Sr Security Analyst

ecsfederal

Illinois

On-site

USD 110,000 - 150,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

ECS is seeking a Senior Security Analyst to support at Scott AFB, IL. You will investigate alerts, hunt threats, and operationalize detection across network, cloud, and endpoint telemetry.

You will leverage Elastic SIEM, Kibana, and log pipelines to create detections, dashboards, and automation. Travel for short engagements and direct customer interaction are expected. A Secret clearance and US Passport are required.

Qualifications

  • 2+ years of cybersecurity experience required.
  • Elastic SIEM proficiency for monitoring, triage, and investigation.
  • Strong fundamentals in networking, encryption, and vulnerabilities.
  • Scripting/automation experience in Python or PowerShell.
  • Experience creating/tuning SIEM rules, signatures, and dashboards.
  • Excellent written and verbal communication skills.
  • Willingness to travel domestically or internationally for short engagements.
  • U.S. Passport and at least a Secret clearance required.

Responsibilities

  • Monitor networks and detect intrusions using defense tools.
  • Operate Elastic SIEM to correlate events and produce actionable intel.
  • Develop and tune SIEM content, rules, dashboards, and ML rules.
  • Correlate data across network, cloud, and endpoints to identify attacks.
  • Triaging alerts and documenting incidents with recommendations.
  • Develop threat detection engineering approaches and tune detections.
  • Perform phishing analysis and support incident response actions.
  • Create scripts to automate investigations and enrich telemetry sources.
  • Train customer teams on SIEM usage and investigation workflows.
  • Contribute to runbooks, playbooks, and SOC workflow improvements.

Skills

Elastic SIEM
Python/PowerShell
Threat hunting
Analytical thinking
Communication
Travel readiness
US Passport
Security clearance

Tools

Kibana
Logstash

Job description

ECS is seeking a Senior Security Analyst to work in our Scott AFB, IL office.

As a leading managed cybersecurity services provider, ECS delivers highly tailored cybersecurity solutions aligned to each customer's mission needs. The Professional Services Team partners with customers to understand their environment, strengthen security posture, and deliver measurable outcomes across detection, response, and continuous improvement.

We are seeking a Security Analyst with strong Elastic SIEM experience and solid cybersecurity fundamentals who can investigate alerts, hunt threats, and help operationalize detection capabilities across network, cloud, and endpoint telemetry. This role requires analytical rigor, comfort working directly with customers, and the ability to operate with limited oversight in fast-paced environments.

Key Responsibilities
  • Network Monitoring & Intrusion Detection: Perform analysis using defense tools including IDS/IPS, firewalls, and host-based security systems.
  • SIEM Operations (Elastic SIEM): Use Elastic SIEM to correlate events, identify indicators of compromise, and produce actionable intelligence for response.
  • Threat Detection Engineering (Analyst-led): Implement and improve log-based and endpoint-based detection strategies; validate detections and recommend tuning based on outcomes.
  • Content Development: Develop and tune SIEM content such as detection rules, machine learning rules, dashboards, and visualizations aligned to customer requirements.
  • Activity Correlation: Correlate data across network, cloud, and endpoints to identify attacks and unauthorized actions.
  • Alert Management & Reporting: Triage alerts from SIEM and other sensors; document incidents with clear technical reporting and recommendations.
  • Threat Research: Investigate emerging threats and vulnerabilities to enhance detection and incident identification processes.
  • Phishing Analysis: Analyze phishing submissions and recommend appropriate response actions.
  • Incident Response Support: Support containment and mitigation activities; contribute to root cause analysis and corrective actions.
  • Automation & Integrations: Create or maintain scripts (Python/PowerShell) for investigation support, enrichment, and workflow automation; help integrate telemetry sources into Elastic as needed.
  • Customer Training & Enablement: Provide training to customer teams on SIEM usage, detection capabilities, investigation workflows, and security best practices to drive long-term operational success.
  • Operational Excellence: Contribute to documentation (runbooks, detection standards, triage playbooks) and continuous improvement of SOC workflows.
  • 2+ years of cybersecurity experience
  • Elastic SIEM proficiency: Monitoring, detection, triage, and investigation using Elastic SIEM; experience with Kibana and familiarity with Logstash / ingest pipelines preferred
  • Strong cybersecurity fundamentals including network protocols, encryption concepts, and vulnerabilities
  • Strong analytical skills for identifying patterns and anomalies across multiple data sources
  • Scripting/automation experience using Python or PowerShell
  • Experience creating and tuning SIEM rules, signatures, and dashboards
  • Strong written and verbal communication skills
  • Ability to problem-solve and operate under pressure in fast-paced environments
  • Willingness to support domestic or international travel (short, planned engagements)
  • Must possess and maintain a U.S. Passport
  • Must have a Secret clearance, at minimum
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr Security Analyst
Sr Security Analyst

ECS • Shiloh (IL)

On-site
USD 80,000 - 110,000
Senior Security Analyst: Elastic SIEM & Threat Detection
Senior Security Analyst: Elastic SIEM & Threat Detection

ECS • Shiloh (IL)

On-site
USD 80,000 - 110,000
Senior Security Analyst - Elastic SIEM & Threat Hunting
Senior Security Analyst - Elastic SIEM & Threat Hunting

ecsfederal • Illinois

On-site
USD 110,000 - 150,000
Sr. Elastic Engineer
Sr. Elastic Engineer

ecsfederal • Illinois

On-site
USD 90,000 - 130,000
Sr. Elastic Engineer
Sr. Elastic Engineer

ECS • Shiloh (IL)

On-site
USD 100,000 - 130,000
Security Operations Analyst – Senior
Security Operations Analyst – Senior

C3EL • Washington

On-site
USD 95,000 - 125,000
CYBERSECURITY ENGINEER
CYBERSECURITY ENGINEER

Y-Tech, LLC. • Fort Belvoir (VA)

On-site
USD 90,000 - 130,000
SIEM Engineer - Mid
SIEM Engineer - Mid

ecsfederal • Washington

On-site
USD 108,000 - 125,000
Detection Analyst (Elastic)
Detection Analyst (Elastic)

BreakPoint Labs LLC • Charleston (SC), Northern (KY)

On-site
USD 110,000 - 140,000
Detect Engineers (Elastic ) and (Cloud) with Security Clearance
Detect Engineers (Elastic ) and (Cloud) with Security Clearance

BreakPoint Labs, LLC • Charleston (SC)

On-site
USD 120,000 - 150,000