Jobs · Information Technology · Texas

Senior Information Security Analyst

INSPYR Solutions · Houston, TX · Yesterday
HybridInformation TechnologyFull-time

About the role

This is a role with our external client, who is a global lawfirm. The Senior Information Security Analyst is one of several senior analyst roles within the firm's global Security Operations (SOC) team.

Responsibilities

  • Operate and manage security incidents and requests to SLA guidelines, acting as an intermediate escalation point for complex investigations.
  • Monitor, triage and investigate alerts across endpoints, cloud, identity, email and network telemetry, reviewing and escalating unusual event behavior.
  • Lead structured incident response aligned to a recognized lifecycle, including containment, eradication, recovery, evidence preservation and digital forensic analysis as authorized.
  • Triage and remediate phishing, vishing and impersonation attacks in a timely and efficient manner as the risk dictates.
  • Configure and tune appropriate security parameters in monitoring systems and act as a technical point of escalation for alerted issues.
  • Conduct proactive, hypothesis-driven threat hunting on a scheduled basis to identify adversary activity not surfaced by existing detections.
  • Design, test, tune and maintain detection rules and use cases (e.g. Sigma / KQL), and map detection coverage to the MITRE ATT&CK framework to identify and close detection gaps.
  • Maintain technical awareness of adversary tradecraft, emerging attack techniques and threat intelligence relevant to the legal sector, translating these into new or improved detections.
  • Develop and maintain security automation and orchestration (SOAR) playbooks to streamline incident response and automate repetitive operational tasks.
  • Use AI-assisted detection, triage and investigation tooling effectively, and critically validate, tune and quality-assure AI-generated findings and recommendations.
  • Act as a technical mentor for junior and peer analysts, supporting skills development and succession planning within the region.
  • Take ownership of one or more SOC processes, functions or technologies globally, ensuring their continued maintenance and improvement.
  • Aid in the development and maintenance of SOC playbooks, runbooks, monitoring configuration and standard operating procedures, identifying improvements and reporting on incidents.

Requirements

  • Technical bachelor's degree or equivalent IT / Information Security experience (required).
  • At least 5 years' experience working within security operations or Information Security infrastructure, or a strong vocation and demonstrable transferable experience from another technical discipline.
  • Proven ability to adapt quickly to emerging threats or new information, shifting focus as needed.
  • Demonstrated expertise in Microsoft 365 Defender and Microsoft Sentinel for detecting, investigating and responding to suspicious and anomalous activity.
  • Strong knowledge of core security technologies (firewalls, IDS/IPS, EDR, SIEM) and of structured incident-response methodologies (e.g. NIST).
  • Working knowledge of endpoint security and monitoring infrastructure (EDR, DLP, removable-media encryption) and of cloud-based web and email security solutions (e.g. Zscaler, Mimecast, Proofpoint, Cisco).
  • Experience working with a service management tool (e.g. ServiceNow).

Skills

  • Strong experience in Azure Sentinel is a requirement for this position.
  • Strong skills in Security Operations is critical, including incident management and response, threat investigations, etc.

Benefits

The Senior Information Security Analyst will be based in either Houston or Austin, TX (primarily remote with in-office visits as needed).

Pay

Commensurate with experience.

Schedule

Permanent, Direct-Hire.

Qualifications

  • US Citizens, GC Holders or Authorized to Work in the US.

Team

The Security Operations (SOC) team is a dedicated sub-team of Global Information Security responsible for near-24x7 monitoring, detection and response to security incidents. Operating in shifts across time zones, the team is the firm's first line of defense against cyber threats, triaging alerts from multiple sources and acting swiftly to contain and remediate when a threat is confirmed, collaborating with regional IT teams to prevent recurrence.

About INSPYR Solutions

INSPYR Solutions Technology is our focus and quality is our commitment. As a national expert in delivering flexible technology and talent solutions, we strategically align industry and technical expertise with our clients' business objectives and cultural needs. Our solutions are tailored to each client and include a wide variety of professional services, project, and talent solutions. By always striving for excellence and focusing on the human aspect of our business, we work seamlessly with our talent and clients to match the right solutions to the right opportunities.

Similar jobs