Security Operations Analyst

Esri

Redlands (CA)

On-site

USD 70,000 - 114,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical insurance
Dental insurance
Vision insurance
Life insurance
401(k) plan
Paid vacation
Paid holidays

Job summary

Esri is seeking an Enterprise Security Analyst II to join the Security Operations Center, focusing on monitoring, investigating, and responding to security events. You will apply threat intelligence and conduct threat hunting to enhance detections and response capabilities.

The role emphasizes hand-on security monitoring across endpoints, identity, network, cloud, and email, along with on-call rotation after onboarding and demonstrated familiarity with the tools and response procedures.

Qualifications

  • 2+ years of cybersecurity experience with hands-on involvement in security monitoring, alert triage, and incident investigation.
  • Experience analyzing endpoint, identity, network, cloud, email, and log data to identify suspicious or malicious activity.
  • Working knowledge of SIEM and EDR platforms, common triage workflows, and security telemetry analysis.
  • Strong understanding of networking, operating systems, identity and access concepts, cloud security fundamentals, and core security protocols.
  • Working knowledge of cyber threat intelligence concepts, including indicators, threat actors, campaigns, vulnerabilities, and adversary tactics, techniques, and procedures.
  • Ability to write clear investigation notes, incident records, intelligence summaries, and recommendations for technical and non-technical audiences.
  • U.S. citizenship is mandatory
  • Ability and willingness to obtain security clearance
  • Bachelors in Cybersecurity, Information Technology, Computer Science, or a related STEM degree

Responsibilities

  • Monitor and manage the SOC alert queue across endpoint, identity, network, email, cloud, and log monitoring platforms.
  • Independently triage and investigate security alerts and events, distinguishing confirmed threats from benign activity using available evidence and telemetry.
  • Support the full incident lifecycle, including investigation, escalation, containment support, remediation follow-up, documentation, and closure.
  • Escalate incidents with clear evidence, impact assessment, and recommended next steps.
  • Apply playbooks and runbooks while identifying opportunities to improve alert quality, response consistency, automation, and analyst enablement.
  • Analyze relevant threat intelligence to identify threats, campaigns, vulnerabilities, and adversary behaviors that may affect the organization.
  • Enrich alerts and investigations with context about threat actors, malware, indicators, vulnerabilities, and attack techniques.
  • Assist with threat hunts across endpoint, identity, network, cloud, and application telemetry.
  • Use MITRE ATT&CK to support investigations, communicate adversary behavior, and identify detection gaps.
  • Partner with security engineers and analysts to turn relevant intelligence into detections, hunts, watchlists, playbooks, blocking recommendations, or response improvements.

Skills

SOC monitoring
Incident investigation
Threat intelligence
Threat hunting
MITRE ATT&CK
SIEM
EDR
Networking basics
Cloud security
On-call readiness
U.S. citizenship

Education

Bachelors in Cybersecurity, IT, CS, or related STEM

Tools

SIEM
EDR
SOAR Platforms
PowerShell
Python
KQL
SPL

Job description

Overview

The Enterprise Security Analyst II is a hands‑on Security Operations Center (SOC) role responsible for monitoring alerts, investigating security events, supporting incident response, and improving security operations. This role also applies cyber threat intelligence and threat hunting practices to add context to investigations, identify emerging threats, and strengthen detection and response capabilities. Primary schedule is business hours, Monday through Friday. Participation in an after‑hours on‑call rotation is expected after onboarding and demonstrated familiarity with systems, tools, and response procedures.

Responsibilities
Security Operations and Incident Response
  • Monitor and manage the SOC alert queue across endpoint, identity, network, email, cloud, and log monitoring platforms
  • Independently triage and investigate security alerts and events, distinguishing confirmed threats from benign activity using available evidence and telemetry
  • Support the full incident lifecycle, including investigation, escalation, containment support, remediation follow‑up, documentation, and closure
  • Escalate incidents with clear evidence, impact assessment, and recommended next steps
  • Apply playbooks and runbooks while identifying opportunities to improve alert quality, response consistency, automation, and analyst enablement
Threat Intelligence and Threat Hunting
  • Analyze relevant threat intelligence to identify threats, campaigns, vulnerabilities, and adversary behaviors that may affect the organization
  • Enrich alerts and investigations with context about threat actors, malware, indicators, vulnerabilities, and attack techniques
  • Assist with threat hunts across endpoint, identity, network, cloud, and application telemetry
  • Use MITRE ATT&CK to support investigations, communicate adversary behavior, and identify detection gaps
  • Partner with security engineers and analysts to turn relevant intelligence into detections, hunts, watchlists, playbooks, blocking recommendations, or response improvements
Requirements
  • 2+ years of cybersecurity experience with hands‑on involvement in security monitoring, alert triage, and incident investigation
  • Experience analyzing endpoint, identity, network, cloud, email, and log data to identify suspicious or malicious activity
  • Working knowledge of SIEM and EDR platforms, common triage workflows, and security telemetry analysis
  • Strong understanding of networking, operating systems, identity and access concepts, cloud security fundamentals, and core security protocols
  • Working knowledge of cyber threat intelligence concepts, including indicators, threat actors, campaigns, vulnerabilities, and adversary tactics, techniques, and procedures
  • Ability to write clear investigation notes, incident records, intelligence summaries, and recommendations for technical and non‑technical audiences
  • U.S. citizenship is mandatory
  • Ability and willingness to obtain security clearance
  • Bachelors in Cybersecurity, Information Technology, Computer Science, or a related STEM degree
Recommended Qualifications
  • Experience performing threat intelligence analysis, threat hunting, incident response, or security engineering in an enterprise environment
  • Experience converting threat intelligence into detections, hunts, watchlists, playbooks, response actions, or mitigation recommendations
  • Experience researching threat actors, malware, ransomware activity, vulnerability exploitation, or emerging attack techniques
  • Familiarity with SOAR platforms, detection engineering practices, automation, scripting, or query languages such as PowerShell, Python, KQL, or SPL
  • Relevant certifications such as CompTIA Security+, GCIH, GCED, GCIA, GCFA, GCTI, CTIA, or Microsoft security certifications
Total Rewards

Esri’s competitive total rewards strategy includes industry‑leading health and welfare benefits:

  • medical
  • dental
  • vision
  • basic and supplemental life insurance for employees (and their families)
  • 401(k) and profit‑sharing programs
  • minimum accrual of 80 hours of vacation leave
  • twelve paid holidays throughout the calendar year
  • opportunities for personal and professional growth

Base salary is one component of our total rewards strategy. Compensation decisions and the base range for this role take into account many factors including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs.

A reasonable estimate of the base salary range is

$70,304 — $114,400 USD

The Company

At Esri, diversity is more than just a word on a map. When employees of different experiences, perspectives, backgrounds, and cultures come together, we are more innovative and ultimately a better place to work. We believe in having a diverse workforce that is unified under our mission of creating positive global change. We understand that diversity, equity, and inclusion is not a destination but an ongoing process. We are committed to the continuation of learning, growing, and changing our workplace so every employee can contribute to their life’s best work. Our commitment to these principles extends to the global communities we serve by creating positive change with GIS technology. For more information on Esri’s Racial Equity and Social Justice initiatives, please visit our website here.

Esri is an equal opportunity employer (EOE) and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability status, protected veteran status, or any other characteristic protected by law. If you need reasonable accommodation for any part of the employment process, please email askcareers@esri.com and let us know the nature of your request and your contact information. Please note that only those inquiries concerning a request for reasonable accommodation will be responded to from this e‑mail address.

Esri Privacy Esri takes our responsibility to protect your privacy seriously. We are committed to respecting your privacy by providing transparency in how we acquire and use your information, giving you control of your information and preferences, and holding ourselves to the highest national and international standards, including CCPA and GDPR compliance.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Analyst
Security Operations Analyst

Esri • Vienna (VA)

On-site
USD 70,000 - 114,000
Medical
Dental
Vision
+3
Security Operations Analyst
Security Operations Analyst

Esri • Town of Vienna (WI)

On-site
USD 70,000 - 114,000
Health Insurance
401(k)
Paid Holidays
Sr. Systems Engineer
Sr. Systems Engineer

Esri • Town of Vienna (WI)

On-site
USD 81,000 - 166,000
Medical insurance
Dental insurance
Vision insurance
+5
System Engineer- Cyber Security Engineering Focus
System Engineer- Cyber Security Engineering Focus

Esri • St. Louis (MO)

On-site
USD 121,000 - 198,000
Relocation assistance
DevOps Systems Engineer
DevOps Systems Engineer

Esri • Redlands (CA)

On-site
USD 70,000 - 123,000
Medical
Dental
Vision
+3
Sr. Systems Engineer
Sr. Systems Engineer

ESRI • Vienna (VA)

On-site
USD 81,000 - 166,000
Sr. Application Security Engineer
Sr. Application Security Engineer

Esri • Redlands (CA)

On-site
USD 93,600 - 157,560
Health and welfare benefits
401(k) and profit-sharing programs
Minimum accrual of 80 hours of vacation
+1
Sr. Application Security Engineer
Sr. Application Security Engineer

Esri • Town of Vienna (WI)

On-site
USD 94,000 - 158,000
Sr. Software Development Engineer – National Imagery
Sr. Software Development Engineer – National Imagery

Esri • Town of Vienna (WI)

On-site
USD 123,000 - 202,000
Sr. Application Security Engineer
Sr. Application Security Engineer

ESRI • Vienna (VA)

On-site
USD 94,000 - 158,000