> Markdown version of [/jobs/ext/2028418-siem-threat-monitoring-analysts](https://www.wearedevelopers.com/jobs/ext/2028418-siem-threat-monitoring-analysts). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SIEM / Threat Monitoring Analysts - **Company:** Blue Rose Consulting Group - **Location:** Washington, DC, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Audit Trail, Cyber Security, Databases, Digital Forensics, Disaster Recovery, Network Security, Open Source Intelligence, Security Information and Event Management, Cyber Threat Analysis, SC Clearance, Information Technology, Hardware Infrastructure, Splunk - **Published:** August 11, 2026 - **Apply:** https://www.clearancejobs.com/jobs/8983964/siem-threat-monitoring-analysts ## About the Role * 3+ years of SIEM administration, security monitoring, threat analysis, or SOC experience. * Hands-on experience with Splunk or another enterprise SIEM/log-management platform. * Experience triaging and investigating alerts, correlating events, and escalating potential incidents. * Familiarity with incident response, digital forensics, OSINT, threat intelligence, and recovery procedures. * Ability to work shift-based operations when required and communicate clearly during high-priority incidents. * Active Secret clearance; Top Secret may be preferred or required for certain assignments. Preferred Qualifications * Splunk, Security+, CySA+, GCIH, GCIA, or equivalent certification. * Experience supporting Federal or Department of State security operations. * Experience with cloud logs, endpoint detection and response, network security monitoring, or automation. ## Description Monitor, analyze, correlate, and investigate security events using SIEM, log-management, threat intelligence, OSINT, and incident-response processes. This position supports the Department of State Consular Affairs global information technology environment, which includes domestic and overseas facilities, on-premises infrastructure, cloud platforms, applications, databases, and enterprise support services. This is a contingent position based on contract award and final customer requirements. What You'll Do * Monitor SIEM alerts, logs, audit trails, network events, endpoint events, and other telemetry for suspicious or policy-violating activity. * Triage, correlate, investigate, document, and escalate potential security incidents in accordance with established procedures. * Develop and tune SIEM searches, dashboards, correlation rules, alerts, reports, and use cases to improve detection quality. * Use open-source intelligence, threat intelligence, and digital-forensics techniques to enrich investigations and assess potential impact. * Coordinate with security, infrastructure, network, application, and incident-response teams during investigation, containment, recovery, and lessons-learned activities. * Maintain incident timelines, case notes, evidence, metrics, trends, and management reports. * Identify recurring patterns, coverage gaps, false positives, and opportunities to improve monitoring and response processes. ## Related Videos - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [No Keys for the Robot: GitOps as the Control Plane for Autonomous Agents](https://www.wearedevelopers.com/videos/100095-no-keys-for-the-robot-gitops-as-the-control-plane-for-autonomous-agents) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)