Esri

Security Operations Analyst

Esri$70K — $114K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 2+ years of experience in cybersecurity with practical skills in security monitoring and incident investigation.
  • Proficient in analyzing diverse data types including endpoint, identity, network, cloud, and log data for security threats.
  • Familiarity with SIEM and EDR tools, along with established triage workflows and security telemetry analysis.
  • Solid understanding of networking principles, operating systems, identity and access management, and cloud security basics.
  • Understanding of cyber threat intelligence, including adversary tactics, techniques, and procedures (TTPs).
  • Strong writing skills for effective documentation of investigations and incident records for various audiences.
  • U.S. citizenship is required, along with the ability and willingness to obtain a security clearance.

Responsibilities

  • Monitor and manage alerts across multiple security platforms in the SOC.
  • Independently triage and investigate alerts, differentiating between threats and benign activity.
  • Support the complete incident lifecycle, from investigation to remediation and closure.
  • Escalate incidents providing clear evidence and actionable next steps.
  • Utilize playbooks to identify opportunities for improving alert quality and analyst efficiency.
  • Apply threat intelligence to enrich investigations and identify potential vulnerabilities.
  • Collaborate with security engineers to develop detections and improve overall incident response.

Benefits

  • Comprehensive medical, dental, and vision insurance for employees and their families.
  • 401(k) and profit-sharing programs to support retirement savings.
  • Minimum of 80 hours of vacation leave annually, plus twelve paid holidays each year.
  • Opportunities for personal and professional development in a supportive environment.
Full Job Description
Overview

The Enterprise Security Analyst II is a hands-on Security Operations Center (SOC) role responsible for monitoring alerts, investigating security events, supporting incident response, and improving security operations. This role also applies cyber threat intelligence and threat hunting practices to add context to investigations, identify emerging threats, and strengthen detection and response capabilities. Primary schedule is business hours, Monday through Friday. Participation in an after-hours on-call rotation is expected after onboarding and demonstrated familiarity with systems, tools, and response procedures.

Responsibilities

Security Operations and Incident Response
  • Monitor and manage the SOC alert queue across endpoint, identity, network, email, cloud, and log monitoring platforms
  • Independently triage and investigate security alerts and events, distinguishing confirmed threats from benign activity using available evidence and telemetry
  • Support the full incident lifecycle, including investigation, escalation, containment support, remediation follow-up, documentation, and closure
  • Escalate incidents with clear evidence, impact assessment, and recommended next steps
  • Apply playbooks and runbooks while identifying opportunities to improve alert quality, response consistency, automation, and analyst enablement

Threat Intelligence and Threat Hunting
  • Analyze relevant threat intelligence to identify threats, campaigns, vulnerabilities, and adversary behaviors that may affect the organization
  • Enrich alerts and investigations with context about threat actors, malware, indicators, vulnerabilities, and attack techniques
  • Assist with threat hunts across endpoint, identity, network, cloud, and application telemetry
  • Use MITRE ATT&CK to support investigations, communicate adversary behavior, and identify detection gaps
  • Partner with security engineers and analysts to turn relevant intelligence into detections, hunts, watchlists, playbooks, blocking recommendations, or response improvements

Requirements
  • 2+ years of cybersecurity experience with hands-on involvement in security monitoring, alert triage, and incident investigation
  • Experience analyzing endpoint, identity, network, cloud, email, and log data to identify suspicious or malicious activity
  • Working knowledge of SIEM and EDR platforms, common triage workflows, and security telemetry analysis
  • Strong understanding of networking, operating systems, identity and access concepts, cloud security fundamentals, and core security protocols
  • Working knowledge of cyber threat intelligence concepts, including indicators, threat actors, campaigns, vulnerabilities, and adversary tactics, techniques, and procedures
  • Ability to write clear investigation notes, incident records, intelligence summaries, and recommendations for technical and non-technical audiences
  • U.S. citizenship is mandatory
  • Ability and willingness to obtain security clearance
  • Bachelors in Cybersecurity, Information Technology, Computer Science, or a related STEM degree

Recommended Qualifications
  • Experience performing threat intelligence analysis, threat hunting, incident response, or security engineering in an enterprise environment
  • Experience converting threat intelligence into detections, hunts, watchlists, playbooks, response actions, or mitigation recommendations
  • Experience researching threat actors, malware, ransomware activity, vulnerability exploitation, or emerging attack techniques
  • Familiarity with SOAR platforms, detection engineering practices, automation, scripting, or query languages such as PowerShell, Python, KQL, or SPL
  • Relevant certifications such as CompTIA Security+, GCIH, GCED, GCIA, GCFA, GCTI, CTIA, or Microsoft security certifications

#LI-TM1

#LI-onsite

Total Rewards

Esri's competitive total rewards strategy includes industry-leading health and welfare benefits: medical, dental, vision, basic and supplemental life insurance for employees (and their families), 401(k) and profit-sharing programs, minimum accrual of 80 hours of vacation leave, twelve paid holidays throughout the calendar year, and opportunities for personal and professional growth. Base salary is one component of our total rewards strategy. Compensation decisions and the base range for this role take into account many factors including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs.

A reasonable estimate of the base salary range is

$70,304-$114,400 USD

About Esri

Esri is a global leader in geographic information system (GIS) software, location intelligence, and mapping. The company was founded in 1969 and is headquartered in Redlands, California. Esri's software is used by governments, businesses, and non-profit organizations worldwide to analyze and visualize data in order to make better decisions. The company's flagship product, ArcGIS, is a powerful mapping and analytics platform that allows users to create, manage, and share geographic information. Esri has a strong commitment to sustainability and social responsibility, and works to promote environmental stewardship and social equity through its products and services.
Learn more about Esri
Size
11,000 employees
Industry
Founded
1969

Similar Jobs

More Jobs at Esri

More Information Technology Jobs

Find similar Security Operations Analyst jobs: