Seeking experienced security operations professionals to join a leading cybersecurity and enterprise security firm as a Security Operations Analyst, supporting organization-wide threat detection, incident response, and security monitoring for cloud and hybrid environments. This role offers a dynamic environment focused on operational excellence, team mentorship, and continuous security improvement.
Role Overview
This position entails managing security operations on a shift basis, investigating security events, coordinating incident escalations, and fostering team development within a high-volume security operations center. The Security Operations Analyst will play a critical role in maintaining security posture, enhancing detection capabilities, and ensuring compliance with industry standards such as FedRAMP.
Key Responsibilities
- Serve as a senior analyst on shift, independently overseeing security operations, identifying threats, managing escalations, and supporting incident response efforts.
- Investigate security alerts and events using SIEM platforms, cloud security tools, and network monitoring systems; perform root cause analysis and recommend preventive measures.
- Make informed escalation decisions to contain threats, monitor ongoing incidents, or escalate to senior team members, leadership, or external stakeholders.
- Document security incidents accurately, maintain shift logs, update runbooks, and ensure clear communication during handoffs to team members.
- Monitor enterprise and cloud environments for malicious activity, suspicious behaviors, vulnerabilities, and operational issues using tools like Security Information and Event Management (SIEM), Cloud Security Posture Management (CSPM), and Endpoint Detection and Response (EDR).
- Collaborate with team members to identify opportunities for improving detection rules, alert accuracy, escalation procedures, and incident response processes.
- Contribute to incident review meetings, security operations process improvements, and compliance documentation such as FedRAMP evidence.
- Provide mentorship to junior analysts, fostering skill development in troubleshooting, threat analysis, and operational decision-making.
- Support shift leadership by establishing escalation standards, developing operational best practices, and promoting team growth.
Core Qualifications & Requirements
- Minimum of 3 years experience in security operations, incident response, or network operations within a Security Operations Center (SOC), Network Operations Center (NOC), or similar environment.
- Proven experience investigating security alerts, managing escalations, and coordinating incident response efforts in enterprise or cloud environments.
- Strong incident triage, escalation judgment, and decision-making skills.
- Hands-on experience with security monitoring tools, SIEM (ArcSight, Splunk, QRadar), EDR solutions, cloud security platforms (AWS Security Hub, Azure Security Center), and network security protocols.
- Knowledge of security frameworks (NIST, CIS Controls), security protocols, and operational procedures.
- Excellent documentation skills, including maintaining incident records, operational logs, handoff reports, and runbooks.
- Ability to mentor junior team members and foster a collaborative learning environment.
- Relevant certifications such as Security+ (CompTIA), CySA+, SSCP, or equivalent are preferred.
- Ability to obtain U.S. citizenship and pass government background checks due to federal client engagement.
Nice-to-Have Qualifications
- Five or more years of security operations experience, including shift leadership and detection engineering.
- Previous experience developing detection rules, security automation, or threat hunting capabilities.
- Knowledge of FedRAMP compliance processes and federal security standards.
- Experience with security orchestration, automation, and response (SOAR) platforms.
Core Technical Skills
- Cloud Security Platforms: AWS Security Hub, Azure Security Center, GCP Security (Security Command Center)
- Endpoint Detection and Response (EDR): CrowdStrike, Carbon Black, Defender ATP
- Security Frameworks & Standards: NIST, CIS, FedRAMP requirements
- Network Security: Firewalls, IDS/IPS, VPNs, VPNs, TCP/IP protocols
- Incident Response & Forensics: Root cause analysis, threat containment, evidence collection