
Security Monitoring – SIEM Analyst
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Oversee SIEM dashboards and event queues to detect suspicious or anomalous cybersecurity activities.
• Correlate logs from firewalls, endpoints, cloud services, authentication platforms, and various security data sources.
• Investigate events and alerts to assess severity, likelihood of threats, and potential escalation paths.
• Assist in gathering information and conducting preliminary triage for cybersecurity incidents.
• Analyze user activities, authentication logs, and system behaviors for indicators of compromise.
• Aid in fine-tuning SIEM rules, correlation logic, thresholds, and suppression patterns.
• Document details of security events, timelines, and findings from investigations.
• Elevate confirmed or high-risk events to the incident response team, including thorough analysis.
• Maintain daily and weekly reports on events, trends, and identified threats.
• Engage in continuous monitoring and security operations cycles in accordance with DoD RMF requirements.
• Contribute to the development of SOC playbooks, detection use cases, and monitoring procedures.
• Must possess an active Top Secret clearance, validated by a Tier 5 background investigation.
• Bachelor’s degree in Information Security, Information Technology, Digital Forensics, or a related discipline.
• At least 5 years of experience in security monitoring, SOC operations, threat analysis, or cybersecurity investigations.
• Proficient in analyzing logs and events from SIEM platforms.
• Skilled in identifying suspicious activities, anomalous behaviors, or indicators of compromise (IOCs).
• Experienced in correlating data from multiple systems to evaluate potential threats.
• Capable of documenting findings and escalating incidents to senior cybersecurity personnel.
• Strong knowledge of SIEM platforms, log aggregation tools, and event correlation techniques.
• Familiarity with common attack vectors, threat behaviors, and MITRE ATT&CK methodologies.
• Understanding of DoD cybersecurity monitoring, continuous monitoring principles, and incident escalation protocols.
• Knowledgeable about logs generated by operating systems, firewalls, authentication systems, and cloud platforms.
• Required to hold a Security+ certification.
• Excellent analytical, investigative, and problem-solving skills.
• Outstanding written and verbal communication abilities.
• Capacity to thrive in a fast-paced SOC environment while managing multiple active investigations.
• Exceptional attention to detail.
• Ability to work collaboratively with cybersecurity, engineering, and incident response teams.
• Regular full-time employment.
• Requirement for an active Top Secret clearance supported by a Tier 5 background investigation.
• Equal Employment Opportunity and Affirmative Action employer.
• Protections for pay transparency.
Sicredi
Sicredi
NBCUniversal
Get handpicked remote jobs straight to your inbox weekly.