Security Operations Pro: Threat Hunting & Incident Response

Esri

Washington (District of Columbia)

On-site

USD 70,000 - 114,000

Full time

10 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Esri in Washington, DC is seeking an Enterprise Security Analyst II to monitor security events across endpoints, identity, network, cloud, and email, investigate incidents, and support the full incident lifecycle with structured evidence and clear remediation steps.

The role applies cyber threat intelligence and threat hunting to add context, conduct hunts, and strengthen detections, with after‑hours on‑call after onboarding and a base salary in the posted range.

Qualifications

  • 2+ years of cybersecurity experience with hands-on involvement in security monitoring, alert triage, and incident investigation
  • Experience analyzing endpoint, identity, network, cloud, email, and log data to identify suspicious or malicious activity
  • Working knowledge of SIEM and EDR platforms, common triage workflows, and security telemetry analysis
  • Strong understanding of networking, operating systems, identity and access concepts, cloud security fundamentals, and core security protocols
  • Working knowledge of cyber threat intelligence concepts, including indicators, threat actors, campaigns, vulnerabilities, and adversary tactics, techniques, and procedures
  • Ability to write clear investigation notes, incident records, intelligence summaries, and recommendations for technical and non-technical audiences
  • U.S. citizenship is mandatory
  • Ability and willingness to obtain security clearance
  • Bachelor’s in Cybersecurity, Information Technology, Computer Science, or a related STEM degree

Responsibilities

  • Monitor and manage the SOC alert queue across endpoint, identity, network, email, cloud, and log monitoring platforms
  • Independently triage and investigate security alerts and events, distinguishing confirmed threats from benign activity using available evidence and telemetry
  • Support the full incident lifecycle, including investigation, escalation, containment support, remediation follow-up, documentation, and closure
  • Escalate incidents with clear evidence, impact assessment, and recommended next steps
  • Apply playbooks and runbooks while identifying opportunities to improve alert quality, response consistency, automation, and analyst enablement
  • Analyze relevant threat intelligence to identify threats, campaigns, vulnerabilities, and adversary behaviors that may affect the organization
  • Enrich alerts and investigations with context about threat actors, malware, indicators, vulnerabilities, and attack techniques
  • Assist with threat hunts across endpoint, identity, network, cloud, and application telemetry
  • Use MITRE ATT&CK to support investigations, communicate adversary behavior, and identify detection gaps
  • Partner with security engineers and analysts to turn relevant intelligence into detections, hunts, watchlists, playbooks, blocking recommendations, or response improvements

Skills

Security monitoring
Incident investigation
Threat hunting
Cyber threat intelligence
On-call readiness
Technical report writing

Education

Bachelor's degree in Cybersecurity/IT/CS

Tools

SIEM
EDR
MITRE ATT&CK

Job description

Esri in Washington, DC is seeking an Enterprise Security Analyst II to monitor security events across endpoints, identity, network, cloud, and email, investigate incidents, and support the full incident lifecycle with structured evidence and clear remediation steps.

The role applies cyber threat intelligence and threat hunting to add context, conduct hunts, and strengthen detections, with after‑hours on‑call after onboarding and a base salary in the posted range.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Pro: Threat Hunting & Incident Response
Security Operations Pro: Threat Hunting & Incident Response

Esri • Redlands (CA)

On-site
USD 70,000 - 114,000
Medical insurance
Dental insurance
Vision insurance
+4
Security Operations & Threat Hunting Analyst
Security Operations & Threat Hunting Analyst

Esri • Vienna (VA)

On-site
USD 70,000 - 114,000
Medical
Dental
Vision
+3
Security Operations Analyst
Security Operations Analyst

NextGenEnergyJobs • Vienna (VA), Northern (KY)

Hybrid
USD 90,000 - 140,000
Health benefits
401(k) and profit-sharing
Paid holidays
+1
Security Operations Analyst
Security Operations Analyst

Esri • Washington

On-site
USD 70,000 - 114,000
Cyber Defense Analyst — Incident Response & Threat Hunting
Cyber Defense Analyst — Incident Response & Threat Hunting

Erias Ventures, LLC • Fort Meade (MD)

On-site
USD 210,000 - 232,000
Above market pay
401k with vesting
Spot bonuses
+12
Security Operations Analyst II - Incident Response
Security Operations Analyst II - Incident Response

NextGenEnergyJobs • Vienna (VA), Northern (KY)

Hybrid
USD 90,000 - 140,000
Health benefits
401(k) and profit-sharing
Paid holidays
+1
Security Engineer I: Threat Hunting & SIRT Response
Security Engineer I: Threat Hunting & SIRT Response

Amazon • Arlington (VA)

On-site
USD 136,000 - 184,000
Health insurance
Paid time off
401(k) matching
+2
Security Operations Analyst
Security Operations Analyst

Esri • Redlands (CA)

On-site
USD 70,000 - 114,000
Medical insurance
Dental insurance
Vision insurance
+4
Security Operations Analyst
Security Operations Analyst

Esri • Vienna (VA)

On-site
USD 70,000 - 114,000
Medical
Dental
Vision
+3
Security Operations Lead: Threat Hunting & Incident Response
Security Operations Lead: Threat Hunting & Incident Response

Accenture Federal Services • Washington

On-site
USD 126,000 - 244,000