Security Operations Analyst

The Phoenix Group

Arlington (VA)

On-site

USD 90,000 - 120,000

Full time

11 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

The Phoenix Group is seeking an experienced Security Operations Analyst to join our security operations center in Arlington, VA. You will monitor cloud and hybrid environments, lead incident response efforts, and drive continuous improvement in detection and alerting.

You will mentor junior analysts, coordinate escalations, and document incidents and runbooks to support FedRAMP-compliant operations and enterprise security posture.

Qualifications

  • 3+ years in security operations, SOC/NOC or similar environments.
  • Experience investigating alerts, managing escalations, and coordinating incident response in enterprise or cloud.
  • Certifications such as Security+ (CompTIA), CySA+, SSCP preferred.

Responsibilities

  • Serve as a senior analyst on shift, overseeing security operations, threats, escalations, and incident response.
  • Investigate alerts and events using SIEM, cloud tools, and network monitoring; perform root cause analysis.
  • Make informed escalation decisions to contain threats and coordinate with stakeholders.
  • Document security incidents, maintain shift logs, update runbooks, and ensure clear handoffs.
  • Monitor enterprise and cloud environments for malicious activity using SIEM, CSPM, and EDR tools.
  • Collaborate to improve detection rules, alert accuracy, escalation procedures, and incident response."
  • Contribute to incident reviews, security process improvements, and FedRAMP evidence documentation.
  • Mentor junior analysts and build team capability in troubleshooting and threat analysis.
  • Support shift leadership by developing escalation standards and operational best practices.

Skills

Incident response
Threat detection
Escalation decisions
Mentoring teammates
Documentation

Education

Security+ (CompTIA)
CySA+
SSCP

Tools

ArcSight
Splunk
QRadar
CrowdStrike
Carbon Black
Defender ATP
AWS Security Hub
Azure Security Center
GCP Security Command Center
SOAR platforms

Job description

Seeking experienced security operations professionals to join a leading cybersecurity and enterprise security firm as a Security Operations Analyst, supporting organization-wide threat detection, incident response, and security monitoring for cloud and hybrid environments. This role offers a dynamic environment focused on operational excellence, team mentorship, and continuous security improvement.

Role Overview

This position entails managing security operations on a shift basis, investigating security events, coordinating incident escalations, and fostering team development within a high-volume security operations center. The Security Operations Analyst will play a critical role in maintaining security posture, enhancing detection capabilities, and ensuring compliance with industry standards such as FedRAMP.

Key Responsibilities
  • Serve as a senior analyst on shift, independently overseeing security operations, identifying threats, managing escalations, and supporting incident response efforts.
  • Investigate security alerts and events using SIEM platforms, cloud security tools, and network monitoring systems; perform root cause analysis and recommend preventive measures.
  • Make informed escalation decisions to contain threats, monitor ongoing incidents, or escalate to senior team members, leadership, or external stakeholders.
  • Document security incidents accurately, maintain shift logs, update runbooks, and ensure clear communication during handoffs to team members.
  • Monitor enterprise and cloud environments for malicious activity, suspicious behaviors, vulnerabilities, and operational issues using tools like Security Information and Event Management (SIEM), Cloud Security Posture Management (CSPM), and Endpoint Detection and Response (EDR).
  • Collaborate with team members to identify opportunities for improving detection rules, alert accuracy, escalation procedures, and incident response processes.
  • Contribute to incident review meetings, security operations process improvements, and compliance documentation such as FedRAMP evidence.
  • Provide mentorship to junior analysts, fostering skill development in troubleshooting, threat analysis, and operational decision-making.
  • Support shift leadership by establishing escalation standards, developing operational best practices, and promoting team growth.
Core Qualifications & Requirements
  • Minimum of 3 years experience in security operations, incident response, or network operations within a Security Operations Center (SOC), Network Operations Center (NOC), or similar environment.
  • Proven experience investigating security alerts, managing escalations, and coordinating incident response efforts in enterprise or cloud environments.
  • Strong incident triage, escalation judgment, and decision-making skills.
  • Hands-on experience with security monitoring tools, SIEM (ArcSight, Splunk, QRadar), EDR solutions, cloud security platforms (AWS Security Hub, Azure Security Center), and network security protocols.
  • Knowledge of security frameworks (NIST, CIS Controls), security protocols, and operational procedures.
  • Excellent documentation skills, including maintaining incident records, operational logs, handoff reports, and runbooks.
  • Ability to mentor junior team members and foster a collaborative learning environment.
  • Relevant certifications such as Security+ (CompTIA), CySA+, SSCP, or equivalent are preferred.
  • Ability to obtain U.S. citizenship and pass government background checks due to federal client engagement.
Nice-to-Have Qualifications
  • Five or more years of security operations experience, including shift leadership and detection engineering.
  • Previous experience developing detection rules, security automation, or threat hunting capabilities.
  • Knowledge of FedRAMP compliance processes and federal security standards.
  • Experience with security orchestration, automation, and response (SOAR) platforms.
Core Technical Skills
  • Cloud Security Platforms: AWS Security Hub, Azure Security Center, GCP Security (Security Command Center)
  • Endpoint Detection and Response (EDR): CrowdStrike, Carbon Black, Defender ATP
  • Security Frameworks & Standards: NIST, CIS, FedRAMP requirements
  • Network Security: Firewalls, IDS/IPS, VPNs, VPNs, TCP/IP protocols
  • Incident Response & Forensics: Root cause analysis, threat containment, evidence collection
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Operations Analyst
Senior Security Operations Analyst

Prosegur Security USA, Inc • Lowell (MA), Northern (KY)

Hybrid
USD 90,000 - 140,000
Security Operations Lead
Security Operations Lead

The Phoenix Group • Washington

On-site
USD 140,000 - 190,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Security Operations Analyst – Senior
Security Operations Analyst – Senior

C3EL • Washington

On-site
USD 95,000 - 125,000
Security Analyst II
Security Analyst II

Gilder Search Group • Cleveland (OH)

On-site
USD 70,000 - 100,000
Senior Security Operations Analyst
Senior Security Operations Analyst

Saronic • San Diego (CA), Austin (TX)

On-site
USD 90,000 - 120,000
Network Security Analyst
Network Security Analyst

vTech Solution • Washington

On-site
USD 75,000 - 110,000
Information Security Analyst
Information Security Analyst

Cisive Inc. • Maryland

On-site
USD 90,000 - 130,000
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

10xTalents • Washington

On-site
USD 80,000 - 110,000
Information Security Analyst
Information Security Analyst

Cobalt Benefits Group LLC • Manchester (NH)

On-site
USD 85,000 - 110,000