Security Operations Analyst II - Threat Detection & Incident Response
DevCare Solutions
Harrisburg, PA, United States
18 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$85,280.0 - $95,680.0
Working hours
Shift work
Job source
Tech stack
Cyber Security
Computer Networks
Query Languages
Intrusion Detection and Prevention
Security Information and Event Management
Information Technology
Cybercrime
Job description
- Perform continuous security monitoring and proactive response for critical IT systems and communication environments.
- Investigate escalated security alerts to determine scope, root cause, severity, and potential impact.
- Analyze security logs, network traffic, endpoint telemetry, and other data sources to identify threats and indicators of compromise (IOCs).
- Conduct threat hunting activities to identify suspicious activity and potential adversary behavior.
- Create and optimize SIEM queries, reports, scripts, dashboards, and detection rules.
- Tune security alerts and correlation logic to improve detection accuracy and reduce false positives.
- Follow, maintain, and improve SOC playbooks, procedures, and standard operating processes.
- Document security incidents, investigations, response actions, and findings.
- Support incident response activities and assist with security event resolution.
- Monitor threat intelligence sources for emerging risks and actionable security events.
- Participate in root cause analysis and lessons learned activities.
Requirements
The ideal candidate will have experience with SOC operations, SIEM analysis, security investigations, threat hunting, and developing detection improvements to strengthen cybersecurity operations., * Experience in a Security Operations Center (SOC), cybersecurity operations, or related security role.
- Ability to analyze and interpret complex technical security information.
- Experience creating queries, reports, and scripts using SIEM query languages.
- Strong troubleshooting and investigation skills.
- Ability to prioritize multiple tasks in a fast-paced security environment.
- Excellent written and verbal communication skills.
- Ability to work independently and as part of a team., * Experience with threat hunting, security investigations, and incident response.
- Experience with SIEM tools, alert tuning, and detection engineering.
- Knowledge of cybersecurity monitoring and response processes.
Benefits & conditions
$41 - $46 an hour - Full-time, Contract
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
about 2 years ago
KD
Krissy Davis
Best Paying Jobs in Technology
about 3 years ago
LM
Luis Minvielle
Is Software Engineering Over-Saturated?
over 2 years ago
DC
Daniel Cranney
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents
10 months ago
LM
Luis Minvielle
The Most Popular IT Jobs on the Market
over 2 years ago
LM
Luis Minvielle
Where To Find Software Engineering Jobs
over 2 years ago