Security Operations Analyst

NextGenEnergyJobs

Vienna, Northern (VA, KY)

Hybrid

USD 90,000 - 140,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health benefits
401(k) and profit-sharing
Paid holidays
Vacation leave

Job summary

NextGenEnergyJobs is seeking an Enterprise Security Analyst II to join our hands-on SOC team in Virginia. You will monitor alerts across endpoints, identity, network, cloud and email environments, triage incidents, and support full incident response lifecycle from investigation to closure.

The role requires 2+ years of cybersecurity experience, strong telemetry analysis, and the ability to communicate findings clearly to technical and non-technical audiences. U.S.

Qualifications

  • 2+ years of cybersecurity experience in security monitoring, alert triage, and incident investigation.
  • Experience analyzing endpoint, identity, network, cloud, email, and log data.
  • Knowledge of SIEM and EDR platforms.
  • Understanding of networking, OS, identity concepts, cloud security.
  • Ability to write investigation notes and recommendations for technical and non-technical audiences.
  • U.S. citizenship is mandatory.
  • Ability to obtain security clearance.
  • Experience converting threat intelligence into detections, hunts, playbooks, response actions, or mitigation recommendations.
  • Familiarity with scripting and query languages (PowerShell, Python, KQL, SPL).

Responsibilities

  • Security Operations and Incident Response
  • Monitor and manage the SOC alert queue across endpoint, identity, network, email, cloud, and log monitoring platforms
  • Independently triage and investigate security alerts and events, distinguishing confirmed threats from benign activity using available evidence and telemetry
  • Support the full incident lifecycle, including investigation, escalation, containment support, remediation follow-up, documentation, and closure
  • Escalate incidents with clear evidence, impact assessment, and recommended next steps
  • Apply playbooks and runbooks while identifying opportunities to improve alert quality, response consistency, automation, and analyst enablement
  • Threat Intelligence and Threat Hunting
  • Analyze relevant threat intelligence to identify threats, campaigns, vulnerabilities, and adversary behaviors that may affect the organization
  • Enrich alerts and investigations with context about threat actors, malware, indicators, vulnerabilities, and attack techniques
  • Assist with threat hunts across endpoint, identity, network, cloud, and application telemetry
  • Use MITRE ATT&CK to support investigations, communicate adversary behavior, and identify detection gaps
  • Partner with security engineers and analysts to turn relevant intelligence into detections, hunts, watchlists, playbooks, blocking recommendations, or response improvements

Skills

Cybersecurity experience
Incident investigation
Threat hunting
Telemetry analysis

Education

Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related STEM

Tools

SIEM platforms
EDR platforms
SOAR familiarity
PowerShell scripting

Job description

The Enterprise Security Analyst II is a hands-on Security Operations Center (SOC) role responsible for monitoring alerts, investigating security events, supporting incident response, and improving security operations.

Key Responsibilities
  • Security Operations and Incident Response
  • Monitor and manage the SOC alert queue across endpoint, identity, network, email, cloud, and log monitoring platforms
  • Independently triage and investigate security alerts and events, distinguishing confirmed threats from benign activity using available evidence and telemetry
  • Support the full incident lifecycle, including investigation, escalation, containment support, remediation follow-up, documentation, and closure
  • Escalate incidents with clear evidence, impact assessment, and recommended next steps
  • Apply playbooks and runbooks while identifying opportunities to improve alert quality, response consistency, automation, and analyst enablement
  • Threat Intelligence and Threat Hunting
  • Analyze relevant threat intelligence to identify threats, campaigns, vulnerabilities, and adversary behaviors that may affect the organization
  • Enrich alerts and investigations with context about threat actors, malware, indicators, vulnerabilities, and attack techniques
  • Assist with threat hunts across endpoint, identity, network, cloud, and application telemetry
  • Use MITRE ATT&CK to support investigations, communicate adversary behavior, and identify detection gaps
  • Partner with security engineers and analysts to turn relevant intelligence into detections, hunts, watchlists, playbooks, blocking recommendations, or response improvements
Requirements
  • 2+ years of cybersecurity experience with hands-on involvement in security monitoring, alert triage, and incident investigation
  • Experience analyzing endpoint, identity, network, cloud, email, and log data to identify suspicious or malicious activity
  • Working knowledge of SIEM and EDR platforms, common triage workflows, and security telemetry analysis
  • Strong understanding of networking, operating systems, identity and access concepts, cloud security fundamentals, and core security protocols
  • Working knowledge of cyber threat intelligence concepts, including indicators, threat actors, campaigns, vulnerabilities, and adversary tactics, techniques, and procedures
  • Ability to write clear investigation notes, incident records, intelligence summaries, and recommendations for technical and non-technical audiences
  • U.S. citizenship is mandatory
  • Ability and willingness to obtain security clearance
  • Bachelors in Cybersecurity, Information Technology, Computer Science, or a related STEM degree
  • Experience performing threat intelligence analysis, threat hunting, incident response, or security engineering in an enterprise environment
  • Experience converting threat intelligence into detections, hunts, watchlists, playbooks, response actions, or mitigation recommendations
  • Experience researching threat actors, malware, ransomware activity, vulnerability exploitation, or emerging attack techniques
  • Familiarity with SOAR platforms, detection engineering practices, automation, scripting, or query languages such as PowerShell, Python, KQL, or SPL
  • Relevant certifications such as CompTIA Security+, GCIH, GCED, GCIA, GCFA, GCTI, CTIA, or Microsoft security certifications
  • #LI-TM1
  • #LI-onsite
  • Esri’s competitive total rewards strategy includes industry-leading health and welfare benefits: medical, dental, vision, basic and supplemental life insurance for employees (and their families), 401(k) and profit-sharing programs, minimum accrual of 80 hours of vacation leave, twelve paid holidays throughout the calendar year, and opportunities for personal and professional growth. Base salary is one component of our total rewards strategy. Compensation decisions and the base range for this role take into account many factors including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs.
  • A reasonable estimate of the base salary range is
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

Hybrid
USD 97,000 - 110,000
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
Technical Consultant- Cyber Security Engineering
Technical Consultant- Cyber Security Engineering

NextGenEnergyJobs • Vienna (VA), Northern (KY)

Hybrid
USD 110,000 - 160,000
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

Hybrid
USD 80,000 - 110,000
System Engineer- Cyber Security Engineering Focus
System Engineer- Cyber Security Engineering Focus

NextGenEnergyJobs • Vienna (VA), Northern (KY)

Hybrid
USD 120,000 - 170,000
Health benefits
401(k) plan
Profit sharing
+1
Analyst, Security
Analyst, Security

Southern Star Central Gas Pipeline • Owensboro (KY)

On-site
USD 70,000 - 110,000
Medical
Vision
Dental
+7
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

10xTalents • Washington

On-site
USD 80,000 - 110,000
Sr Information Security Analyst
Sr Information Security Analyst

Scorpion Therapeutics • Michigan

Hybrid
USD 120,000 - 180,000
Hybrid work two days from home
Career development opportunities
Information Security Analyst
Information Security Analyst

NPAworldwide • City of Syracuse (NY)

On-site
USD 85,000 - 90,000