SOC Splunk Analyst I

GCS Recruitment Specialists

United States

On-site

USD 65,000 - 90,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

A Security Operations Analyst (Tier 1) position in Northern Virginia is part of a 24/7 operations center. You will monitor alert queues, classify incidents, and ensure proper handoffs to senior responders while maintaining thorough case records in ServiceNow.

A degree in cybersecurity or hands-on experience, plus working knowledge of Splunk or equivalent SIEM, are required. Shifts rotate, including nights, weekends, and holidays.

Qualifications

  • Degree or hands-on experience in cybersecurity, IT, CS, or related field.
  • Understanding of how a SOC operates and incident workflows.
  • Working knowledge of Splunk or equivalent SIEM.
  • Experience with ticketing platforms such as ServiceNow.
  • Foundation in networking and core security concepts, plus log reading.
  • Willingness to rotate shifts including nights, weekends and holidays.

Responsibilities

  • Monitor alert queues and dashboards in SIEM for signs of malicious or unusual activity across networks, endpoints, and cloud systems.
  • Assess incoming alerts against runbooks, rate their severity, and determine next steps.
  • Escalate confirmed issues within required response times and hand off to senior responders.
  • Maintain detailed case records in a ticketing platform from first alert to closure.
  • Stay updated on current threat activity, vulnerabilities, and attacker behavior.
  • Assist senior analysts in reconstructing incidents and suggesting fixes to prevent recurrence.
  • Collaborate with engineering and threat-hunting teams to close gaps and improve defenses.
  • Follow runbooks consistently and propose improvements when observed.
  • Provide clear status updates to internal teams during an incident.

Skills

SIEM (Splunk)
Incident response
Threat detection
Networking basics
Analytical/problem solving
Written and verbal communication

Education

Degree in cybersecurity/IT/CS or related field

Tools

ServiceNow

Job description

Security Operations Analyst (Tier 1)
Northern Virginia | Shift based, with coverage around the clock

The Opportunity

Our client, a major network and communications provider, is growing its security operations team and needs analysts who want to get their start in hands on cyber defense. Youll sit on the front line of a mature, metrics driven operations center, watching for threats, sorting real issues from noise, and making sure incidents get to the right people fast. Expect clear processes, strong mentorship, and a defined path to more advanced work.

What Youll Do
  • Watch alert queues and dashboards in a SIEM platform (Splunk preferred) for signs of malicious or unusual activity across networks, endpoints, and cloud systems
  • Assess incoming alerts against established runbooks, rate their severity, and decide on next steps
  • Escalate confirmed issues within required response times and hand them off cleanly to senior responders
  • Keep detailed case records in a ticketing platform such as ServiceNow from first alert through closure
  • Keep up with current threat activity, newly disclosed vulnerabilities, and common attacker behavior
  • Help senior analysts piece together what happened during an incident and suggest ways to fix it
  • Partner with engineering and threat hunting teams to close gaps and improve defenses
  • Use runbooks consistently and suggest improvements when you spot them
  • Give clear status updates to internal teams throughout an incident
What You Bring
  • Degree in cybersecurity, IT, computer science, or similar, or comparable hands on experience
  • Solid grasp of how a security operations center runs and how incidents move from detection to resolution
  • Working knowledge of Splunk or a comparable SIEM
  • Experience with ServiceNow or another ticketing tool
  • Foundation in networking, core security concepts, and reading logs
  • Sharp problem solving instincts and attention to detail
  • Willingness to work rotating shifts, including nights, weekends, and holidays
  • Strong writing and speaking skills
Nice to Have
  • Security+ or a Splunk certification
  • Exposure to MITRE ATT&CK or threat intelligence work
  • Around two years in security monitoring or incident response
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Splunk Analyst I: Hands-On Security Ops
SOC Splunk Analyst I: Hands-On Security Ops

GCS Recruitment Specialists • United States

On-site
USD 65,000 - 90,000
Security Analyst I
Security Analyst I

Aquent • Houston (TX)

On-site
USD 70,000 - 100,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Security Operations Analyst
Security Operations Analyst

Intrinsicamerica • Northern (KY)

Hybrid
USD 70,000 - 90,000
Security Operations Lead
Security Operations Lead

The Phoenix Group • Washington

On-site
USD 140,000 - 190,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

On-site
USD 80,000 - 110,000
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

10xTalents • Washington

On-site
USD 80,000 - 110,000
Cybersecurity Engineer
Cybersecurity Engineer

Accylerate, LLC. • Richmond (VA)

On-site
USD 110,000 - 140,000
Security Analyst I
Security Analyst I

Procom • Houston (TX)

On-site
USD 65,000 - 90,000
Security Operations Center (SOC) Analyst / Engineer
Security Operations Center (SOC) Analyst / Engineer

Zoho • United States

On-site
USD 110,000 - 160,000