SIEM / Threat Monitoring Analysts

Blue Rose Consulting Group
Washington, DC, United States
24 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Audit Trail Cyber Security Databases Digital Forensics Disaster Recovery Network Security Open Source Intelligence Security Information and Event Management Cyber Threat Analysis SC Clearance Information Technology Hardware Infrastructure
+1 more
Splunk

Job description

Monitor, analyze, correlate, and investigate security events using SIEM, log-management, threat intelligence, OSINT, and incident-response processes. This position supports the Department of State Consular Affairs global information technology environment, which includes domestic and overseas facilities, on-premises infrastructure, cloud platforms, applications, databases, and enterprise support services. This is a contingent position based on contract award and final customer requirements.

What You’ll Do

  • Monitor SIEM alerts, logs, audit trails, network events, endpoint events, and other telemetry for suspicious or policy-violating activity.

  • Triage, correlate, investigate, document, and escalate potential security incidents in accordance with established procedures.

  • Develop and tune SIEM searches, dashboards, correlation rules, alerts, reports, and use cases to improve detection quality.

  • Use open-source intelligence, threat intelligence, and digital-forensics techniques to enrich investigations and assess potential impact.

  • Coordinate with security, infrastructure, network, application, and incident-response teams during investigation, containment, recovery, and lessons-learned activities.

  • Maintain incident timelines, case notes, evidence, metrics, trends, and management reports.

  • Identify recurring patterns, coverage gaps, false positives, and opportunities to improve monitoring and response processes.

Requirements

  • 3+ years of SIEM administration, security monitoring, threat analysis, or SOC experience.

  • Hands-on experience with Splunk or another enterprise SIEM/log-management platform.

  • Experience triaging and investigating alerts, correlating events, and escalating potential incidents.

  • Familiarity with incident response, digital forensics, OSINT, threat intelligence, and recovery procedures.

  • Ability to work shift-based operations when required and communicate clearly during high-priority incidents.

  • Active Secret clearance; Top Secret may be preferred or required for certain assignments.

Preferred Qualifications

  • Splunk, Security+, CySA+, GCIH, GCIA, or equivalent certification.

  • Experience supporting Federal or Department of State security operations.

  • Experience with cloud logs, endpoint detection and response, network security monitoring, or automation.

Benefits & conditions

Compensation will be commensurate with experience, qualifications, assigned work location, and final contract requirements. Blue Rose offers a competitive benefits package for eligible full-time employees. Specific compensation and benefit details will be provided during the recruiting process.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:56 min

Leveraging GitOps for AI auditing and instant rollbacks

Jaroslaw Gajewski Jaroslaw Gajewski · World Congress 2026 Europe

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

1:09 min

Core functions of security information and event monitoring

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

1:09 min

Managing enterprise execution with the Operate runtime

Marcin Makowski Marcin Makowski · World Congress 2026 Europe

Videos

See all

Related articles

See all