Job Description
We are seeking an experienced Security Consultant / Security Operations Analyst to support the integration of HHSC and DSHS applications into Google SecOps (SIEM/SOAR).
This is a hands-on security operations role focused on monitoring, investigating, detecting, and responding to security events across network, endpoint, identity, and cloud environments.
The ideal candidate will have strong experience with Microsoft Sentinel, SIEM/SOAR, NDR, EDR, KQL, SPL, network security, threat hunting, and incident response, along with the ability to communicate security risks to both technical and business stakeholders.
Key Responsibilities
- Monitor security alerts, logs, network events, endpoint telemetry, and threat intelligence feeds.
- Triage and investigate suspicious activities and determine scope, impact, and severity.
- Lead escalation and coordinate containment and response activities.
- Build, tune, and maintain detection rules, dashboards, alerts, playbooks, and automation workflows.
- Perform threat hunting using KQL, SPL, packet/session analysis, and endpoint telemetry.
- Support vulnerability assessments, risk assessments, and security control evaluations.
- Prepare detailed incident reports and track corrective actions through resolution.
- Provide security briefings and communicate risks to security leadership and business stakeholders.
- Collaborate with network, infrastructure, cloud, and application teams to validate events and reduce security risks.
- Provide security evidence, metrics, and documentation for compliance and audit requests.
- Participate occasionally in after-hours support for high-priority security incidents and planned maintenance.
Required Qualifications
- 7+ years of experience in cybersecurity, network security, security operations, or incident response.
- Hands-on experience with Microsoft Sentinel, including:
- Incident management
- Analytics rules
- Workbooks
- Automation
- Data connectors
- KQL
- Strong SIEM experience with log analysis, alert investigation, correlation searches, and dashboard development.
- Experience with NDR technologies, including network traffic and packet/session analysis.
- Experience with EDR, including alert triage, device investigation, advanced hunting, and response actions.
- Strong understanding of:
- Firewalls
- IDS/IPS
- Proxy logs
- DNS
- VPN
- TCP/IP
- Network segmentation
- Knowledge of NIST, CIS Controls, HIPAA, and state information security requirements.
- Strong analytical, written, and verbal communication skills.
- Ability to explain security risks and technical findings to both technical and non-technical audiences.
- Experience with Google SecOps or Wiz.
Preferred Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field. Equivalent relevant experience may be considered.
- Google SecOps or Wiz certification.
- Microsoft security certifications such as SC-200, AZ-500, or SC-100.
- Security certifications such as:
- Security+
- CySA+
- GIAC
- CISSP
- CISM
- CISA
- Splunk Core Certified Power User
- Splunk ES Administrator
- SentinelOne certifications
- Hands-on Splunk / SPL experience.
- Experience mentoring junior security analysts.
- Healthcare or public-sector cybersecurity experience.