> Markdown version of [/jobs/ext/2196089-security-operations-analyst](https://www.wearedevelopers.com/jobs/ext/2196089-security-operations-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Operations Analyst - **Company:** MultiPlan - **Location:** McLean, VA, United States - **Experience:** Experienced - **Salary:** $95,000.0 - $105,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Amazon Web Services, Microsoft Azure, Cloud Computing Security, CompTIA Security+, Cyber Security, Linux, Identity and Access Management, Information Technology Operations, Intrusion Detection Systems, Network Security, Microsoft Security Essentials, Phishing, Microsoft SharePoint, Security Information and Event Management, Software Vulnerability Management, Google Cloud, Cloud Platform System, In-Plane Switching (IPS), Mitre Att&ck, Software Troubleshooting, Cyber Threat Analysis, Information Technology, Cybercrime, Splunk, Security Orchestration, Automation & Response, Servicenow - **Published:** August 23, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/18048187?backUrl=%2Fcareer%2F18048187%2FSecurity-Operations-Analyst-Virginia-Mclean ## About the Role * Bachelor's degree in Cybersecurity, Information Security, Information Technology, Computer Science, or related field; or equivalent combination of education and experience. * 3+ years of cybersecurity, information security, IT operations, or SOC experience (Level I/II). * Experience investigating security alerts and incidents. * Familiarity with SIEM platforms and security monitoring tools. * (Preferred) Security Information and Event Management (SIEM) platforms (Splunk) * (Preferred) Endpoint Detection and Response (EDR) solutions (Crowdstrike) * (Preferred) Reliaquest managed detection and response (MDR) and Servicenow experience * Microsoft 365 and Azure security technologies * Network security concepts and protocols * Identity and Access Management (IAM) * Windows, Linux, and cloud environments * MITRE ATT&CK framework * Incident response methodologies * Strong troubleshooting and investigative abilities * Ability to prioritize multiple security events in a fast-paced environment * Excellent attention to detail * Strong written and verbal communication skills Preferred Qualifications: * CompTIA Security+ * CompTIA CySA+ * GIAC Certified Incident Handler (GCIH) * GIAC Security Essentials (GSEC) * SSCP * Certified Ethical Hacker (CEH) * SC-200 Security Operations Analyst * CISSP * Experience with Splunk, Microsoft core infrastructure technologies (Entra/Active Directory, Sharepoint, Copilot, etc.), CrowdStrike, or similar platforms. * Experience with SOAR and security automation technologies. * Exposure to cloud security platforms (Azure, AWS, GCP). * Knowledge of NIST Cybersecurity Framework and incident response best practices. ## Description JOB SUMMARY: The SOC Analyst is responsible for monitoring, detecting, investigating, and responding to cybersecurity threats across the organization's technology environment. This role serves as a frontline defender against cyber threats by analyzing security alerts, conducting incident investigations, and escalating security events as appropriate. The analyst works closely with IT, infrastructure, cloud, and application teams to protect organizational assets, maintain security monitoring capabilities, and strengthen the overall security posture., Security Monitoring & Detection * Monitor security events and alerts generated by SIEM, EDR, IDS/IPS, email security, cloud security, and other security tools. * Analyze and triage security alerts to determine legitimacy, severity, and business impact. * Identify indicators of compromise (IOCs), suspicious behavior, and emerging threats. * Perform continuous threat monitoring and situational awareness activities. Incident Response * Investigate cybersecurity incidents including malware infections, phishing attacks, account compromises, insider threats, and unauthorized access attempts. * Execute incident response procedures and playbooks. * Document findings, actions taken, and lessons learned. * Coordinate containment, eradication, and recovery activities with appropriate stakeholders. * Escalate significant incidents according to established procedures. Threat Hunting & Intelligence * Utilize threat intelligence feeds to enrich investigations. * Research emerging threats, vulnerabilities, and attack techniques. * Develop and refine detection use cases based on threat intelligence and incident trends. Security Operations * Support vulnerability management efforts by validating findings and tracking remediation. * Assist with security tool administration and tuning. * Review and improve alerting logic to reduce false positives. * Participate in security assessments and operational readiness activities. * Support audit and compliance initiatives as required. * And other duties as assigned. Documentation & Reporting * Maintain accurate incident records, investigation notes, and operational metrics. * Prepare reports on security incidents, trends, and findings. * Contribute to development and maintenance of standard operating procedures (SOPs). * Provide security recommendations to business and technical stakeholders. Collaboration * Work closely with infrastructure, networking, cloud, and identity teams. * Participate in on-call rotations and after-hours incident response activities when required. * Support user awareness efforts through identification of phishing and social engineering trends. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)