Netrio logo

Cyber Security Analyst

Netrio

On-site
McKinney, TX
Full-time
Mid Level
Senior
2+ yrs
Salary not listedPosted 4h ago

Real job — pulled straight from Netrio’s careers page · Verified August 19, 2026 · No reposts.

Job description

Netrio is hiring a Cyber Security Analyst — a full-time, based in McKinney, TX role. Apply directly on Netrio's careers page below.

Level 2 Cyber Security Analyst

Location: McKinney, TX

Department: Service Delivery

Position Summary

The SOC Analyst II is a mid-level, hands-on investigative role responsible for deep-dive analysis, incident response, and mentorship of Tier 1 analysts within Netrio's Government SOC. This role aligns to the DoD 8140/DCWF Cyber Defense Analyst (511) work role at an intermediate proficiency level and serves as the primary escalation point for confirmed or suspected security incidents across federal and Defense Industrial Base (DIB) client environments hosted in government-authorized cloud platforms.

Key Responsibilities

Perform in-depth investigation of escalated alerts and incidents using SIEM/XDR and EDR platforms

Conduct root-cause analysis, threat correlation, and impact assessment across multi-tenant government client environments

Lead containment, eradication, and recovery actions for confirmed incidents per incident response playbooks

Own DFARS 252.204-7012 incident reporting workflow, including 72-hour DIBNet reporting coordination and 90-day data preservation requirements

Perform threat hunting activities across EDR, SIEM, and identity telemetry (conditional access alerts, sign-in logs)

Mentor and validate escalations from Tier 1 analysts; provide on-shift coaching and quality review of Tier 1 triage decisions

Refine and author detection use cases, correlation rules, and playbooks based on investigation findings

Coordinate with client points of contact during active incidents, within defined communication protocols

Support endpoint management (RMM) and email security investigations as they intersect with broader incidents

Maintain and validate chain-of-custody and evidence-handling procedures for CUI-related investigations under CMMC Level 2 / NIST SP 800-171

Participate in tabletop exercises, incident response plan reviews, and audit/assessment support (C3PAO readiness activities)

Required Qualifications

2–5 years of experience in a SOC analyst, incident response, or threat hunting role

Demonstrated experience with at least one SIEM/XDR platform and one EDR platform in a production capacity

Solid understanding of the cyber kill chain, MITRE ATT&CK framework, and common adversary TTPs

Experience with log analysis, network traffic analysis, and basic malware/artifact triage

Strong incident documentation and client communication skills, including under time pressure

U.S. Citizenship (required for access to government client environments)

Ability to pass a background investigation as required by client contracts

Required Certifications (DoD 8140/DCWF Alignment)

CompTIA CySA+ and/or GIAC GCIH (Certified Incident Handler). GIAC GCFA (Certified Forensic Analyst) preferred, especially for candidates focused on investigation/forensics depth.

If not held at hire, required certification(s) must be obtained within the first 6 months of employment as a condition of continued assignment to government client accounts (DoD 8140 intermediate-level certification requirement).

Preferred Qualifications

Prior experience supporting CMMC, FedRAMP, or NIST 800-171/800-53 controlled environments

Experience in a multi-tenant MSSP or managed detection and response (MDR) setting

Scripting/automation experience (PowerShell, Python) for detection engineering or response automation

Familiarity with government cloud administrative constructs (e.g., GCC High, Azure Government, or equivalent)

Experience mentoring or leading junior analysts

Work Environment & Physical Requirements

Extended periods at a workstation monitoring multiple screens/dashboards and investigation tooling

Ability to work rotating shifts, including nights, weekends, and holidays

Ability to respond to off-hours pages/alerts during on-call rotation, including leading response for active incidents outside normal working hours

This is a 24/7 operational function — reliable attendance and shift punctuality are essential job functions

This job requisition is intended to describe the general nature of the work performed. It is not an exhaustive list of all duties, responsibilities, and qualification

About the Company

Netrio is a leading MSP in North America, specializing in IT solutions for small- to mid-market enterprises. We serve over 1,000 clients across industries with services including managed IT, cybersecurity, cloud, connectivity, voice, and custom application development.

Get Cyber Security Analyst jobs like this

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
Helsing logo

Software Engineer, Platform Engineering

Washington, DC
✓ From careers page· 37m ago
Clasp logo

Manager of Information Security (Remote)

$170k–$190kRemote · US-eligible
✓ From careers page· 38m ago
CBTS logo

CBTS

New

Security Services Specialist (Remote)

$110k–$160kRemote · US-eligible
✓ From careers page· 1h ago
CBTS logo

CBTS

New

Security Services Specialist

$109k–$137kCincinnati, OH
✓ From careers page· 1h ago

Frequently asked questions

What skills are required for Cyber Security Analyst at Netrio?

The required skills for Cyber Security Analyst at Netrio include: SIEM, PowerShell, Python.

What is the seniority level for Cyber Security Analyst at Netrio?

Cyber Security Analyst at Netrio is a Mid Level / Senior level position.

How do I apply for Cyber Security Analyst at Netrio?

You can view the full description and apply for Cyber Security Analyst at Netrio on EchoJobs: https://echojobs.io/job/netrio-level-2-cyber-security-analyst-48cp4.