Security Operations Analyst in New York at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Operations Analyst based in the United States.
As a Security Operations Analyst, you will help protect critical Department of Defense systems through hands-on cybersecurity monitoring and incident response.
You will work across endpoint, network, cloud, and secure-access environments using modern security technologies and monitoring platforms.
The role focuses on detecting threats, investigating security events, managing vulnerabilities, and escalating incidents according to established procedures.
You will use SIEM, vulnerability management, endpoint security, firewall, and cloud security tools to maintain a strong security posture.
You will also contribute to continuous monitoring reports, security dashboards, and KPI reporting for program leadership.
The position offers a structured and collaborative environment where clear escalation, operational discipline, and continuous learning are highly valued.
This is an opportunity to strengthen your cybersecurity expertise while supporting mission-critical defense operations.
- Monitor and analyze security events and alerts using Elastic Security SIEM, identifying suspicious activity and potential threats.
- Conduct vulnerability scans using Tenable SecurityCenter (Tenable SC) and assess cloud workloads through Tenable Cloud Security.
- Manage and enforce endpoint security policies using Trellix ePO and/or Microsoft Defender for Endpoint (MDE).
- Monitor network security activity across Palo Alto Next-Generation Firewalls (NGFWs).
- Analyze secure-access traffic and activity through Zscaler Private Access (ZPA) and Zscaler Internet Access (ZIA).
- Detect, investigate, document, and appropriately escalate security incidents in accordance with established incident response procedures.
- Support continuous security monitoring across endpoint, network, cloud, and access environments.
- Develop and maintain security monitoring reports and contribute to security posture dashboards.
- Track, analyze, and present cybersecurity KPIs and operational metrics to program leadership.
- Collaborate with security and technical teams to identify emerging risks and support appropriate remediation activities.
- Maintain accurate documentation of security events, findings, vulnerabilities, and response activities.
- Travel to Scott Air Force Base on a quarterly basis as required.
- Active Secret or Top Secret security clearance is required.
- 3–5 years of professional experience in a Security Operations Center (SOC) or comparable security operations environment.
- Hands-on experience working with a Security Information and Event Management (SIEM) platform; Elastic Security experience is strongly preferred.
- Working knowledge of vulnerability scanning and management tools, with Tenable SC experience preferred.
- Familiarity with network security monitoring and firewall technologies.
- DoD 8140.03M DCWF Basic Tier certification, with one of the following: CC, GDSA, or GISF.
- Ability to meet applicable DoD 8140 interim education options.
- Strong understanding of cybersecurity monitoring, threat detection, incident escalation, and security operations processes.
- Ability to analyze technical security information, identify potential risks, and communicate findings clearly.
- Strong documentation, analytical, organizational, and problem-solving skills.
- Ability to work effectively within a structured team environment and follow established security procedures.
- Preferred: Elastic Certified Analyst or Elastic Certified Engineer certification.
- Preferred: Experience with Palo Alto NGFW and/or Zscaler platforms.
- Preferred: Experience or exposure to cloud workload security monitoring.
- Preferred: Bachelor’s degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, Software Engineering, or a related field.
- Preferred: DoD 8140.03M DCWF Intermediate Tier certification, such as CEH(P), ECIH, GRID, RCCE Level 1, CBROPS, CCSP, CEH, Cloud+, FITSP-O, GCED, GCIH, GSEC, PenTest+, or Security+.
- Willingness and ability to travel locally up to approximately 10%, including quarterly travel requirements.
- National salary range of $75,200–$158,100 per year, with final compensation determined by factors such as location, relevant experience, skills, education, certifications, and applicable contract requirements.
- Fully remote position available across any US state, with quarterly travel to Scott Air Force Base required.
- Comprehensive healthcare and wellness benefits.
- Retirement and financial benefits, including a 401(k) savings plan.
- Flexible paid time off designed to support work-life balance.
- Company holidays and time-off benefits.
- Family support benefits and resources.
- Continuing education and professional learning opportunities.
- Career development resources designed to support ongoing technical growth.
- Opportunity to work with modern cybersecurity technologies across endpoint, network, cloud, and secure-access environments.
- Mission-driven work supporting critical national defense and security operations.
- Collaborative environment focused on integrity, trust, innovation, and continuous professional development.