The SOC/Cybersecurity Analyst will support the Texas Health and Human Services Commission on the Cybersecurity Operations Center (CSOC). This role performs advanced cybersecurity analysis and threat triage within the CSOC, monitoring and investigating security alerts across enterprise platforms to protect agency information systems, networks, and data. The analyst serves as a primary point of contact for security event analysis, threat identification, and incident escalation. Work includes correlating data from multiple security tools, validating potential incidents, and coordinating response activities with technical teams. The analyst also documents investigations, supports continuous improvement of detection capabilities, and contributes to operational procedures and playbooks. This position requires the ability to work independently and as part of a 24x7 cybersecurity operations team.
Responsibilities:
- Monitor, analyze, and triage cybersecurity alerts generated by SIEM, EDR, cloud security, email security, identity protection, and network security platforms.
- Conduct initial investigations of detected and reported security events to determine severity, scope, and impact.
- Identify, validate, and prioritize potential cybersecurity incidents, escalating confirmed threats according to established procedures.
- Correlate security events from multiple data sources, including endpoints, firewalls, intrusion detection and prevention systems, cloud services, and threat intelligence feeds.
- Review and analyze indicators of compromise, suspicious network activity, phishing emails, malware detections, and anomalous user behavior.
- Document investigations, findings, and response actions in ticketing and case management systems.
- Assist with incident containment, eradication, and recovery efforts by coordinating with technical teams and stakeholders.
- Report and escalate findings to the CSOC Team Lead and/or SOC Manager.
- Support continuous improvement of threat detection capabilities through alert tuning, process refinement, and threat intelligence integration.
- Perform vulnerability assessment reviews and support development of operational procedures, playbooks, and knowledge base articles.
Requirements
Minimum Qualifications:
- 5 years of experience triaging security alerts.
- 5 years of experience analyzing security events.
- 5 years of experience documenting incident investigations.
- 5 years of experience with cybersecurity frameworks.
- 5 years of experience with incident response processes.
- 5 years of experience with threat detection methodologies.
- 5 years of experience in cybersecurity operations.
- 5 years of experience in security monitoring.
- 5 years of experience in incident response.
- 5 years of experience in threat detection.
- 5 years of experience in security investigations.
- 5 years of experience in related cybersecurity disciplines.
Preferred Qualifications:
- Experience with one or more Texas state agencies.
- Bachelor's degree in cybersecurity, information security, computer science, computer information systems, management information systems, or a related field (relevant education and experience may be substituted).
- A security certification such as CompTIA Security+, GIAC Certified Incident Handler (GCIH), GIAC Certified Intrusion Analyst (GCIA), Certified SOC Analyst (CSA), Microsoft Cybersecurity Analyst (SC-200), or another GIAC or SOC-related certification.
- Experience with enterprise SOC tools and technologies such as Microsoft Sentinel, Splunk, CrowdStrike, Tenable, Qualys, Zscaler, or Prisma.
Additional Requirements:
- Candidates are subject to a pre-employment security review and criminal background check to determine employment eligibility.
- Candidates must currently reside in Texas and be local to the Austin area. Candidates who reside out of state, including those planning to relocate, will not be accepted.
- May be required to work outside normal business hours, including weekends, evenings, and holidays, during high-priority security incidents, as approved by the SOC Manager.
Work Location and Schedule:
- Location: 701 W 51st Street, Austin, TX 78751.
- Schedule: Monday through Friday, 8:00 a.m. to 5:00 p.m., excluding Texas state holidays. May require work outside normal business hours during high-priority incidents.
- Work Arrangement: Onsite.
Skills Required
- 5 years of experience triaging security alerts
- 5 years of experience analyzing security events
- 5 years of experience documenting incident investigations
- 5 years of experience with cybersecurity frameworks
- 5 years of experience with incident response processes
- 5 years of experience with threat detection methodologies
- 5 years of experience in cybersecurity operations
- 5 years of experience in security monitoring
- 5 years of experience in incident response
- 5 years of experience in threat detection
- 5 years of experience in security investigations
- 5 years of experience in related cybersecurity disciplines
- Experience with one or more Texas state agencies
- Bachelor's degree in cybersecurity, information security, computer science, computer information systems, management information systems, or a related field; relevant education and experience may be substituted
- Security certification such as CompTIA Security+, GCIH, GCIA, Certified SOC Analyst, Microsoft Cybersecurity Analyst SC-200, or another GIAC or SOC-related certification
- Experience with enterprise SOC tools such as Microsoft Sentinel, Splunk, CrowdStrike, Tenable, Qualys, Zscaler, or Prisma
- Current Texas residency and local availability in the Austin area
- Successful pre-employment security review and criminal background check
What We Do
Air InfoSec is a veteran-owned and led cybersecurity consulting and staffing firm based in Austin, Texas, focused on enhancing government security through expert staff placement.







