{"schemaVersion":"jobsearcher.job.v1","id":"80dfd93cd43f6b0036da5bf0","url":"https://jobsearcher.com/jobs/80dfd93cd43f6b0036da5bf0","canonicalUrl":"https://jobsearcher.com/jobs/80dfd93cd43f6b0036da5bf0","title":"Security Operations Analyst","description":"Overview\n\nThe Enterprise Security Analyst II is a hands-on Security Operations Center (SOC) role responsible for monitoring alerts, investigating security events, supporting incident response, and improving security operations. This role also applies cyber threat intelligence and threat hunting practices to add context to investigations, identify emerging threats, and strengthen detection and response capabilities. Primary schedule is business hours, Monday through Friday. Participation in an after-hours on-call rotation is expected after onboarding and demonstrated familiarity with systems, tools, and response procedures.\n\nResponsibilities\n\nSecurity Operations and Incident Response\n\nMonitor and manage the SOC alert queue across endpoint, identity, network, email, cloud, and log monitoring platforms\nIndependently triage and investigate security alerts and events, distinguishing confirmed threats from benign activity using available evidence and telemetry\nSupport the full incident lifecycle, including investigation, escalation, containment support, remediation follow-up, documentation, and closure\nEscalate incidents with clear evidence, impact assessment, and recommended next steps\nApply playbooks and runbooks while identifying opportunities to improve alert quality, response consistency, automation, and analyst enablement\n\nThreat Intelligence and Threat Hunting\n\nAnalyze relevant threat intelligence to identify threats, campaigns, vulnerabilities, and adversary behaviors that may affect the organization\nEnrich alerts and investigations with context about threat actors, malware, indicators, vulnerabilities, and attack techniques\nAssist with threat hunts across endpoint, identity, network, cloud, and application telemetry\nUse MITRE ATT&CK to support investigations, communicate adversary behavior, and identify detection gaps\nPartner with security engineers and analysts to turn relevant intelligence into detections, hunts, watchlists, playbooks, blocking recommendations, or response improvements\n\nRequirements\n\n2+ years of cybersecurity experience with hands-on involvement in security monitoring, alert triage, and incident investigation\nExperience analyzing endpoint, identity, network, cloud, email, and log data to identify suspicious or malicious activity\nWorking knowledge of SIEM and EDR platforms, common triage workflows, and security telemetry analysis\nStrong understanding of networking, operating systems, identity and access concepts, cloud security fundamentals, and core security protocols\nWorking knowledge of cyber threat intelligence concepts, including indicators, threat actors, campaigns, vulnerabilities, and adversary tactics, techniques, and procedures\nAbility to write clear investigation notes, incident records, intelligence summaries, and recommendations for technical and non-technical audiences\nU.S. citizenship is mandatory\nAbility and willingness to obtain security clearance\nBachelors in Cybersecurity, Information Technology, Computer Science, or a related STEM degree\n\nRecommended Qualifications\n\nExperience performing threat intelligence analysis, threat hunting, incident response, or security engineering in an enterprise environment\nExperience converting threat intelligence into detections, hunts, watchlists, playbooks, response actions, or mitigation recommendations\nExperience researching threat actors, malware, ransomware activity, vulnerability exploitation, or emerging attack techniques\nFamiliarity with SOAR platforms, detection engineering practices, automation, scripting, or query languages such as PowerShell, Python, KQL, or SPL\nRelevant certifications such as CompTIA Security+, GCIH, GCED, GCIA, GCFA, GCTI, CTIA, or Microsoft security certifications\n\n#LI-TM1\n\n#LI-onsite\n\nThe Company\n\nAt Esri, diversity is more than just a word on a map. When employees of different experiences, perspectives, backgrounds, and cultures come together, we are more innovative and ultimately a better place to work. We believe in having a diverse workforce that is unified under our mission of creating positive global change. We understand that diversity, equity, and inclusion is not a destination but an ongoing process. We are committed to the continuation of learning, growing, and changing our workplace so every employee can contribute to their life's best work. Our commitment to these principles extends to the global communities we serve by creating positive change with GIS technology. For more information on Esri's Racial Equity and Social Justice initiatives, please visit our website here.\n\nIf you don't meet all of the preferred qualifications for this position, we encourage you to still apply!\n\nEsri is an equal opportunity employer (EOE) and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability status, protected veteran status, or any other characteristic protected by law. If you need reasonable accommodation for any part of the employment process, please email askcareers@esri.com and let us know the nature of your request and your contact information. Please note that only those inquiries concerning a request for reasonable accommodation will be responded to from this e-mail address.\n\nEsri Privacy Esri takes our responsibility to protect your privacy seriously. We are committed to respecting your privacy by providing transparency in how we acquire and use your information, giving you control of your information and preferences, and holding ourselves to the highest national and international standards, including CCPA and GDPR compliance.","company":"Esri","rawCompany":"esri","city":"Reston","state":"VA","isRemote":false,"isActive":false,"createdAt":"2026-09-06T13:28:50.152Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Security Operations Analyst","description":"Overview\n\nThe Enterprise Security Analyst II is a hands-on Security Operations Center (SOC) role responsible for monitoring alerts, investigating security events, supporting incident response, and improving security operations. This role also applies cyber threat intelligence and threat hunting practices to add context to investigations, identify emerging threats, and strengthen detection and response capabilities. Primary schedule is business hours, Monday through Friday. Participation in an after-hours on-call rotation is expected after onboarding and demonstrated familiarity with systems, tools, and response procedures.\n\nResponsibilities\n\nSecurity Operations and Incident Response\n\nMonitor and manage the SOC alert queue across endpoint, identity, network, email, cloud, and log monitoring platforms\nIndependently triage and investigate security alerts and events, distinguishing confirmed threats from benign activity using available evidence and telemetry\nSupport the full incident lifecycle, including investigation, escalation, containment support, remediation follow-up, documentation, and closure\nEscalate incidents with clear evidence, impact assessment, and recommended next steps\nApply playbooks and runbooks while identifying opportunities to improve alert quality, response consistency, automation, and analyst enablement\n\nThreat Intelligence and Threat Hunting\n\nAnalyze relevant threat intelligence to identify threats, campaigns, vulnerabilities, and adversary behaviors that may affect the organization\nEnrich alerts and investigations with context about threat actors, malware, indicators, vulnerabilities, and attack techniques\nAssist with threat hunts across endpoint, identity, network, cloud, and application telemetry\nUse MITRE ATT&CK to support investigations, communicate adversary behavior, and identify detection gaps\nPartner with security engineers and analysts to turn relevant intelligence into detections, hunts, watchlists, playbooks, blocking recommendations, or response improvements\n\nRequirements\n\n2+ years of cybersecurity experience with hands-on involvement in security monitoring, alert triage, and incident investigation\nExperience analyzing endpoint, identity, network, cloud, email, and log data to identify suspicious or malicious activity\nWorking knowledge of SIEM and EDR platforms, common triage workflows, and security telemetry analysis\nStrong understanding of networking, operating systems, identity and access concepts, cloud security fundamentals, and core security protocols\nWorking knowledge of cyber threat intelligence concepts, including indicators, threat actors, campaigns, vulnerabilities, and adversary tactics, techniques, and procedures\nAbility to write clear investigation notes, incident records, intelligence summaries, and recommendations for technical and non-technical audiences\nU.S. citizenship is mandatory\nAbility and willingness to obtain security clearance\nBachelors in Cybersecurity, Information Technology, Computer Science, or a related STEM degree\n\nRecommended Qualifications\n\nExperience performing threat intelligence analysis, threat hunting, incident response, or security engineering in an enterprise environment\nExperience converting threat intelligence into detections, hunts, watchlists, playbooks, response actions, or mitigation recommendations\nExperience researching threat actors, malware, ransomware activity, vulnerability exploitation, or emerging attack techniques\nFamiliarity with SOAR platforms, detection engineering practices, automation, scripting, or query languages such as PowerShell, Python, KQL, or SPL\nRelevant certifications such as CompTIA Security+, GCIH, GCED, GCIA, GCFA, GCTI, CTIA, or Microsoft security certifications\n\n#LI-TM1\n\n#LI-onsite\n\nThe Company\n\nAt Esri, diversity is more than just a word on a map. When employees of different experiences, perspectives, backgrounds, and cultures come together, we are more innovative and ultimately a better place to work. We believe in having a diverse workforce that is unified under our mission of creating positive global change. We understand that diversity, equity, and inclusion is not a destination but an ongoing process. We are committed to the continuation of learning, growing, and changing our workplace so every employee can contribute to their life's best work. Our commitment to these principles extends to the global communities we serve by creating positive change with GIS technology. For more information on Esri's Racial Equity and Social Justice initiatives, please visit our website here.\n\nIf you don't meet all of the preferred qualifications for this position, we encourage you to still apply!\n\nEsri is an equal opportunity employer (EOE) and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability status, protected veteran status, or any other characteristic protected by law. If you need reasonable accommodation for any part of the employment process, please email askcareers@esri.com and let us know the nature of your request and your contact information. Please note that only those inquiries concerning a request for reasonable accommodation will be responded to from this e-mail address.\n\nEsri Privacy Esri takes our responsibility to protect your privacy seriously. We are committed to respecting your privacy by providing transparency in how we acquire and use your information, giving you control of your information and preferences, and holding ourselves to the highest national and international standards, including CCPA and GDPR compliance.","datePosted":"2026-09-06T13:28:50.152Z","dateModified":"2026-09-06T13:28:50.152Z","hiringOrganization":{"@type":"Organization","name":"Esri","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Reston","addressRegion":"VA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"80dfd93cd43f6b0036da5bf0"},"url":"https://jobsearcher.com/jobs/80dfd93cd43f6b0036da5bf0"}}