Security Operations Analyst

MultiPlan
McLean, VA, United States
6 days ago
Apply on diversityjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$95,000.0 - $105,000.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Active Directory Amazon Web Services Microsoft Azure Cloud Computing Security CompTIA Security+ Cyber Security Linux Identity and Access Management Information Technology Operations Intrusion Detection Systems Network Security
+16 more
Microsoft Security Essentials Phishing Microsoft SharePoint Security Information and Event Management Software Vulnerability Management Google Cloud Cloud Platform System In-Plane Switching (IPS) Mitre Att&ck Software Troubleshooting Cyber Threat Analysis Information Technology Cybercrime Splunk Security Orchestration, Automation & Response Servicenow

Job description

JOB SUMMARY: The SOC Analyst is responsible for monitoring, detecting, investigating, and responding to cybersecurity threats across the organization’s technology environment. This role serves as a frontline defender against cyber threats by analyzing security alerts, conducting incident investigations, and escalating security events as appropriate. The analyst works closely with IT, infrastructure, cloud, and application teams to protect organizational assets, maintain security monitoring capabilities, and strengthen the overall security posture., Security Monitoring & Detection

  • Monitor security events and alerts generated by SIEM, EDR, IDS/IPS, email security, cloud security, and other security tools.

  • Analyze and triage security alerts to determine legitimacy, severity, and business impact.

  • Identify indicators of compromise (IOCs), suspicious behavior, and emerging threats.

  • Perform continuous threat monitoring and situational awareness activities.

Incident Response

  • Investigate cybersecurity incidents including malware infections, phishing attacks, account compromises, insider threats, and unauthorized access attempts.

  • Execute incident response procedures and playbooks.

  • Document findings, actions taken, and lessons learned.

  • Coordinate containment, eradication, and recovery activities with appropriate stakeholders.

  • Escalate significant incidents according to established procedures.

Threat Hunting & Intelligence

  • Utilize threat intelligence feeds to enrich investigations.

  • Research emerging threats, vulnerabilities, and attack techniques.

  • Develop and refine detection use cases based on threat intelligence and incident trends.

Security Operations

  • Support vulnerability management efforts by validating findings and tracking remediation.

  • Assist with security tool administration and tuning.

  • Review and improve alerting logic to reduce false positives.

  • Participate in security assessments and operational readiness activities.

  • Support audit and compliance initiatives as required.

  • And other duties as assigned.

Documentation & Reporting

  • Maintain accurate incident records, investigation notes, and operational metrics.

  • Prepare reports on security incidents, trends, and findings.

  • Contribute to development and maintenance of standard operating procedures (SOPs).

  • Provide security recommendations to business and technical stakeholders.

Collaboration

  • Work closely with infrastructure, networking, cloud, and identity teams.

  • Participate in on-call rotations and after-hours incident response activities when required.

  • Support user awareness efforts through identification of phishing and social engineering trends.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Security, Information Technology, Computer Science, or related field; or equivalent combination of education and experience.

  • 3+ years of cybersecurity, information security, IT operations, or SOC experience (Level I/II).

  • Experience investigating security alerts and incidents.

  • Familiarity with SIEM platforms and security monitoring tools.

  • (Preferred) Security Information and Event Management (SIEM) platforms (Splunk)

  • (Preferred) Endpoint Detection and Response (EDR) solutions (Crowdstrike)

  • (Preferred) Reliaquest managed detection and response (MDR) and Servicenow experience

  • Microsoft 365 and Azure security technologies

  • Network security concepts and protocols

  • Identity and Access Management (IAM)

  • Windows, Linux, and cloud environments

  • MITRE ATT&CK framework

  • Incident response methodologies

  • Strong troubleshooting and investigative abilities

  • Ability to prioritize multiple security events in a fast-paced environment

  • Excellent attention to detail

  • Strong written and verbal communication skills

Preferred Qualifications:

  • CompTIA Security+

  • CompTIA CySA+

  • GIAC Certified Incident Handler (GCIH)

  • GIAC Security Essentials (GSEC)

  • SSCP

  • Certified Ethical Hacker (CEH)

  • SC-200 Security Operations Analyst

  • CISSP

  • Experience with Splunk, Microsoft core infrastructure technologies (Entra/Active Directory, Sharepoint, Copilot, etc.), CrowdStrike, or similar platforms.

  • Experience with SOAR and security automation technologies.

  • Exposure to cloud security platforms (Azure, AWS, GCP).

  • Knowledge of NIST Cybersecurity Framework and incident response best practices.

Benefits & conditions

The salary range for this position is $95K -105K. Specific offers take into account a candidate’s education, experience and skills, as well as the candidate’s work location and internal equity. This position is also eligible for health insurance, 401k and bonus opportunity.

Why Claritev?

Healthcare is complex. We help make it clearer.

At Claritev, you’ll do work that matters. Together, we’re helping make healthcare more transparent and affordable for all through the power of data, technology, and expertise. We offer meaningful opportunities to grow your career, collaborate with talented colleagues, and make an impact on the clients and communities we serve. If you’re looking for purpose, growth, and a team that succeeds together, you’ll find it here.

What Guides Us

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on diversityjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Defining application, pipeline, and security operations roles

Aarno Aukia · LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · World Congress 2026 Europe

Videos

See all

Related articles

See all