Security Operations Analyst (Tier 1)
Northern Virginia | Shift based, with coverage around the clock
The Opportunity
Our client, a major network and communications provider, is growing its security operations team and needs analysts who want to get their start in hands on cyber defense. Youll sit on the front line of a mature, metrics driven operations center, watching for threats, sorting real issues from noise, and making sure incidents get to the right people fast. Expect clear processes, strong mentorship, and a defined path to more advanced work.
What Youll Do
- Watch alert queues and dashboards in a SIEM platform (Splunk preferred) for signs of malicious or unusual activity across networks, endpoints, and cloud systems
- Assess incoming alerts against established runbooks, rate their severity, and decide on next steps
- Escalate confirmed issues within required response times and hand them off cleanly to senior responders
- Keep detailed case records in a ticketing platform such as ServiceNow from first alert through closure
- Keep up with current threat activity, newly disclosed vulnerabilities, and common attacker behavior
- Help senior analysts piece together what happened during an incident and suggest ways to fix it
- Partner with engineering and threat hunting teams to close gaps and improve defenses
- Use runbooks consistently and suggest improvements when you spot them
- Give clear status updates to internal teams throughout an incident
What You Bring
- Degree in cybersecurity, IT, computer science, or similar, or comparable hands on experience
- Solid grasp of how a security operations center runs and how incidents move from detection to resolution
- Working knowledge of Splunk or a comparable SIEM
- Experience with ServiceNow or another ticketing tool
- Foundation in networking, core security concepts, and reading logs
- Sharp problem solving instincts and attention to detail
- Willingness to work rotating shifts, including nights, weekends, and holidays
- Strong writing and speaking skills
Nice to Have
- Security+ or a Splunk certification
- Exposure to MITRE ATT&CK or threat intelligence work
- Around two years in security monitoring or incident response