Security Operations Analyst II - Threat Detection & Incident Response

DevCare Solutions
Harrisburg, PA, United States
18 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$85,280.0 - $95,680.0
Working hours
Shift work
Job source

Tech stack

Cyber Security Computer Networks Query Languages Intrusion Detection and Prevention Security Information and Event Management Information Technology Cybercrime

Job description

  • Perform continuous security monitoring and proactive response for critical IT systems and communication environments.
  • Investigate escalated security alerts to determine scope, root cause, severity, and potential impact.
  • Analyze security logs, network traffic, endpoint telemetry, and other data sources to identify threats and indicators of compromise (IOCs).
  • Conduct threat hunting activities to identify suspicious activity and potential adversary behavior.
  • Create and optimize SIEM queries, reports, scripts, dashboards, and detection rules.
  • Tune security alerts and correlation logic to improve detection accuracy and reduce false positives.
  • Follow, maintain, and improve SOC playbooks, procedures, and standard operating processes.
  • Document security incidents, investigations, response actions, and findings.
  • Support incident response activities and assist with security event resolution.
  • Monitor threat intelligence sources for emerging risks and actionable security events.
  • Participate in root cause analysis and lessons learned activities.

Requirements

The ideal candidate will have experience with SOC operations, SIEM analysis, security investigations, threat hunting, and developing detection improvements to strengthen cybersecurity operations., * Experience in a Security Operations Center (SOC), cybersecurity operations, or related security role.

  • Ability to analyze and interpret complex technical security information.
  • Experience creating queries, reports, and scripts using SIEM query languages.
  • Strong troubleshooting and investigation skills.
  • Ability to prioritize multiple tasks in a fast-paced security environment.
  • Excellent written and verbal communication skills.
  • Ability to work independently and as part of a team., * Experience with threat hunting, security investigations, and incident response.
  • Experience with SIEM tools, alert tuning, and detection engineering.
  • Knowledge of cybersecurity monitoring and response processes.

Benefits & conditions

$41 - $46 an hour - Full-time, Contract

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:05 min

Fetching platform telemetry data with query languages

Daisy Muyldermans · LIVE

4:23 min

Boosting security operations center productivity with intelligent data analysis

Chris Wysopal Chris Wysopal +2 · WWC 2024

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

14:14 min

Addressing audience inquiries on analytical implementation and career growth

Julian Joseph · LIVE

Videos

See all

Related articles

See all