×
Register Here to Apply for Jobs or Post Jobs. X

Security Operations Analyst

Job in Washington, District of Columbia, 20022, USA
Listing for: Workstreet
Full Time position
Listed on 2026-10-02
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations, Network Security
Salary/Wage Range or Industry Benchmark: 90000 - 120000 USD Yearly USD 90000.00 120000.00 YEAR
Job Description & How to Apply Below

Get to know the
Security Services Team

We are the team our clients trust to be their eyes and ears around the clock, watching over their environments even when their own teams are offline. Our MDR function spans real-time monitoring and alert triage, threat detection and investigation, and incident analysis and response guidance, using the EDR, SIEM, IPS, WAF, and firewall platforms deployed across our client base to catch what automated rules miss and help clients stop incidents before they become breaches.

We don't just close tickets. Our analysts tune detection logic, document what they see, and elevate with the context client stakeholders need to act fast. If you want to build deep, hands-on detection and investigation experience across a wide range of client environments, and be part of a team that backs each other up on every shift, you'll be in good company here.

The Opportunity

Workstreet is seeking a Security Operations Analyst to join our Security Services team. This is a hands-on monitoring and investigation role: you'll triage and validate alerts, lead deep investigations across EDR, firewall, IPS, WAF, and SIEM tooling, and deliver clear, actionable findings and remediation guidance across our clients' environments, with clients owning execution of the actual response.

You'll work as part of a 24x7 rotating shift schedule, partnering directly with client stakeholders to keep detection coverage strong around the clock. The successful candidate will ramp into our detection stack and client environments quickly, taking ownership of shift-level monitoring, investigation quality, and escalation judgment within their first 30 days.

What you'll do
  • Execute real-time monitoring and triage - monitor alerts across EDR, firewall, IPS, WAF, and SIEM platforms, prioritizing severity and distinguishing true positives under time pressure.
  • Maintain 24x7 shift coverage - deliver continuous threat monitoring as part of a rotating shift schedule including assigned nights, weekends, and holidays.
  • Conduct deep incident investigations - correlate telemetry across EDR, network, and cloud log sources to determine root cause, scope, and indicators of compromise.
  • Deliver remediation guidance - provide clear incident analysis and containment recommendations to client teams who own response execution within their environments.
  • Tune detection logic and rules - refine SIEM correlation rules and detection logic to eliminate false positives and close security coverage gaps.
  • Maintain SOC playbooks and documentation - document investigation findings and incident timelines in case management systems while updating standard operating runbooks.
  • Drive cross-functional security alignment - partner with GRC engineers and vCISOs to ensure threat detection activity supports client compliance obligations.
  • Support shift handoffs and mentorship - execute seamless investigation handoffs across shift rotations while guiding junior analysts on investigative techniques.
Who you are
  • Experienced SOC analyst - bring 3+ years of hands-on experience monitoring, triaging, and investigating security alerts within a high-velocity SOC setting.
  • Multi-platform telemetry investigator - skilled at correlating data daily across EDR, firewall, IPS, WAF, and SIEM tools to trace root causes under pressure.
  • Autonomous incident owner - demonstrated ability to own complex investigations end to end and make sound escalation calls with minimal oversight.
  • Clear technical communicator - able to document findings and explain complex technical incidents in plain language directly to client stakeholders.
  • 24x7 rotation performer - willing and able to work a 24x7 rotating shift schedule, including nights, weekends, and holidays as assigned.
  • Collaborative shift operator - thrives in fast-paced team environments, backing up colleagues across shift transitions and maintaining operational continuity.
What help you succeed
  • Active security credentials - hold recognized industry designations such as CompTIA Security+, CySA+, GCIH, or equivalent credentials.
  • EDR and SIEM platform mastery - practical experience with EDR tools (Crowd Strike, Sentinel One, Defender) and SIEM solutions (Splunk, Microsoft Sentinel, Sumo Logic, Wazuh).
  • Tooling administration and tuning - experience configuring, maintaining, and tuning security platforms beyond day-to-day alert triage.
  • SOAR and automation scripting - proficiency writing Python or Power Shell scripts and developing SOAR playbooks to automate triage workflows.
  • MSSP…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary