Strong experience with threat intelligence and detection engineering methodologies.
- Hands-on experience with Microsoft Sentinel, including analytics rules, workbooks, automation, data connectors, incident management, and KQL.
- Strong ability to write and interpret KQL, SPL, and security queries for investigations and reporting.
- Experience with NDR/network traffic analysis, packet/session investigation, and threat detection.
- Experience with EDR alert triage, endpoint investigation, advanced hunting, and response actions.
- Strong knowledge of firewalls, IDS/IPS, DNS, VPN, TCP/IP, proxy logs, network segmentation, and secure network architecture.
- Knowledge of NIST, CIS Controls, HIPAA, and applicable information security requirements.
- Strong analytical, problem-solving, communication, documentation, and incident-prioritization skills.
- Ability to work independently in a fast-paced security operations environment.
- 10+ years of relevant experience is preferred.
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, IT, or a related field is preferred.
Preferred Certifications:
Microsoft Security certifications, including Security Operations Analyst Associate, Cybersecurity Architect Expert, Azure Security Engineer Associate, or Microsoft 365 Defender certifications are preferred.
Additional preferred certifications include Security+, CySA+, GIAC, CISSP, CISM, CISA, Splunk certifications, and SentinelOne certifications.
ASSYST is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, disability, military status, national origin or any other characteristic protected under federal, state, or applicable local law.
Description as published by ASSYST, Inc..