SIEM / Threat Monitoring Analysts
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+1 more
Job description
Monitor, analyze, correlate, and investigate security events using SIEM, log-management, threat intelligence, OSINT, and incident-response processes. This position supports the Department of State Consular Affairs global information technology environment, which includes domestic and overseas facilities, on-premises infrastructure, cloud platforms, applications, databases, and enterprise support services. This is a contingent position based on contract award and final customer requirements.
What You’ll Do
-
Monitor SIEM alerts, logs, audit trails, network events, endpoint events, and other telemetry for suspicious or policy-violating activity.
-
Triage, correlate, investigate, document, and escalate potential security incidents in accordance with established procedures.
-
Develop and tune SIEM searches, dashboards, correlation rules, alerts, reports, and use cases to improve detection quality.
-
Use open-source intelligence, threat intelligence, and digital-forensics techniques to enrich investigations and assess potential impact.
-
Coordinate with security, infrastructure, network, application, and incident-response teams during investigation, containment, recovery, and lessons-learned activities.
-
Maintain incident timelines, case notes, evidence, metrics, trends, and management reports.
-
Identify recurring patterns, coverage gaps, false positives, and opportunities to improve monitoring and response processes.
Requirements
-
3+ years of SIEM administration, security monitoring, threat analysis, or SOC experience.
-
Hands-on experience with Splunk or another enterprise SIEM/log-management platform.
-
Experience triaging and investigating alerts, correlating events, and escalating potential incidents.
-
Familiarity with incident response, digital forensics, OSINT, threat intelligence, and recovery procedures.
-
Ability to work shift-based operations when required and communicate clearly during high-priority incidents.
-
Active Secret clearance; Top Secret may be preferred or required for certain assignments.
Preferred Qualifications
-
Splunk, Security+, CySA+, GCIH, GCIA, or equivalent certification.
-
Experience supporting Federal or Department of State security operations.
-
Experience with cloud logs, endpoint detection and response, network security monitoring, or automation.
Benefits & conditions
Compensation will be commensurate with experience, qualifications, assigned work location, and final contract requirements. Blue Rose offers a competitive benefits package for eligible full-time employees. Specific compensation and benefit details will be provided during the recruiting process.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Data Analyst Salary in Switzerland
Data Analyst Salary in the UK
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents