JOBSEARCHER

Network Security Engineer

We are seeking an experienced Network Security Analyst II to support enterprise cybersecurity and security operations. The selected professional will monitor, detect, investigate, and respond to security events across network, endpoint, identity, cloud, and on-premises environments.The ideal candidate will have strong hands-on experience with Microsoft Sentinel, SIEM, SOAR, EDR, XDR, NDR, threat intelligence, detection engineering, incident response, and security-query languages such as KQL and SPL.Key ResponsibilitiesMonitor security alerts, server and network logs, endpoint telemetry, threat-intelligence feeds, and security events.Investigate suspicious activity, malware indicators, anomalous network behavior, endpoint detections, and SIEM correlation events.Determine the scope, impact, severity, and appropriate response to cybersecurity incidents.Perform incident triage, investigation, escalation, containment coordination, and documentation.Develop, tune, and maintain SIEM detection rules, alerts, dashboards, workbooks, queries, automation, and response playbooks.Support threat-hunting activities using KQL, SPL, packet and session analysis, endpoint telemetry, and other investigative techniques.Analyze network traffic using NDR tools to identify threats and support incident investigations.Perform endpoint alert triage, device investigations, advanced hunting, and response actions using EDR tools.Support vulnerability, risk, and control assessments for network infrastructure and enterprise information systems.Identify indicators of compromise, suspicious network patterns, attacker tactics, and endpoint-based threats.Prepare incident reports, document findings, track corrective actions, and communicate recommendations.Collaborate with network, infrastructure, cloud, endpoint, identity, and application teams to validate events and mitigate risks.Support compliance, audit, and security-reporting activities by providing evidence, metrics, and operational documentation.Maintain awareness of emerging threats, attack techniques, and cybersecurity best practices relevant to healthcare and public-sector environments.Participate in incident-response escalation and after-action review activities.Required QualificationsAt least seven years of experience in cybersecurity, network security, security operations, incident response, or a closely related information-security role.Seven years of experience with SIEM, SOAR, EDR, XDR, and NDR technologies.Seven years of experience with security-log collection, management, analysis, and monitoring.Seven years of experience applying threat-intelligence concepts.Seven years of experience writing and interpreting KQL, SPL, or similar security queries.Seven years of experience supporting SIEM platforms and architecture.Seven years of experience with detection-engineering methodologies and implementation.Hands-on Microsoft Sentinel experience, including:Incident managementAnalytics rulesWorkbooks and dashboardsAutomationData connectorsKusto Query LanguageExperience using SIEM platforms for log analysis, alert investigation, correlation searches, security monitoring, and reporting.Experience with NDR tools for network-traffic analysis, packet or session investigation, threat detection, and incident support.Experience with EDR tools for endpoint-alert triage, advanced hunting, device investigation, and response.Strong knowledge of firewalls, IDS/IPS, proxy logs, DNS, VPN, TCP/IP, network segmentation, and secure network architecture.Ability to correlate complex security data across multiple sources and produce clear findings and recommendations.Familiarity with NIST, CIS Controls, HIPAA, and applicable state information-security requirements.Strong analytical, problem-solving, communication, and collaboration skills.Preferred QualificationsTen or more years of experience with:SIEM, SOAR, EDR, XDR, and NDRSecurity-log collection and managementThreat intelligenceKQL, SPL, and security-query developmentSIEM platform and architecture supportDetection-engineering methodology and implementationBachelor’s degree in cybersecurity, computer science, information systems, information technology, or a related discipline. Relevant experience may be considered in place of education.Previous cybersecurity experience in healthcare, government, or another regulated environment.Preferred CertificationsMicrosoft security certifications are strongly preferred, including:Microsoft Certified: Security Operations Analyst AssociateMicrosoft Certified: Cybersecurity Architect ExpertMicrosoft Certified: Azure Security Engineer AssociateMicrosoft 365 Defender-related certificationsAdditional preferred certifications include:CISSPCISMCISACompTIA Security+CompTIA CySA+GIAC security certificationsSplunk Core Certified Power UserSplunk Enterprise Security Certified AdminSentinelOne product certifications