Enter a job title or keyword

Network Security Analyst 2

Ampcus Inc.


Job Location:

Austin, TX - USA

Monthly Salary: Not provided by the employer
Posted: 29 September 2026 (Yesterday)
Application Deadline: 27 December 2026
Vacancies: 1 Vacancy

Job Summary

Ampcus Inc. is a certified global provider of a broad range of Technology and Business consulting services. We are in search of a highly motivated candidate to join our talented Team.

Job Title:Network Security Analyst 2

Location(s):Austin TX


Job Summary
The Network Security Analyst II performs advanced cybersecurity and network security analysis work in support of enterprise security operations. This role is responsible for monitoring detecting investigating and responding to security events across on-premises cloud and endpoint environments.

The ideal candidate is a hands-on security operations professional with strong experience across SIEM SOAR EDR network detection and incident response platforms. This role requires sound judgment technical depth attention to detail and a strong commitment to protecting systems data and services.

Essential Job Functions

  • Monitor security alerts logs network events endpoint telemetry and threat intelligence feeds.
  • Analyze suspicious activity anomalous network behavior malware indicators endpoint detections and SIEM correlation events to determine scope impact and required response actions.
  • Perform incident triage investigation escalation containment coordination and documentation in alignment with security operations procedures.
  • Develop tune and maintain detection rules dashboards alerts playbooks and queries to improve visibility across network endpoint identity and cloud environments.
  • Support threat hunting activities using KQL SPL packet/session analysis endpoint telemetry and other investigative techniques.
  • Assist with vulnerability risk and control assessments for network security infrastructure and enterprise information systems.
  • Document findings prepare incident reports track corrective actions and communicate technical information to security leadership and business stakeholders.
  • Collaborate with network infrastructure cloud endpoint and application teams to validate security events and implement risk mitigation measures.
  • Maintain awareness of emerging cyber threats attack techniques indicators of compromise and security best practices relevant to healthcare and public-sector environments.
  • Support compliance audit and reporting activities by providing evidence metrics and security operations documentation as requested.

Required Qualifications

  • Minimum of seven years of experience in cybersecurity network security security operations incident response or a closely related information security role.
  • Hands-on experience with Microsoft Sentinel including incident management analytics rules workbooks automation data connectors and Kusto Query Language (KQL).
  • Experience using SIEM for log analysis alert investigation dashboarding correlation searches and security monitoring.
  • Experience with NDR for network traffic analysis packet/session investigation threat detection and incident support.
  • Experience with EDR tools including endpoint alert triage device investigation advanced hunting and response actions.
  • Working knowledge of network security concepts including firewalls IDS/IPS proxy logs DNS VPN TCP/IP segmentation and secure network architecture.
  • Ability to analyze complex security events correlate data across multiple sources and produce clear written documentation and recommendations.
  • Knowledge of security frameworks standards and regulatory considerations such as NIST CIS Controls HIPAA and state information security requirements.
  • Strong communication collaboration problem-solving and analytical skills.
  • Ability to maintain the security and integrity of critical infrastructure systems by preventing unauthorized access and ensuring compliance with applicable laws regulations and security requirements.

Preferred Education and Certifications

  • Bachelors degree in cybersecurity computer science information systems information technology or a related field. Relevant experience may be considered in place of education where applicable.
  • Microsoft security certifications are strongly preferred such as:
    • Microsoft Certified: Security Operations Analyst Associate
    • Microsoft Certified: Cybersecurity Architect Expert
    • Microsoft Certified: Azure Security Engineer Associate
    • Microsoft 365 Defender-related certifications
  • Additional preferred certifications include:
    • CompTIA Security
    • CompTIA CySA
    • GIAC security certifications
    • CISSP
    • CISM
    • CISA
    • Splunk Core Certified Power User
    • Splunk Enterprise Security Certified Admin
    • SentinelOne product certifications

Knowledge Skills and Abilities

  • Knowledge of SIEM SOAR EDR XDR network detection and response log management and threat intelligence concepts.
  • Skill in writing and interpreting KQL SPL and security queries to support investigations and reporting.
  • Skill in identifying indicators of compromise attacker tactics suspicious network patterns and endpoint-based threats.
  • Ability to prioritize alerts document investigative steps and escalate incidents based on severity and business impact.
  • Ability to work independently and collaboratively in a security operations environment with shifting priorities and time-sensitive incidents.
  • Ability to communicate cybersecurity risks findings and recommended actions to both technical and non-technical audiences.

Work Expectations

  • Participate in incident response escalation and after-action review activities as needed.
  • Support enterprise security monitoring for systems that process store or transmit sensitive information.
  • Follow applicable policies procedures standards and state and federal security requirements.
  • Maintain accurate operational documentation investigation notes metrics and leadership-ready summaries.
  • May be required to provide support outside normal business hours during high-priority security incidents or planned maintenance activities.

Candidate Skills and Qualifications
Minimum Requirements

  • 7 years: Knowledge of SIEM SOAR EDR XDR and NDR.
  • 7 years: Experience with security log collection and management.
  • 7 years: Experience with threat intelligence concepts.
  • 7 years: Skill in writing and interpreting KQL SPL and security queries to support investigations and reporting.
  • 7 years: Experience in SIEM platform/architecture support.
  • 7 years: Experience in detection engineering methodology and implementation.

Preferred Requirements

  • 10 years: Knowledge of SIEM SOAR EDR XDR and NDR.
  • 10 years: Experience with security log collection and management.
  • 10 years: Experience with threat intelligence concepts.
  • 10 years: Skill in writing and interpreting KQL SPL and security queries to support investigations and reporting.
  • 10 years: Experience in SIEM platform/architecture support.
  • 10 years: Experience in detection engineering methodology and implementation.

Additional Information

  • Candidates may be subject to a pre-employment security review to determine employment eligibility.
  • Candidates may be required to undergo criminal background checks as authorized by applicable law.

Schedule:

  • MondayFriday during agency business hours.


Ampcus is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race color religion sex sexual orientation gender identity national origin age protected veterans or individuals with disabilities.


Required Experience:

IC