NEW JOB OPENING
SENIOR NETWORK SECURITY ANALYST MICROSOFT SENTINEL, KQL & THREAT DETECTION
IN Austin, TX, USA!

 

Date Posted: 09/15/2026
Hiring Organization: Rose International
Position Number: 507480
Industry: Government
Job Title: Senior Network Security Analyst Microsoft Sentinel, KQL & Threat Detection
Job Location: Austin, TX, USA, 78751
Work Model: Onsite
Shift: Monday through Friday from 8:00 AM to 5:00 PM
Employment Type: Temporary
FT/PT: Full-Time
Estimated Duration (In months): 11
Min Hourly Rate($): 90.00
Max Hourly Rate($): 94.00
Must Have Skills/Attributes: Analytics, Cybersecurity, DNS, HIPAA, Network Security, TCP/IP
Experience Desired: Knowledge of SIEM, SOAR, EDR, XDR, NDR (7 yrs); Experience with security log collection and management (7 yrs); Experience with threat intelligence concepts (7 yrs); Skill in writing and interpreting KQL, SPL, and security queries to support investigations (7 yrs)
Required Minimum Education: Bachelor’s Degree

**C2C is not available**

 

Job Description
Required Education:

• Bachelor’s degree in cybersecurity, computer science, information systems, information technology, or a related field. Relevant experience may be considered in place of education where applicable.



Required Skills/Experience:

• Minimum of seven years of experience in cybersecurity, network security, security operations, incident response, or a closely related information security role.

• Hands-on experience with Microsoft Sentinel, including incident management, analytics rules, workbooks, automation, data connectors, and Kusto Query Language.

• Experience using SIEM for log analysis, alert investigation, dashboarding, correlation searches, and security monitoring.

• Experience with NDR for network traffic analysis, packet/session investigation, threat detection, and incident support.

• Experience with EDR tools, including endpoint alert triage, device investigation, advanced hunting, and response actions.

• Working knowledge of network security concepts, including firewalls, IDS/IPS, proxy logs, DNS, VPN, TCP/IP, segmentation, and secure network architecture.

• Ability to analyze complex security events, correlate data across multiple sources, and produce clear written documentation and recommendations.

• Knowledge of security frameworks, standards, and regulatory considerations such as NIST, CIS Controls, HIPAA, and state information security requirements.

• Strong communication, collaboration, problem-solving, and analytical skills.

• 7 Year Required Knowledge of SIEM, SOAR, EDR, XDR, NDR

• 7 Year Required Experience with security log collection and management

• 7 Year Required Experience with threat intelligence concepts

• 7 Year Required Skill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting

• 7 Year Required Experience in SIEM platform/architecture support

• 7 Year Required Experience in detection engineering methodology and implementation



Knowledge, Skills, and Abilities

• Knowledge of SIEM, SOAR, EDR, XDR, network detection and response, log management, and threat intelligence concepts.

• Skill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting.

• Skill in identifying indicators of compromise, attacker tactics, suspicious network patterns, and endpoint-based threats.

• Ability to prioritize alerts, document investigative steps, and escalate incidents based on severity and business impact.

• Ability to work independently and collaboratively in a security operations environment with shifting priorities and time-sensitive incidents.

• Ability to communicate cybersecurity risks, findings, and recommended actions to both technical and non-technical audiences.



Preferred Qualifications:

• 10 Year Preferred Knowledge of SIEM, SOAR, EDR, XDR, NDR

• 10 Year Preferred Experience with security log collection and management

• 10 Year Preferred Experience with threat intelligence concepts

• 10 Year Preferred Skill in writing and interpreting KQL, SPL, and security queries to support investigations and reporting

• 10 Year Preferred Experience in SIEM platform/architecture support

• 10 Year Preferred Experience in detection engineering methodology and implementation

• Microsoft security certifications are strongly preferred, such as Microsoft Certified: Security Operations Analyst Associate, Microsoft Certified: Cybersecurity Architect Expert, Microsoft Certified: Azure Security Engineer Associate, or Microsoft 365 Defender-related certifications.

• Additional preferred certifications include CompTIA Security+, CySA+, GIAC security certifications, CISSP, CISM, CISA, Splunk Core Certified Power User, Splunk Enterprise Security Certified Admin, or Sentinel One product certifications.



Job Summary

The Network Security Analyst II performs advanced cybersecurity and network security analysis work in support of HHSC’s enterprise security operations. This role is responsible for monitoring, detecting, investigating, and responding to security events across on-premises, cloud, and endpoint environments. The ideal candidate is a hands-on security operations professional with strong experience across SIEM, SOAR, EDR, network detection, and incident response platforms. This role requires sound judgment, technical depth, attention to detail, and a strong commitment to protecting HHSC systems, data, and services that support the health and well-being of Texans.



Responsibilities:

• Monitor security alerts, logs, network events, endpoint telemetry, and threat intelligence feeds.

• Analyze suspicious activity, anomalous network behavior, malware indicators, endpoint detections, and SIEM correlation events to determine scope, impact, and required response actions.

• Perform incident triage, investigation, escalation, containment coordination, and documentation in alignment with HHSC security operations procedures.

• Develop, tune, and maintain detection rules, dashboards, alerts, playbooks, and queries to improve visibility across network, endpoint, identity, and cloud environments.

• Support threat hunting activities using KQL, SPL, packet/session analysis, endpoint telemetry, and other investigative techniques.

• Assist with vulnerability, risk, and control assessments for network security infrastructure and enterprise information systems.

• Document findings, prepare incident reports, track corrective actions, and communicate technical information to security leadership and business stakeholders.

• Collaborate with network, infrastructure, cloud, endpoint, and application teams to validate security events and implement risk mitigation measures.

• Maintain awareness of emerging cyber threats, attack techniques, indicators of compromise, and security best practices relevant to healthcare and public-sector environments.

• Support compliance, audit, and reporting activities by providing evidence, metrics, and security operations documentation as requested.
  • **Only those lawfully authorized to work in the designated country associated with the position will be considered.**

  • **Please note that all Position start dates and duration are estimates and may be reduced or lengthened based upon a client’s business needs and requirements.**


 

Benefits:
For information and details on employment benefits offered with this position, please visit here. Should you have any questions/concerns, please contact our HR Department via our secure website.

California Pay Equity:
For information and details on pay equity laws in California, please visit the State of California Department of Industrial Relations' website here.

Rose International is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, sexual orientation, gender (expression or identity), national origin, arrest and conviction records, disability, veteran status or any other characteristic protected by law. Positions located in San Francisco and Los Angeles, California will be administered in accordance with their respective Fair Chance Ordinances.

If you need assistance in completing this application, or during any phase of the application, interview, hiring, or employment process, whether due to a disability or otherwise, please contact our HR Department.

Rose International has an official agreement (ID #132522), effective June 30, 2008, with the U.S. Department of Homeland Security, U.S. Citizenship and Immigration Services, Employment Verification Program (E-Verify). (Posting required by OCGA 13/10-91.).

 

Apply Now

 

About Rose

  • Founded in 1993
  • Office Locations Across the U.S.
  • 150+ Clients: Corporations and Government Agencies
  • Employee Oriented Company
  • Challenging Assignments Across the U.S.
  • Continuous Professional Development

I believe the best thing that Rose HR has going for it is the incredible responsiveness. Everyone is very quick to reply to any concerns, and contacts the contracted employees very quickly and efficiently.

Kevin, Consultant

My on-boarding with Rose was outstanding. The packets of information, the process, and great attention to detail each person gave me allowed me to get started quickly.I appreciated each person's friendly and helpful attitude.

Diana, Consultant

Rose International has been great to me. I thank everyone there for all of their hard work; it has not gone unnoticed.

Melody, Consultant

Your team at Rose International is always very helpful and responsive.

Barbara, Consultant

I have been very pleased with my experience with Rose International. Everyone that I encountered was very helpful and courteous.

Stephanie, Consultant

EMPLOYEE COMMENTS

  • We want you to work with us, but don't take our word for it. Take a look at this sampling of employee comments. They speak for themselves.