{"schemaVersion":"jobsearcher.job.v1","id":"8eb7cbba82232c432e287e07","url":"https://jobsearcher.com/jobs/8eb7cbba82232c432e287e07","canonicalUrl":"https://jobsearcher.com/jobs/8eb7cbba82232c432e287e07","title":"Sr Security Analyst","description":"ECS is seeking a Senior Security Analyst to work in our Scott AFB, IL office.\nAs a leading managed cybersecurity services provider, ECS delivers highly tailored cybersecurity solutions aligned to each customer's mission needs. The Professional Services Team partners with customers to understand their environment, strengthen security posture, and deliver measurable outcomes across detection, response, and continuous improvement.\nWe are seeking a Security Analyst with strong Elastic SIEM experience and solid cybersecurity fundamentals who can investigate alerts, hunt threats, and help operationalize detection capabilities across network, cloud, and endpoint telemetry. This role requires analytical rigor, comfort working directly with customers, and the ability to operate with limited oversight in fast-paced environments.\nKey Responsibilities\nNetwork Monitoring & Intrusion Detection: Perform analysis using defense tools including IDS/IPS, firewalls, and host-based security systems.\nSIEM Operations (Elastic SIEM): Use Elastic SIEM to correlate events, identify indicators of compromise, and produce actionable intelligence for response.\nThreat Detection Engineering (Analyst-led): Implement and improve log-based and endpoint-based detection strategies; validate detections and recommend tuning based on outcomes.\nContent Development: Develop and tune SIEM content such as detection rules, machine learning rules, dashboards, and visualizations aligned to customer requirements.\nActivity Correlation: Correlate data across network, cloud, and endpoints to identify attacks and unauthorized actions.\nAlert Management & Reporting: Triage alerts from SIEM and other sensors; document incidents with clear technical reporting and recommendations.\nThreat Research: Investigate emerging threats and vulnerabilities to enhance detection and incident identification processes.\nPhishing Analysis: Analyze phishing submissions and recommend appropriate response actions.\nIncident Response Support: Support containment and mitigation activities; contribute to root cause analysis and corrective actions.\nAutomation & Integrations: Create or maintain scripts (Python/PowerShell) for investigation support, enrichment, and workflow automation; help integrate telemetry sources into Elastic as needed.\nCustomer Training & Enablement: Provide training to customer teams on SIEM usage, detection capabilities, investigation workflows, and security best practices to drive long-term operational success.\nOperational Excellence: Contribute to documentation (runbooks, detection standards, triage playbooks) and continuous improvement of SOC workflows.\nRequirements:\n2+ years of cybersecurity experience\nElastic SIEM proficiency: Monitoring, detection, triage, and investigation using Elastic SIEM; experience with Kibana and familiarity with Logstash / ingest pipelines preferred\nStrong cybersecurity fundamentals including network protocols, encryption concepts, and vulnerabilities\nStrong analytical skills for identifying patterns and anomalies across multiple data sources\nScripting/automation experience using Python or PowerShell\nExperience creating and tuning SIEM rules, signatures, and dashboards\nStrong written and verbal communication skills\nAbility to problem-solve and operate under pressure in fast-paced environments\nWillingness to support domestic or international travel (short, planned engagements)\nMust possess and maintain a U.S. Passport\nMust have a Secret clearance, at minimum\n\nReq Benefits:\nBenefits - Everforth ECS","company":"Everforth Ecs","rawCompany":"everforth ecs","city":"Avon","state":"MN","isRemote":false,"isActive":false,"createdAt":"2026-08-05T15:12:42.031Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"561621","title":"Security Systems Services (except Locksmiths)","slug":"security-systems-services-except-locksmiths"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Sr Security Analyst","description":"ECS is seeking a Senior Security Analyst to work in our Scott AFB, IL office.\nAs a leading managed cybersecurity services provider, ECS delivers highly tailored cybersecurity solutions aligned to each customer's mission needs. The Professional Services Team partners with customers to understand their environment, strengthen security posture, and deliver measurable outcomes across detection, response, and continuous improvement.\nWe are seeking a Security Analyst with strong Elastic SIEM experience and solid cybersecurity fundamentals who can investigate alerts, hunt threats, and help operationalize detection capabilities across network, cloud, and endpoint telemetry. This role requires analytical rigor, comfort working directly with customers, and the ability to operate with limited oversight in fast-paced environments.\nKey Responsibilities\nNetwork Monitoring & Intrusion Detection: Perform analysis using defense tools including IDS/IPS, firewalls, and host-based security systems.\nSIEM Operations (Elastic SIEM): Use Elastic SIEM to correlate events, identify indicators of compromise, and produce actionable intelligence for response.\nThreat Detection Engineering (Analyst-led): Implement and improve log-based and endpoint-based detection strategies; validate detections and recommend tuning based on outcomes.\nContent Development: Develop and tune SIEM content such as detection rules, machine learning rules, dashboards, and visualizations aligned to customer requirements.\nActivity Correlation: Correlate data across network, cloud, and endpoints to identify attacks and unauthorized actions.\nAlert Management & Reporting: Triage alerts from SIEM and other sensors; document incidents with clear technical reporting and recommendations.\nThreat Research: Investigate emerging threats and vulnerabilities to enhance detection and incident identification processes.\nPhishing Analysis: Analyze phishing submissions and recommend appropriate response actions.\nIncident Response Support: Support containment and mitigation activities; contribute to root cause analysis and corrective actions.\nAutomation & Integrations: Create or maintain scripts (Python/PowerShell) for investigation support, enrichment, and workflow automation; help integrate telemetry sources into Elastic as needed.\nCustomer Training & Enablement: Provide training to customer teams on SIEM usage, detection capabilities, investigation workflows, and security best practices to drive long-term operational success.\nOperational Excellence: Contribute to documentation (runbooks, detection standards, triage playbooks) and continuous improvement of SOC workflows.\nRequirements:\n2+ years of cybersecurity experience\nElastic SIEM proficiency: Monitoring, detection, triage, and investigation using Elastic SIEM; experience with Kibana and familiarity with Logstash / ingest pipelines preferred\nStrong cybersecurity fundamentals including network protocols, encryption concepts, and vulnerabilities\nStrong analytical skills for identifying patterns and anomalies across multiple data sources\nScripting/automation experience using Python or PowerShell\nExperience creating and tuning SIEM rules, signatures, and dashboards\nStrong written and verbal communication skills\nAbility to problem-solve and operate under pressure in fast-paced environments\nWillingness to support domestic or international travel (short, planned engagements)\nMust possess and maintain a U.S. Passport\nMust have a Secret clearance, at minimum\n\nReq Benefits:\nBenefits - Everforth ECS","datePosted":"2026-08-05T15:12:42.031Z","dateModified":"2026-08-05T15:12:42.031Z","hiringOrganization":{"@type":"Organization","name":"Everforth Ecs","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Avon","addressRegion":"MN","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"8eb7cbba82232c432e287e07"},"url":"https://jobsearcher.com/jobs/8eb7cbba82232c432e287e07"}}