> Markdown version of [/jobs/ext/1490080-security-monitoring-siem-analyst](https://www.wearedevelopers.com/jobs/ext/1490080-security-monitoring-siem-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Monitoring / SIEM Analyst - **Company:** DecisionPoint Corporation - **Location:** Reston, VA, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Cloud Computing, Cyber Security, Digital Forensics, Identity and Access Management, Intrusion Detection and Prevention, Log Analysis, Cloud Services, Security Information and Event Management, EndPointSecurity, Mitre Att&ck, Cyber Threat Analysis, Firewalls (Computer Science), Information Technology, ArcSight Event Correlation, Cyber Warfare, Vulnerability Analysis - **Published:** July 29, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17736599?backUrl=%2Fcareer%2F17736599%2FSecurity-Monitoring-Siem-Analyst-Virginia-Reston ## About the Role Bachelor's degree in Information Security, Information Technology, Digital Forensics, or a related field. Experience (Required) * Minimum 5 years of experience in security monitoring, SOC operations, threat analysis, or cybersecurity investigation. * Experience analyzing logs and events from SIEM platforms. * Experience identifying suspicious activity, anomalous behavior, or indicators of compromise (IOCs). * Experience correlating data from multiple systems to assess potential threats. * Experience documenting findings and escalating incidents to senior cybersecurity staff. Technical Knowledge (Required) * Strong understanding of SIEM platforms, log aggregation tools, and event correlation. * Knowledge of common attack vectors, threat behaviors, and MITRE ATT&CK techniques. * Familiarity with DoD cybersecurity monitoring, continuous monitoring principles, and incident escalation. * Knowledge of logs produced by operating systems, firewalls, authentication systems, and cloud platforms. Technical Knowledge (Preferred) * Experience tuning SIEM correlation rules or creating new detection logic. * Experience with endpoint detection tools, threat intelligence platforms, or security orchestration workflows. * Familiarity with cloud log monitoring (AWS CloudTrail, GuardDuty, or equivalent). Certifications Required: * Security+ Preferred: * CySA+ * Additional DoD 8570/8140 cyber operations certifications Skills * Strong analytical, investigative, and problem-solving abilities for assessing security events. * Excellent written and verbal communication skills for summarizing findings and documenting incidents. * Ability to operate in a fast-paced SOC environment and manage multiple active investigations. * High attention to detail for reviewing logs, identifying anomalies, and escalating confirmed threats. * Ability to collaborate effectively with other cybersecurity, engineering, and incident response teams. ## Description DecisionPoint seeks a Security Monitoring / SIEM Analyst to support enterprise cybersecurity operations within a federal and DoD-aligned mission environment. This role provides continuous monitoring of security events, log analysis, threat detection, and incident escalation in order to protect mission-critical systems. The analyst will review SIEM alerts, correlate data across multiple log sources, assess anomalous behavior, and support the investigative process for potential threats. The Security Monitoring / SIEM Analyst plays a critical role in maintaining situational awareness, enhancing detection capabilities, and strengthening cyber defense through proactive log analysis and coordination with incident response and engineering teams. This position is fully remote., The Security Monitoring / SIEM Analyst will: Monitor SIEM dashboards and event queues for suspicious or anomalous cybersecurity activity. * Correlate logs from multiple security data sources, including firewalls, endpoints, cloud services, and authentication platforms. * Investigate events and alerts to determine severity, threat likelihood, and required escalation paths. * Support information gathering and preliminary triage for cybersecurity incidents. * Analyze user activity, authentication logs, and system behavior for potential compromise indicators. * Assist with tuning SIEM rules, correlation logic, thresholds, and suppression patterns to improve detection accuracy. * Document security event details, timelines, and investigative findings. * Escalate confirmed or high-risk events to the incident response team with detailed analysis. * Maintain daily and weekly reporting on events, trends, and identified threats. * Participate in continuous monitoring and security operations cycles aligned with DoD RMF requirements. * Contribute to the creation and refinement of SOC playbooks, detection use cases, and monitoring procedures. ## Related Videos - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [APItoolkit: Using Merkle Trees and LLMs to Detect the UnDetectable in Software Monitoring](https://www.wearedevelopers.com/videos/1639-apitoolkit-using-merkle-trees-and-llms-to-detect-the-undetectable-in-software-monitoring) - [Leveraging Large Language Models for Legacy Code Translation: Challenges and Solutions](https://www.wearedevelopers.com/videos/1157-leveraging-large-language-models-for-legacy-code-translation-challenges-and-solutions) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems)