Sr. Security Analyst

ECS Corporate Services, LLC
Fairfax, VA, United States
26 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Compensation
$90,000.0 - $120,000.0
Working hours
Regular working hours

Tech stack

Cyber Security Intrusion Detection and Prevention Intrusion Detection Systems Python (Programming Language) Machine Learning Network Monitoring Network Protocols Pattern Recognition Windows PowerShell Logstash Phishing Security Information and Event Management
+6 more
Systems Integration Scripting Cyber Threat Analysis Firewalls (Computer Science) SC Clearance Kibana

Job description

  • Network Monitoring & Intrusion Detection: Perform analysis using defense tools including IDS/IPS, firewalls, and host-based security systems.
  • SIEM Operations (Elastic SIEM): Use Elastic SIEM to correlate events, identify indicators of compromise, and produce actionable intelligence for response.
  • Threat Detection Engineering (Analyst-led): Implement and improve log-based and endpoint-based detection strategies; validate detections and recommend tuning based on outcomes.
  • Content Development: Develop and tune SIEM content such as detection rules, machine learning rules, dashboards, and visualizations aligned to customer requirements.
  • Activity Correlation: Correlate data across network, cloud, and endpoints to identify attacks and unauthorized actions.
  • Alert Management & Reporting: Triage alerts from SIEM and other sensors; document incidents with clear technical reporting and recommendations.
  • Threat Research: Investigate emerging threats and vulnerabilities to enhance detection and incident identification processes.
  • Phishing Analysis: Analyze phishing submissions and recommend appropriate response actions.
  • Incident Response Support: Support containment and mitigation activities; contribute to root cause analysis and corrective actions.
  • Automation & Integrations: Create or maintain scripts (Python/PowerShell) for investigation support, enrichment, and workflow automation; help integrate telemetry sources into Elastic as needed.
  • Customer Training & Enablement: Provide training to customer teams on SIEM usage, detection capabilities, investigation workflows, and security best practices to drive long-term operational success.
  • Operational Excellence: Contribute to documentation (runbooks, detection standards, triage playbooks) and continuous improvement of SOC workflows.

Salary Range: $90,000 - $120,000

Requirements

We are seeking a Security Analyst with strong Elastic SIEM experience and solid cybersecurity fundamentals who can investigate alerts, hunt threats, and help operationalize detection capabilities across network, cloud, and endpoint telemetry. This role requires analytical rigor, comfort working directly with customers, and the ability to operate with limited oversight in fast-paced environments., * 2+ years of cybersecurity experience

  • Elastic SIEM proficiency: Monitoring, detection, triage, and investigation using Elastic SIEM; experience with Kibana and familiarity with Logstash / ingest pipelines preferred
  • Strong cybersecurity fundamentals including network protocols, encryption concepts, and vulnerabilities
  • Strong analytical skills for identifying patterns and anomalies across multiple data sources
  • Scripting/automation experience using Python or PowerShell
  • Experience creating and tuning SIEM rules, signatures, and dashboards
  • Strong written and verbal communication skills
  • Ability to problem-solve and operate under pressure in fast-paced environments
  • Willingness to support domestic or international travel (short, planned engagements)
  • Must possess and maintain a U.S. Passport
  • Must have a Secret clearance, at minimum

About the company

Everforth ECS is seeking a Sr. Security Analyst to work in our Remote office. This position is contingent upon additional funding.

As a leading managed cybersecurity services provider, ECS delivers highly tailored cybersecurity solutions aligned to each customer’s mission needs. The Professional Services Team partners with customers to understand their environment, strengthen security posture, and deliver measurable outcomes across detection, response, and continuous improvement.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.disabledperson.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:31 min

Exploring the core components of the ELK stack

Derek Binkley · LIVE

1:09 min

Core functions of security information and event monitoring

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

3:21 min

Deploying a primary Elasticsearch and Kibana cluster configuration

Philipp Krenn · WWC 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · WWC Europe 2026

Videos

See all

Related articles

See all