Cybersecurity Ops Analyst Senior

Saic

Tennessee

Hybrid

USD 80,000 - 120,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

SAIC is seeking a Cybersecurity Ops Analyst Sr. for the Enterprise Security Operations Center in Oak Ridge, Tennessee. This senior role supports complex incident investigations, forensic log analysis, and cross-enterprise response activities.

Ideal candidates bring hands-on experience with SIEM (prefer Splunk), EDR, and cloud telemetry. US citizenship is required. The position follows a 4x10 schedule and may require 24/7/365 support as needed.

Qualifications

  • Bachelor’s degree with 5+ years of related experience; master’s with 3+ years allowed.
  • 3+ years of cybersecurity operations experience: monitoring, incident response, or investigations.
  • Must possess CySA+, SSCP, or equivalent.

Responsibilities

  • Lead investigation and triage of escalated security cases.
  • Coordinate containment, eradication, and recovery activities.
  • Develop timelines, evidence summaries, and technical findings for post-incident reviews.
  • Identify detection gaps and drive improvements across ESOC.
  • Support playbooks, tabletop exercises, and training across the team.
  • Mentor junior analysts and share knowledge to raise operational maturity.
  • Contribute to 24/7/365 coverage and cross-functional coordination.

Skills

Leadership
Communication
Multitasking
Team mentoring
Analytical thinking

Education

Bachelor’s degree +5+ yrs
Master’s degree +3+ yrs
Alternative: 4+ yrs experience in lieu

Tools

Splunk
EDR/Endpoint tooling

Job description

Description

SAIC has an opening for a Cybersecurity Ops Analyst Sr. This position is located in Oak Ridge, Tennessee; however, SAIC is open to remote work for qualified candidates within the United States.

This role is a senior analyst position on SAIC’s Cyber Incident Response Team within the Enterprise Security Operations Center. Reporting to the Manager of Defensive Cyber Operations, the Cybersecurity Ops Analyst Sr is responsible for supporting complex cybersecurity incident investigations, forensic log analysis, and response activities across the enterprise.

The senior analyst will investigate escalated security cases, analyze security telemetry, perform forensic review, coordinate response actions, and help ensure SAIC maintains a strong, repeatable, and technically mature incident response capability. This includes analysis across SIEM, EDR, endpoint telemetry, identity platforms, email security tools, network logs, cloud telemetry, and other enterprise security data sources.

This position requires the ability to work laterally across the ESOC and the broader cybersecurity organization to investigate incidents, validate findings, coordinate response actions, and improve operational readiness. The analyst will serve as an escalation point for high priority cases and will help translate technical investigation findings into clear operational recommendations.

In addition to incident response and forensic responsibilities, the analyst contributes to continuous improvement across the ESOC by supporting playbook development, purple team exercises, tabletop exercises, post incident reviews, documentation, process refinement, and knowledge sharing with other analysts. This role is expected to strengthen investigative consistency, improve response readiness, and help mature the organization’s defensive cyber operations capability.

The position will work a 4x10 schedule, 7:00 a.m. EST to 5:00 p.m. EST, Monday through Thursday, with the expectation to support 24/7/365 operations as required.

Job Duties:
  • Take escalated cybersecurity cases and coordinate triage, investigation, containment, eradication, and recovery activities across affected systems, accounts, and environments.
  • Conduct incident investigations using forensic analysis, SIEM, EDR, endpoint, identity, email, network, cloud, and other enterprise security telemetry to determine scope, impact, root cause, and potential data exposure.
  • Coordinate approved remediation actions such as account disablement, session revocation, email purge, endpoint isolation, IP or URL blocking, access review, and other response actions needed to reduce risk and restore affected environments.
  • Develop clear investigative timelines, case narratives, evidence summaries, technical findings, and response documentation to support operational decision making and post incident review.
  • Work laterally across the ESOC and cybersecurity organization to validate findings, communicate risk, coordinate response activity, and support timely incident resolution.
  • Identify detection gaps, control weaknesses, forensic visibility gaps, response gaps, and process improvement opportunities based on incident findings, case reviews, purple team activity, and tabletop exercises.
  • Support purple team exercises by validating alerts, reviewing adversary emulation activity, identifying visibility gaps, and helping convert findings into improved monitoring, investigation, and response procedures.
  • Lead tabletop exercises to validate response processes, escalation paths, communication workflows, analyst readiness, and cross functional coordination.
  • Identify training gaps and provide training, mentoring, and knowledge sharing to junior team members to strengthen investigative quality, technical capability, and operational consistency across the ESOC.
  • Create, maintain, and improve incident response playbooks, forensic investigation guides, case templates, escalation procedures, and operational documentation.
  • Support threat hunting and proactive analysis efforts based on observed incidents, emerging threats, forensic findings, and enterprise risk priorities.
  • Contribute to ESOC continuous improvement initiatives, including AI and automation, case management improvements, workflow refinement, documentation, and operational reporting.
  • Support the ESOC’s 24/7/365 operational needs as required to maintain continuity of coverage during high priority incidents or elevated tempo events.
  • Perform additional duties and support other operational tasks as assigned to meet mission and organizational needs.
Qualifications
Education & Experience:
  • Bachelor’s degree and 5+ years of related experience; master’s degree and 3+ years of related experience. An additional 4+ years of experience may be considered in lieu of a degree.
  • 3+ years of cybersecurity operations experience supporting enterprise security monitoring, incident response, forensic analysis, or cyber investigations.
    • Must have hands on experience working with enterprise SIEM technologies, preferably Splunk.
    • Must have hands on experience using EDR or endpoint security platforms to investigate suspicious activity, endpoint behavior, malware, account compromise, and incident scope.
  • Must possess one of the following certifications:
    • CySA+, SSCP, or equivalent.
Required Skills:
  • Strong leadership skills with a proven ability to lead and motivate a team effectively.
  • Can-do attitude.
  • Self-motivated and quick learner.
  • Excellent verbal and written communication skills.
  • Ability to multitask and collaborate to solve complex technical problems.
  • US Citizenship is required.
Desirables:
  • One or more of the following certifications.
    • ISC2, Certified Information Systems Security Professional, CISSP.
    • GIAC, Certified Incident Handler, GCIH.
    • GIAC, Certified Forensic Analyst, GCFA.

Target salary range: $80,001 - $120,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

Saic • Washington

Hybrid
USD 120,000 - 160,000
Health insurance
Senior Cybersecurity Ops Lead - Remote Ready
Senior Cybersecurity Ops Lead - Remote Ready

Saic • Tennessee

Hybrid
USD 80,000 - 120,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Ampcus Inc • Washington

On-site
USD 90,000 - 120,000
Security Operations Center Analyst
Security Operations Center Analyst

Seneca Resources • Huntsville (AL)

On-site
USD 132,000 - 148,000
Competitive pay
Comprehensive benefits including health, dental, and vision
401(k) plan
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Security Operations Analyst – Senior
Security Operations Analyst – Senior

C3EL • Washington

On-site
USD 95,000 - 125,000
Senior Cybersecurity Operations Analyst 23-E-15
Senior Cybersecurity Operations Analyst 23-E-15

Illinois Attorney General (IL) • Chicago (IL)

On-site
USD 120,000 - 160,000
Senior Security Analyst
Senior Security Analyst

Yardi • Santa Barbara (CA)

On-site
USD 97,000 - 110,000
Sr. Cyber Defense Analyst
Sr. Cyber Defense Analyst

Patriot Talent Solutions • United States

On-site
USD 120,000 - 190,000