> Markdown version of [/jobs/ext/3431425-detection-monitoring-analyst](https://www.wearedevelopers.com/jobs/ext/3431425-detection-monitoring-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Detection & Monitoring Analyst - **Company:** Ardent, Inc. - **Location:** Atlanta, GA, United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cloud Engineering, Cyber Security, Query Languages, Issue Tracking Systems, Intrusion Detection and Prevention, Network Security, Packet Analyzer, Anti-Phishing, Zero Trust Network Access, Security Information and Event Management, Data Logging, Mitre Att&ck, Cyber Threat Analysis, Information Technology, Security Orchestration, Automation & Response - **Published:** September 16, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=2fc084910319d17c ## About the Role * Bachelor's degree in cybersecurity, information assurance, computer science, or related field, or equivalent SOC experience. * Proof of relevant professional certifications such as CISSP, CISA, PMP, CEH, or other relevant certifications. * 4 years of hands-on SOC, detection engineering, intrusion analysis, continuous monitoring, incident response, network security, or threat-hunting experience. * Experience with SIEM and EDR/XDR platforms, log query languages, network telemetry, MITRE ATT&CK mapping, case management, and incident escalation. * Ability to document expected versus observed results precisely and maintain evidence integrity. * Knowledge of NIST CSF Detect outcomes and access-control telemetry., * SIEM content development, detection-as-code, or security analytics experience. * Experience with cloud-native logging, identity telemetry, SOAR, packet capture, threat intelligence, and forensic investigation. * Zero Trust monitoring or FedRAMP continuous-monitoring experience. * Government SOC or regulated-sector experience. Due to the nature of the work we support, all candidates in consideration for this role must be willing to undergo the government issued background investigation process. ## Description Ardent is seeking a Detection & Monitoring Analyst that validates whether authorized test activity generates accurate security telemetry and whether agency detection processes identify, triage, escalate, and document events according to approved criteria. The analyst serves as the defender-side specialist connecting simulated activity to SIEM, EDR, network, identity, and ticketing evidence across a potentially broad multi-agency environment., * Monitor approved testing activity across SIEM, EDR/XDR, identity, endpoint, network, cloud, and ticketing systems. * Validate whether expected signals are generated, correlated, enriched, prioritized, and represented accurately in alerts. * Trace analyst triage, escalation, communications, and handling timelines against OCIG-approved criteria and documented agency expectations. * Perform alert investigation, packet and network traffic analysis, log correlation, IOC review, malware or phishing analysis when in approved scope, and event-timeline reconstruction. * Develop or recommend detection logic improvements, use cases, correlation rules, dashboards, and tuning actions while clearly separating recommendations from factual test results. * Preserve screenshots, alerts, queries, logs, timestamps, ticket records, analyst actions, and annotations in controlled evidence packages. * Identify telemetry gaps, blind spots, false negatives, inaccurate severity, weak correlation, and broken escalation paths. * Support vulnerability, remediation, and incident-specific reviews requested through OCIG. * Help deliver knowledge-transfer sessions on detection validation and evidence interpretation.