Security Operations Analyst
Environmental Systems Research InstituteSecurity Operations Analyst
Environmental Systems Research InstituteLocation
Vienna, VA, Redlands, CA
Type
Full-time
Posted
9/4/2026
Compensation
$70,304 per year
Job description
The Enterprise Security Analyst II is a hands-on role within the Security Operations Center (SOC) focused on monitoring alerts, investigating security events, and supporting incident response. This position emphasizes the application of cyber threat intelligence and threat hunting practices to enhance detection and response capabilities. The analyst will work primarily during business hours, with an expectation to participate in an after-hours on-call rotation. The role requires collaboration with security engineers and analysts to improve security operations.
Requirements
- 2+ years of cybersecurity experience with hands-on involvement in security monitoring, alert triage, and incident investigation.
- Experience analyzing endpoint, identity, network, cloud, email, and log data to identify suspicious or malicious activity.
- Working knowledge of SIEM and EDR platforms, common triage workflows, and security telemetry analysis.
- Strong understanding of networking, operating systems, identity and access concepts, cloud security fundamentals, and core security protocols.
- Working knowledge of cyber threat intelligence concepts, including indicators, threat actors, campaigns, vulnerabilities, and adversary tactics, techniques, and procedures.
- Ability to write clear investigation notes, incident records, intelligence summaries, and recommendations for technical and non-technical audiences.
- U.S. citizenship is mandatory.
- Ability and willingness to obtain security clearance.
- Bachelors in Cybersecurity, Information Technology, Computer Science, or a related STEM degree.
Responsibilities
- Monitor and manage the SOC alert queue across endpoint, identity, network, email, cloud, and log monitoring platforms.
- Independently triage and investigate security alerts and events, distinguishing confirmed threats from benign activity using available evidence and telemetry.
- Support the full incident lifecycle, including investigation, escalation, containment support, remediation follow-up, documentation, and closure.
- Escalate incidents with clear evidence, impact assessment, and recommended next steps.
- Apply playbooks and runbooks while identifying opportunities to improve alert quality, response consistency, automation, and analyst enablement.
- Analyze relevant threat intelligence to identify threats, campaigns, vulnerabilities, and adversary behaviors that may affect the organization.
- Enrich alerts and investigations with context about threat actors, malware, indicators, vulnerabilities, and attack techniques.
- Assist with threat hunts across endpoint, identity, network, cloud, and application telemetry.
- Use MITRE ATT&CK to support investigations, communicate adversary behavior, and identify detection gaps.
- Partner with security engineers and analysts to turn relevant intelligence into detections, hunts, watchlists, playbooks, blocking recommendations, or response improvements.
H-1B filing history
Public USCIS petition and DOL LCA counts · latest USCIS FY2026, LCA FY2026
Filing entity: Environmental Systems Research Institute Inc
As of Aug 23, 2026
Initial approvals
44
FY2026
Approval rate
98.9%
FY2026
LCA certified
67
FY2026
Entry-level share
49.3%
FY2026
Initial approvals YoY
+3%
Trend
LCA certified YoY
-31%
Trend
Initial approvals by fiscal year
Approval rate by fiscal year
Continuing vs initial approvals
LCA certified positions by quarter
LCA certified positions by fiscal year
Based on public USCIS and DOL filings; not a sponsorship guarantee.
Is this posting expired or inaccurate?
