2

Remote Network Forensics Jobs in Austin, TX (NOW HIRING)

Remote Network Forensics information

See Austin, TX salary details

$42.1K

$122.7K

$173.5K

How much do remote network forensics jobs pay per year?

As of Aug 9, 2026, the average yearly pay for remote network forensics in Austin, TX is $122,697.00, according to ZipRecruiter salary data. Most workers in this role earn between $103,100.00 and $141,200.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a remote network forensics specialist, and why are they important?

To thrive as a Remote Network Forensics Specialist, you need strong expertise in network protocols, cybersecurity principles, and digital forensic analysis, often supported by a degree in computer science or information security. Familiarity with tools like Wireshark, EnCase, FTK, and intrusion detection systems, as well as certifications such as GCIA or GCFA, is typically required. Analytical thinking, attention to detail, and effective communication are critical soft skills for investigating incidents and documenting findings. These abilities are essential for accurately identifying, analyzing, and mitigating security breaches in remote environments.

What is remote network forensics?

Remote network forensics is the process of monitoring, capturing, analyzing, and investigating network traffic and data transmissions from a distance, often using specialized tools and software. This field helps organizations identify security incidents, trace cyberattacks, and gather evidence for legal or internal purposes without being physically present at the network site. Experts in remote network forensics can detect breaches, unauthorized access, and data exfiltration, making it a crucial part of modern cybersecurity practices.

What are some common challenges faced by professionals in remote network forensics, and how can they be addressed?

One common challenge in remote network forensics is ensuring secure access to sensitive data while working outside of a centralized office environment. Professionals often need to maintain strict chain-of-custody protocols and use encrypted channels for data transmission to preserve evidence integrity. Another challenge is collaborating effectively with cross-functional teams, such as incident response and IT, despite being physically distant. Utilizing secure communication tools and establishing clear documentation practices can help overcome these hurdles and ensure efficient investigations.

What is the difference between Remote Network Forensics vs Network Security Analyst?

AspectRemote Network ForensicsNetwork Security Analyst
CertificationsCEH, CISSP, GIACCISSP, CompTIA Security+
Work EnvironmentInvestigative, incident response teams, remote analysisSecurity monitoring, policy enforcement, often remote or on-site
Industry UsageCybersecurity firms, law enforcement, corporate securityIT departments, cybersecurity firms, enterprises

Remote Network Forensics focuses on analyzing network data to investigate security incidents, often involving detailed digital forensics. Network Security Analysts monitor and protect networks proactively, implementing security measures and responding to threats. While both roles require similar certifications and may work remotely, their core functions differ: forensic investigation versus ongoing security management.

What are popular job titles related to Remote Network Forensics jobs in Austin, TX? For Remote Network Forensics jobs in Austin, TX, the most frequently searched job titles are:
What job categories do people searching Remote Network Forensics jobs in Austin, TX look for? The top searched job categories for Remote Network Forensics jobs in Austin, TX are:
What cities near Austin, TX are hiring for Remote Network Forensics jobs? Cities near Austin, TX with the most Remote Network Forensics job openings:
Infographic showing various Remote Network Forensics job openings in Austin, TX as of June 2026, with employment types broken down into 53% Full Time, 31% Part Time, and 16% Contract. Highlights an 51% Physical, 3% Hybrid, and 46% Remote job distribution, with an average salary of $122,697 per year, or $59 per hour.

Network Security Analyst 3 (Remote)

Serigor, Inc.

Austin, TX • On-site, Remote

Full-time

Posted 20 hours ago

Posted today


Job description

Job Title: Network Security Analyst 3 (Remote)
Location: Austin, TX
Duration: 12 Months with possible extension
Job Description:
The client is seeking a senior-level Security Operations Analyst to strengthen detection, response, and orchestration capabilities across the agency's security operations. This role blends deep SOC (Security Operations Center) investigative expertise with hands-on security automation engineering, focusing on CrowdStrike Falcon and Torq to build scalable, AI-assisted detection and response workflows. The ideal candidate has practical experience integrating large language model (LLM) tools such as Claude into security operations - for triage acceleration, playbook generation, and analyst augmentation - while operating within a strict Zero Trust, defense-in-depth security posture appropriate to a state Attorney General's office.
Key Responsibilities
  • Serve as a SOC analysis & Tier 3 escalation point for complex security incidents, performing deep-dive investigation, root cause analysis, and threat hunting across endpoint, network, cloud, and identity telemetry.
  • Design, build, and maintain detection analytics, dashboards, and hunting queries (Falcon Query Language / FQL) within CrowdStrike Falcon, tuning correlation rules and detection logic to reduce false positives and improve mean-time-to-detect (MTTD).
  • Architect and maintain security orchestration, automation, and response (SOAR) playbooks in Torq, integrating CrowdStrike Falcon, identity providers, ticketing, and communication platforms into automated response workflows.
  • Design AI-assisted analyst workflows (e.g., automated triage summarization, alert enrichment, playbook drafting) using approved generative AI tooling, ensuring all inputs are sanitized and free of regulated or case-specific data.
  • Lead incident response efforts for high-severity events, coordinating with IT, legal, and divisional stakeholders while strictly adhering to FTI/CJI handling restrictions.
  • Develop and maintain detection engineering documentation, runbooks, and standard operating procedures (SOPs) for Tier 1/Tier 2 analyst use.
  • Mentor and provide technical guidance to Tier 1 and Tier 2 SOC analysts; review and validate their investigative work and escalation quality.
  • Continuously evaluate and integrate emerging SOC automation and AI capabilities, presenting proposals for tooling changes with documented risk and compliance analysis.
  • Participate in an on-call rotation for critical incident escalations.

The above job description and requirements are general in nature and may be subject to change based on the specific needs and requirements of the organization and project.
CANDIDATE SKILLS AND QUALIFICATIONS
Minimum Requirements:
Candidates that do not meet or exceed the minimum stated requirements (skills/experience) will be displayed to customers but may not be chosen for this opportunity.
Years
Required/Preferred
Experience
8
Required
Progressive SOC / security operations experience, including 2+ years functioning at a Tier 3 / senior analyst or detection engineering level.
8
Required
Hands-on production experience with CrowdStrike Falcon (Insight XDR, Discover, and/or Fusion SOAR), including custom detection/IOA authoring, Falcon Query Language (FQL) use, and dashboard development.
8
Required
Demonstrated experience building or maintaining SOAR automation (Torq strongly preferred)
8
Required
Practical, hands-on experience using AI/LLM tools (e.g., Claude, GPT-based tools) to support security operations, with clear understanding of data sanitization and safe-use boundaries in a regulated environment.
8
Required
Working knowledge of Zero Trust architecture principles (NIST 800-207) and general familiarity with regulatory frameworks such as IRS Pub. 1075, FBI CJIS Policy, and HIPAA.
8
Required
Strong scripting/automation ability (PowerShell, Python, or Falcon Query Language-based automation) for building custom detections and integrations.
8
Required
Excellent written communication skills for incident reporting, runbook authorship, and cross-divisional coordination.
8
Required
Experience documenting investigations, creating hunt reports, and communicating technical findings to diverse audiences.
8
Required
Strong analytical, problem-solving, and critical-thinking skills
8
Required
Ability to work independently while collaborating effectively within cross-functional cybersecurity teams.
8
Required
Ability to resolve complex security issues in diverse and decentralized environments; learn, communicate, teach new security technologies; and communicate effectively.
8
Required
Conduct forensic investigations on cyberattacks to determine how they occurred and can be prevented in the future.
8
Required
Experience creating/reviewing/updating security policies and standards for the public/private/hybrid cloud contexts.
4
Required
Bachelor's degree in Computer Science, Information Security, or related field, or equivalent professional experience.
1
Preferred
GIAC certifications (GCIH, GCIA, GCFA) or equivalent.
1
Preferred
CrowdStrike Certified Falcon Responder (CCFR) or CrowdStrike Certified Falcon Administrator (CCFA), or equivalent CrowdStrike security certification.
1
Preferred
Torq certification or demonstrated portfolio of built automation workflows
1
Preferred
Experience designing AI-assisted playbooks or analyst copilots for SOC use cases while maintaining strict data-handling guardrails.
1
Preferred
Familiarity with Microsoft Defender XDR, Splunk, Entra ID Protection, and Tenable One / cloud security posture management (CSPM) tooling.
1
Preferred
Experience in government, legal, or law-enforcement-adjacent security environments