Security Operations Pro: Threat Hunting & Incident Response

Esri

Redlands (CA)

On-site

USD 70,000 - 114,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical insurance
Dental insurance
Vision insurance
Life insurance
401(k) plan
Paid vacation
Paid holidays

Job summary

Esri is seeking an Enterprise Security Analyst II to join the Security Operations Center, focusing on monitoring, investigating, and responding to security events. You will apply threat intelligence and conduct threat hunting to enhance detections and response capabilities.

The role emphasizes hand-on security monitoring across endpoints, identity, network, cloud, and email, along with on-call rotation after onboarding and demonstrated familiarity with the tools and response procedures.

Qualifications

  • 2+ years of cybersecurity experience with hands-on involvement in security monitoring, alert triage, and incident investigation.
  • Experience analyzing endpoint, identity, network, cloud, email, and log data to identify suspicious or malicious activity.
  • Working knowledge of SIEM and EDR platforms, common triage workflows, and security telemetry analysis.
  • Strong understanding of networking, operating systems, identity and access concepts, cloud security fundamentals, and core security protocols.
  • Working knowledge of cyber threat intelligence concepts, including indicators, threat actors, campaigns, vulnerabilities, and adversary tactics, techniques, and procedures.
  • Ability to write clear investigation notes, incident records, intelligence summaries, and recommendations for technical and non-technical audiences.
  • U.S. citizenship is mandatory
  • Ability and willingness to obtain security clearance
  • Bachelors in Cybersecurity, Information Technology, Computer Science, or a related STEM degree

Responsibilities

  • Monitor and manage the SOC alert queue across endpoint, identity, network, email, cloud, and log monitoring platforms.
  • Independently triage and investigate security alerts and events, distinguishing confirmed threats from benign activity using available evidence and telemetry.
  • Support the full incident lifecycle, including investigation, escalation, containment support, remediation follow-up, documentation, and closure.
  • Escalate incidents with clear evidence, impact assessment, and recommended next steps.
  • Apply playbooks and runbooks while identifying opportunities to improve alert quality, response consistency, automation, and analyst enablement.
  • Analyze relevant threat intelligence to identify threats, campaigns, vulnerabilities, and adversary behaviors that may affect the organization.
  • Enrich alerts and investigations with context about threat actors, malware, indicators, vulnerabilities, and attack techniques.
  • Assist with threat hunts across endpoint, identity, network, cloud, and application telemetry.
  • Use MITRE ATT&CK to support investigations, communicate adversary behavior, and identify detection gaps.
  • Partner with security engineers and analysts to turn relevant intelligence into detections, hunts, watchlists, playbooks, blocking recommendations, or response improvements.

Skills

SOC monitoring
Incident investigation
Threat intelligence
Threat hunting
MITRE ATT&CK
SIEM
EDR
Networking basics
Cloud security
On-call readiness
U.S. citizenship

Education

Bachelors in Cybersecurity, IT, CS, or related STEM

Tools

SIEM
EDR
SOAR Platforms
PowerShell
Python
KQL
SPL

Job description

Esri is seeking an Enterprise Security Analyst II to join the Security Operations Center, focusing on monitoring, investigating, and responding to security events. You will apply threat intelligence and conduct threat hunting to enhance detections and response capabilities.

The role emphasizes hand-on security monitoring across endpoints, identity, network, cloud, and email, along with on-call rotation after onboarding and demonstrated familiarity with the tools and response procedures.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations & Threat Hunting Analyst
Security Operations & Threat Hunting Analyst

Esri • Vienna (VA)

On-site
USD 70,000 - 114,000
Medical
Dental
Vision
+3
Security Operations Analyst II: Threat Intel & IR
Security Operations Analyst II: Threat Intel & IR

Esri • Town of Vienna (WI)

On-site
USD 70,000 - 114,000
Health Insurance
401(k)
Paid Holidays
Security Operations Analyst
Security Operations Analyst

NextGenEnergyJobs • Vienna (VA), Northern (KY)

Hybrid
USD 90,000 - 140,000
Health benefits
401(k) and profit-sharing
Paid holidays
+1
SOC Analyst II: Threat Hunting & Incident Response
SOC Analyst II: Threat Hunting & Incident Response

Mbi Llc • Harrisburg

On-site
USD 60,000 - 90,000
SOC Security Analyst II: Threat Hunting & Incident Response
SOC Security Analyst II: Threat Hunting & Incident Response

Cyderes • United States

On-site
USD 60,000 - 100,000
Senior Security Analyst: Threat Hunting & Incident Response
Senior Security Analyst: Threat Hunting & Incident Response

IEHP • Rancho Cucamonga (CA)

On-site
USD 135,000 - 179,000
Competitive salary
On-site fitness center
Medical, Dental, Vision
+8
SOC Analyst: Incident Response & Threat Hunter
SOC Analyst: Incident Response & Threat Hunter

Inforcer • Cerritos (CA)

On-site
USD 90,000 - 130,000
Security Operations Analyst II - Incident Response
Security Operations Analyst II - Incident Response

NextGenEnergyJobs • Vienna (VA), Northern (KY)

Hybrid
USD 90,000 - 140,000
Health benefits
401(k) and profit-sharing
Paid holidays
+1
SOC Threat Hunter & Incident Response Engineer
SOC Threat Hunter & Incident Response Engineer

No Limit Staffing, Inc. • United States

On-site
USD 90,000 - 120,000
Enterprise Security Analyst II - Incident Response & Risk
Enterprise Security Analyst II - Incident Response & Risk

Associated Credit Union • Peachtree Corners (GA)

On-site