> Markdown version of [/jobs/ext/3075625-siem-threat-monitoring-analysts](https://www.wearedevelopers.com/jobs/ext/3075625-siem-threat-monitoring-analysts). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SIEM / Threat Monitoring Analysts - **Company:** Blue Rose Consulting Group - **Location:** Washington, DC, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Audit Trail, Cyber Security, Databases, Digital Forensics, Disaster Recovery, Network Security, Open Source Intelligence, Security Information and Event Management, Enterprise Software Applications, Cyber Threat Analysis, SC Clearance, Information Technology, Hardware Infrastructure, Splunk - **Published:** September 25, 2026 - **Apply:** https://www.juju.com/job/16_24b2d0563 ## About the Role * 3+ years of SIEM administration, security monitoring, threat analysis, or SOC experience. * Hands-on experience with Splunk or another enterprise SIEM/log-management platform. * Experience triaging and investigating alerts, correlating events, and escalating potential incidents. * Familiarity with incident response, digital forensics, OSINT, threat intelligence, and recovery procedures. * Ability to work shift-based operations when required and communicate clearly during high-priority incidents. * Active Secret clearance; Top Secret may be preferred or required for certain assignments. Preferred Qualifications * Splunk, Security+, CySA+, GCIH, GCIA, or equivalent certification. * Experience supporting Federal or Department of State security operations. * Experience with cloud logs, endpoint detection and response, network security monitoring, or automation. Compensation & Benefits ## Description Blue Rose Consulting Group, Inc. (Blue Rose) is a certified HUBZone and Service-Disabled Veteran-Owned Small Business supporting Federal customers with mission-focused technology, professional services, and operational support. We are building a team for the anticipated Department of State Global Mission Operations Support (GMOS) effort supporting the Bureau of Diplomatic Technology, Enterprise Applications Directorate, Office of Consular Systems and Technology. About the Role Monitor, analyze, correlate, and investigate security events using SIEM, log-management, threat intelligence, OSINT, and incident-response processes. This position supports the Department of State Consular Affairs global information technology environment, which includes domestic and overseas facilities, on-premises infrastructure, cloud platforms, applications, databases, and enterprise support services. This is a contingent position based on contract award and final customer requirements. What You'll Do * Monitor SIEM alerts, logs, audit trails, network events, endpoint events, and other telemetry for suspicious or policy-violating activity. * Triage, correlate, investigate, document, and escalate potential security incidents in accordance with established procedures. * Develop and tune SIEM searches, dashboards, correlation rules, alerts, reports, and use cases to improve detection quality. * Use open-source intelligence, threat intelligence, and digital-forensics techniques to enrich investigations and assess potential impact. * Coordinate with security, infrastructure, network, application, and incident-response teams during investigation, containment, recovery, and lessons-learned activities. * Maintain incident timelines, case notes, evidence, metrics, trends, and management reports. * Identify recurring patterns, coverage gaps, false positives, and opportunities to improve monitoring and response processes. ## Related Videos - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)