Security Operations Analyst

The Phoenix Group®

Arlington (VA)

On-site

USD 90,000 - 130,000

Full time

9 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

The Phoenix Group is seeking an experienced Security Operations Analyst in Arlington, VA to support threat detection, incident response, and security monitoring across cloud and hybrid environments.

You will lead on-shift activities, investigate alerts with SIEM and EDR tools, and mentor junior analysts while ensuring disciplined handoffs and runbook updates. Federal client work requires strong compliance discipline.

Qualifications

  • Minimum of 3 years experience in security operations, incident response, or network operations within a SOC/NOC or similar environment.
  • Proven experience investigating security alerts, managing escalations, and coordinating incident response efforts in enterprise or cloud environments.
  • Strong incident triage, escalation judgment, and decision-making skills.
  • Hands-on experience with SIEMs (ArcSight, Splunk, QRadar), EDR solutions, cloud security platforms (AWS Security Hub, Azure Security Center), and network security protocols.
  • Knowledge of security frameworks (NIST, CIS Controls), security protocols, and operational procedures.
  • Excellent documentation skills, including maintaining incident records and runbooks.
  • Ability to mentor junior team members and foster collaboration.
  • Security+ (CompTIA), CySA+, SSCP or equivalent preferred.

Responsibilities

  • Serve as a senior analyst on shift, overseeing security operations, identifying threats, managing escalations, and supporting incident response.
  • Investigate security alerts using SIEM, CSPM, EDR, and cloud tools; perform root cause analysis and recommend preventive measures.
  • Make escalation decisions to contain threats, monitor incidents, and coordinate with leadership or external stakeholders.
  • Document incidents, maintain shift logs, update runbooks, and communicate clearly during handoffs.
  • Monitor enterprise and cloud environments for malicious activity and vulnerabilities using SIEM, CSPM, and EDR tools.
  • Collaborate to improve detection rules, alert accuracy, escalation procedures, and incident response processes.
  • Contribute to incident reviews and FedRAMP evidence; provide mentorship to junior analysts.

Skills

Security operations
Incident response
Mentoring
Documentation
Team leadership

Tools

ArcSight
Splunk
QRadar
AWS Security Hub
Azure Security Center
Defender ATP
CrowdStrike
Carbon Black

Job description

Seeking experienced security operations professionals to join a leading cybersecurity and enterprise security firm as a Security Operations Analyst, supporting organization-wide threat detection, incident response, and security monitoring for cloud and hybrid environments. This role offers a dynamic environment focused on operational excellence, team mentorship, and continuous security improvement.

Role Overview

This position entails managing security operations on a shift basis, investigating security events, coordinating incident escalations, and fostering team development within a high-volume security operations center. The Security Operations Analyst will play a critical role in maintaining security posture, enhancing detection capabilities, and ensuring compliance with industry standards such as FedRAMP.

Key Responsibilities
  • Serve as a senior analyst on shift, independently overseeing security operations, identifying threats, managing escalations, and supporting incident response efforts.
  • Investigate security alerts and events using SIEM platforms, cloud security tools, and network monitoring systems; perform root cause analysis and recommend preventive measures.
  • Make informed escalation decisions to contain threats, monitor ongoing incidents, or elevate to senior team members, leadership, or external stakeholders.
  • Document security incidents accurately, maintain shift logs, update runbooks, and ensure clear communication during handoffs to team members.
  • Monitor enterprise and cloud environments for malicious activity, suspicious behaviours, vulnerabilities, and operational issues using tools like Security Information and Event Management (SIEM), Cloud Security Posture Management (CSPM), and Endpoint Detection and Response (EDR).
  • Collaborate with team members to identify opportunities for improving detection rules, alert accuracy, escalation procedures, and incident response processes.
  • Contribute to incident review meetings, security operations process improvements, and compliance documentation such as FedRAMP evidence.
  • Provide mentorship to junior analysts, fostering skill development in troubleshooting, threat analysis, and operational decision-making.
  • Support shift leadership by establishing escalation standards, developing operational best practices, and promoting team growth.
Core Qualifications & Requirements
  • Minimum of 3 years experience in security operations, incident response, or network operations within a Security Operations Center (SOC), Network Operations Center (NOC), or similar environment.
  • Proven experience investigating security alerts, managing escalations, and coordinating incident response efforts in enterprise or cloud environments.
  • Strong incident triage, escalation judgment, and decision-making skills.
  • Hands-on experience with security monitoring tools, SIEM (ArcSight, Splunk, QRadar), EDR solutions, cloud security platforms (AWS Security Hub, Azure Security Center), and network security protocols.
  • Knowledge of security frameworks (NIST, CIS Controls), security protocols, and operational procedures.
  • Excellent documentation skills, including maintaining incident records, operational logs, handoff reports, and runbooks.
  • Ability to mentor junior team members and foster a collaborative learning environment.
  • Relevant certifications such as Security+ (CompTIA), CySA+, SSCP, or equivalent are preferred.
  • Ability to obtain U.S. citizenship and pass government background checks due to federal client engagement.
Nice-to-Have Qualifications
  • Five or more years of security operations experience, including shift leadership and detection engineering.
  • Previous experience developing detection rules, security automation, or threat hunting capabilities.
  • Knowledge of FedRAMP compliance processes and federal security standards.
  • Experience with security orchestration, automation, and response (SOAR) platforms.
Core Technical Skills
  • SIEM & Log Management: Splunk, ArcSight, QRadar, LogRhythm
  • Cloud Security Platforms: AWS Security Hub, Azure Security Center, GCP Security (Security Command Center)
  • Endpoint Detection and Response (EDR): CrowdStrike, Carbon Black, Defender ATP
  • Security Frameworks & Standards: NIST, CIS, FedRAMP requirements
  • Network Security: Firewalls, IDS/IPS, VPNs, VPNs, TCP/IP protocols
  • Incident Response & Forensics: Root cause analysis, threat containment, evidence collection
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Operations Analyst
Security Operations Analyst

The Phoenix Group • Arlington (VA)

On-site
USD 90,000 - 120,000
Security Operations Lead
Security Operations Lead

The Phoenix Group • Washington

On-site
USD 140,000 - 190,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

On-site
USD 80,000 - 110,000
Senior Security Operations Analyst
Senior Security Operations Analyst

Prosegur Security USA, Inc • Lowell (MA), Northern (KY)

Hybrid
USD 90,000 - 140,000
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

10xTalents • Washington

On-site
USD 80,000 - 110,000
Cybersecurity Analyst
Cybersecurity Analyst

Remote Jobs • New York (NY)

Remote
USD 90,000 - 140,000
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000
Information Systems Security Professional
Information Systems Security Professional

Vytwo • Dallas (TX)

Hybrid
USD 120,000 - 180,000
Manager
Manager

Apexcare Talent Solutions • Berkeley (CA)

On-site
USD 140,000 - 175,000
Health insurance
Dental insurance
Vision insurance
+4