SIEM / Threat Monitoring Analysts

Blue Rose Consulting Group
Washington, DC, United States
8 days ago
Apply on www.juju.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Audit Trail Cyber Security Databases Digital Forensics Disaster Recovery Network Security Open Source Intelligence Security Information and Event Management Enterprise Software Applications Cyber Threat Analysis SC Clearance Information Technology
+2 more
Hardware Infrastructure Splunk

Job description

Blue Rose Consulting Group, Inc. (Blue Rose) is a certified HUBZone and Service-Disabled Veteran-Owned Small Business supporting Federal customers with mission-focused technology, professional services, and operational support. We are building a team for the anticipated Department of State Global Mission Operations Support (GMOS) effort supporting the Bureau of Diplomatic Technology, Enterprise Applications Directorate, Office of Consular Systems and Technology. About the Role

Monitor, analyze, correlate, and investigate security events using SIEM, log-management, threat intelligence, OSINT, and incident-response processes. This position supports the Department of State Consular Affairs global information technology environment, which includes domestic and overseas facilities, on-premises infrastructure, cloud platforms, applications, databases, and enterprise support services. This is a contingent position based on contract award and final customer requirements. What You’ll Do

  • Monitor SIEM alerts, logs, audit trails, network events, endpoint events, and other telemetry for suspicious or policy-violating activity.

  • Triage, correlate, investigate, document, and escalate potential security incidents in accordance with established procedures.

  • Develop and tune SIEM searches, dashboards, correlation rules, alerts, reports, and use cases to improve detection quality.

  • Use open-source intelligence, threat intelligence, and digital-forensics techniques to enrich investigations and assess potential impact.

  • Coordinate with security, infrastructure, network, application, and incident-response teams during investigation, containment, recovery, and lessons-learned activities.

  • Maintain incident timelines, case notes, evidence, metrics, trends, and management reports.

  • Identify recurring patterns, coverage gaps, false positives, and opportunities to improve monitoring and response processes.

Requirements

  • 3+ years of SIEM administration, security monitoring, threat analysis, or SOC experience.

  • Hands-on experience with Splunk or another enterprise SIEM/log-management platform.

  • Experience triaging and investigating alerts, correlating events, and escalating potential incidents.

  • Familiarity with incident response, digital forensics, OSINT, threat intelligence, and recovery procedures.

  • Ability to work shift-based operations when required and communicate clearly during high-priority incidents.

  • Active Secret clearance; Top Secret may be preferred or required for certain assignments. Preferred Qualifications

  • Splunk, Security+, CySA+, GCIH, GCIA, or equivalent certification.

  • Experience supporting Federal or Department of State security operations.

  • Experience with cloud logs, endpoint detection and response, network security monitoring, or automation. Compensation & Benefits

Benefits & conditions

Compensation will be commensurate with experience, qualifications, assigned work location, and final contract requirements. Blue Rose offers a competitive benefits package for eligible full-time employees. Specific compensation and benefit details will be provided during the recruiting process.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:05 min

Automating threat detection with SIEM solutions

Antonio De Mello +1 · LIVE

1:53 min

Adopting Kubernetes and GitOps for standardized deployment environments

Lian Li · World Congress 2022

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · World Congress 2022

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:56 min

Leveraging GitOps for AI auditing and instant rollbacks

Jaroslaw Gajewski Jaroslaw Gajewski · World Congress 2026 Europe

Videos

See all

Related articles

See all