Find Your Perfect Job

Job Search Results for SOC Analyst

Sort and Filter  | 6 Results for SOC Analyst  | Save This Search

Mar 25, 2026

Redmond, WA

|

Security Engineering

|

Contract

|

$41 - $51 (hourly estimate)

{"JobID":511194,"JobType":["Contract"],"EmployerID":null,"Location":{"Latitude":-122.12,"Longitude":47.68,"Distance":null},"State":"Washington","Zip":"98052","ReferenceID":"SEA-4e059988-e92a-4353-91b9-7279617fd551","PostedDate":"\/Date(1774472608000)\/","Description":"An employer is looking for a SOC analyst in the Washington, D.C. area. This team is responsible for the initial response and triage of security incidents across various customers. These incidents have well defined processes and documentation, however there need to be updates to this over time. The ideal candidate will have had experience in a SOC or similar environment engaging with multiple teams to resolve incidents. Every candidate must have an active Top Secret SCI with Polygraph. We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global\u0027s Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.","Title":"SOC Analyst","City":"Redmond","ExpirationDate":null,"PriorityOrder":0,"Requirements":"-1+ years\u0027 experience in a Security Operations Center or similar operations work-Experience working with TSG/SOPs to triage and respond to alerts as well as escalations-Experience with incident response-Active Top Secret SCI FSP Clearance-Experience working in a 24x7x365 environment","Skills":"-Security+, Certified Ethical Hacker, CISSP or CISM certifications","Industry":"Security Engineering","Country":"US","Division":"IT","Office":null,"IsRemoteJob":false,"IsInternalJob":false,"ExtraValues":null,"__RecordIndex":0,"__OrdinalPosition":0,"__Timestamp":0,"Status":null,"ApplicantCount":0,"SubmittalCount":0,"ApplicationToHireRatio":0,"JobDuration":null,"SalaryHigh":51.0000,"SalaryLow":40.8000,"PayRateOvertime":0,"PayRateStraight":0,"Filled":0,"RemainingOpenings":0,"TotalOpenings":0,"Visa":null,"ClearanceType":null,"IsClearanceRequired":false,"IsHealthcare":false,"IsRemote":false,"EndClient":null,"JobCreatedDate":"\/Date(-62135578800000)\/","JobModifiedDate":"\/Date(-62135578800000)\/"}

An employer is looking for a SOC analyst in the Washington, D.C. area. This team is responsible for the initial response and triage of security incidents across various customers. These incidents... have well defined processes and documentation, however there need to be updates to this over time. The ideal candidate will have had experience in a SOC or similar environment engaging with multiple teams to resolve incidents. Every candidate must have an active Top Secret SCI with Polygraph. We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Mar 31, 2026

Houston, TX

|

Security Engineering

|

Contract

|

$62 - $77 (hourly estimate)

{"JobID":513167,"JobType":["Contract"],"EmployerID":null,"Location":{"Latitude":-95.38,"Longitude":29.76,"Distance":null},"State":"Texas","Zip":"77056","ReferenceID":"HOU-25fae8b4-01b5-419a-93c2-bcb69a04efa5","PostedDate":"\/Date(1774979648000)\/","Description":"An employer in the Galleria area of Houston, Texas is seeking a Lead SOC Analyst to join their team. They currently have a global SOC team and are trying to mimic the structure they have in Australia. Right now, there are 2 Leads in Houston overseeing the international team (North and South America) and this person will take the 3rd Lead spot. Their hours will be Monday-Friday 8A-5:30 PM and must sit onsite 3 days a week (their choice of day). Right now, the team works 9/80s and will be off every other Friday. The general rule, is 60% working in office and 40% working from home. This can change depending on what is going on with the team. Most people are onsite 3 days a week. They do allow flexibility as well - this is to be discussed with the manager ahead of time. They will also be on an on-call rotation every 3 weeks and their shift is Thursday-Thursday. They do a follow the sun schedule and pass off to the team in Australia accordingly. This person will be responsible for helping lead a team of 5+ SOC analysts and needs to have experience managing and mentoring junior analysts. This person will be the first escalation point for all major incidents. They need to have extensive threat intelligence review and assessment experience, strong vulnerability management experience and great written and verbal communication as they will provide communication reviews. This position pays between $70-$80/hr depending on skillset and experience.We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global\u0027s Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.","Title":"Lead SOC Analyst","City":"Houston","ExpirationDate":null,"PriorityOrder":0,"Requirements":"5+ years of experience in a Senior SOC Analyst position where they are the major incident escalation point2+ years of experience in a Lead SOC Analyst position managing a team of Junior AnalystsExtensive experience in Threat Intelligence Reviews and AssessmentsExtensive experience in Vulnerability Management (need to have lead a team while doing this)Extensive Incident Response experience","Skills":"Any certifications","Industry":"Security Engineering","Country":"US","Division":"IT","Office":null,"IsRemoteJob":false,"IsInternalJob":false,"ExtraValues":null,"__RecordIndex":0,"__OrdinalPosition":0,"__Timestamp":0,"Status":null,"ApplicantCount":0,"SubmittalCount":0,"ApplicationToHireRatio":0,"JobDuration":null,"SalaryHigh":77.0000,"SalaryLow":61.6000,"PayRateOvertime":0,"PayRateStraight":0,"Filled":0,"RemainingOpenings":0,"TotalOpenings":0,"Visa":null,"ClearanceType":null,"IsClearanceRequired":false,"IsHealthcare":false,"IsRemote":false,"EndClient":null,"JobCreatedDate":"\/Date(-62135578800000)\/","JobModifiedDate":"\/Date(-62135578800000)\/"}

An employer in the Galleria area of Houston, Texas is seeking a Lead SOC Analyst to join their team. They currently have a global SOC team and are trying to mimic the structure they have in... Australia. Right now, there are 2 Leads in Houston overseeing the international team (North and South America) and this person will take the 3rd Lead spot. Their hours will be Monday-Friday 8A-5:30 PM and must sit onsite 3 days a week (their choice of day). Right now, the team works 9/80s and will be off every other Friday. The general rule, is 60% working in office and 40% working from home. This can change depending on what is going on with the team. Most people are onsite 3 days a week. They do allow flexibility as well - this is to be discussed with the manager ahead of time. They will also be on an on-call rotation every 3 weeks and their shift is Thursday-Thursday. They do a follow the sun schedule and pass off to the team in Australia accordingly. This person will be responsible for helping lead a team of 5+ SOC analysts and needs to have experience managing and mentoring junior analysts. This person will be the first escalation point for all major incidents. They need to have extensive threat intelligence review and assessment experience, strong vulnerability management experience and great written and verbal communication as they will provide communication reviews. This position pays between $70-$80/hr depending on skillset and experience.We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Jan 06, 2026

Austin, TX

|

Security Engineering

|

Contract

|

$34 - $42 (hourly estimate)

{"JobID":479430,"JobType":["Contract"],"EmployerID":null,"Location":{"Latitude":-97.74,"Longitude":30.26,"Distance":null},"State":"Texas","Zip":"78751","ReferenceID":"BAL-7ce78600-a566-475a-a720-fc3c009fa82e","PostedDate":"\/Date(1767740557000)\/","Description":"A client of Insight Global is looking for a SOC Analyst to weekends FULLY onsite in Austin, TX. In this role, you will actively monitor and analyze security events using one or more SIEM platforms, creating custom dashboards and reports as needed. You?ll research events of interest, assess threats, and apply intrusion response techniques through detailed network traffic analysis and impact assessments. Daily tasks include interpreting data from network tools, performing packet-level analysis with tools, and leveraging your knowledge of TCP/IP protocols, DNS, routing, and network architecture. You will apply cybersecurity principles, encryption concepts, and access control mechanisms while following established SOC processes for escalation, incident management, and change control. Familiarity with frameworks such as MITRE ATT\u0026CK, MITRE D3FEND, and the Cyber Kill Chain, as well as compliance standards and defense-in-depth strategies, is essential to ensure robust threat detection and response.Compensation:$30/hr to $35/hr.Exact compensation may vary based on several factors, including skills, experience, and education.Employees in this role will enjoy a comprehensive benefits package starting on day one of employment, including options for medical, dental, and vision insurance. Eligibility to enroll in the 401(k) retirement plan begins after 90 days of employment. Additionally, employees in this role will have access to paid sick leave and other paid time off benefits as required under the applicable law of the worksite location.We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global\u0027s Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.","Title":"Part-Time Weekend SOC Analyst","City":"Austin","ExpirationDate":null,"PriorityOrder":0,"Requirements":"?3-5 years of Security Incident Response, Security Operations Center, and/or threat analysis experience?Experience with SIEM tools, preferably MS Sentinel ?Familiar with Cyber kill chain and Mitre Attack?Demonstrated experience using either an enterprise and/or cloud Security SIEM technologies as an analyst?Ability to support and work across multiple customer and bespoke systems?Strong Documentation (SOP/Standard Operations Procedure) development?Understanding of Ticket Flow and how to read inbound and outbound traffic?CompTIA Security + certification (equivalent or higher)? Must be willing to work weekends, either 8AM to 8PM OR 8PM to 8AM","Skills":"","Industry":"Security Engineering","Country":"US","Division":"IT","Office":null,"IsRemoteJob":false,"IsInternalJob":false,"ExtraValues":null,"__RecordIndex":0,"__OrdinalPosition":0,"__Timestamp":0,"Status":null,"ApplicantCount":0,"SubmittalCount":0,"ApplicationToHireRatio":0,"JobDuration":null,"SalaryHigh":42.0000,"SalaryLow":33.6000,"PayRateOvertime":0,"PayRateStraight":0,"Filled":0,"RemainingOpenings":0,"TotalOpenings":0,"Visa":null,"ClearanceType":null,"IsClearanceRequired":false,"IsHealthcare":false,"IsRemote":false,"EndClient":null,"JobCreatedDate":"\/Date(-62135578800000)\/","JobModifiedDate":"\/Date(-62135578800000)\/"}

A client of Insight Global is looking for a SOC Analyst to weekends FULLY onsite in Austin, TX. In this role, you will actively monitor and analyze security events using one or more SIEM platforms,... creating custom dashboards and reports as needed. You?ll research events of interest, assess threats, and apply intrusion response techniques through detailed network traffic analysis and impact assessments. Daily tasks include interpreting data from network tools, performing packet-level analysis with tools, and leveraging your knowledge of TCP/IP protocols, DNS, routing, and network architecture. You will apply cybersecurity principles, encryption concepts, and access control mechanisms while following established SOC processes for escalation, incident management, and change control. Familiarity with frameworks such as MITRE ATT&CK, MITRE D3FEND, and the Cyber Kill Chain, as well as compliance standards and defense-in-depth strategies, is essential to ensure robust threat detection and response.Compensation:$30/hr to $35/hr.Exact compensation may vary based on several factors, including skills, experience, and education.Employees in this role will enjoy a comprehensive benefits package starting on day one of employment, including options for medical, dental, and vision insurance. Eligibility to enroll in the 401(k) retirement plan begins after 90 days of employment. Additionally, employees in this role will have access to paid sick leave and other paid time off benefits as required under the applicable law of the worksite location.We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Mar 06, 2026

Vancouver, BC

|

Security Engineering

|

Contract

|

$45 - $56 (hourly estimate)

{"JobID":503527,"JobType":["Contract"],"EmployerID":null,"Location":{"Latitude":0,"Longitude":0,"Distance":null},"State":"British Columbia","Zip":"V6C 3","ReferenceID":"VAN-9a3be7fd-379e-4e87-8224-d25c8127c64a","PostedDate":"\/Date(1772823562000)\/","Description":"Senior Security Analyst - Detection EngineeringDetection Engineering Experience?8+ years of experience in cybersecurity, with at least 3+ years focused on detection engineering, threat detection, or security analytics?Proven experience designing, implementing, and maintaining high fidelity security detections across multiple telemetry sources?Strong understanding of how attacker behaviors manifest in logs, events, and telemetry across enterprise environmentsDetection Design \u0026 Framework Alignment?Demonstrated experience building detections aligned to MITRE ATT\u0026CK, focusing on behavior based rather than signature only detection?Ability to perform detection gap analysis and systematically improve coverage, quality, and resilience of detection content?Experience validating detections through testing, simulation, or retrospective analysis [Security O...n Engineer | Word]Security Tooling \u0026 Query Languages?Hands on experience with SIEM and EDR platforms, including ingesting and querying large volumes of security telemetry?Strong proficiency writing detection logic using KQL and working with Microsoft Sentinel/Defender?Experience using scripting languages such as Python, PowerShell, Bash, or JavaScript to support detection and automation workflowsAutomation \u0026 SOAR?Experience designing and implementing security automation using SOAR platforms to reduce manual effort and improve response consistency?Ability to automate alert enrichment, triage, IOC lookups, and ticketing workflows using Logic Apps?Experience integrating SIEM, EDR, threat intelligence, and case management systems into cohesive workflowsOperational Collaboration?Strong collaboration with SOC analysts, Incident Response, and Threat Intelligence teams to ensure detections are actionable and operationally effective?Ability to support incident response by providing deep technical insight into detections, telemetry, and attacker behaviorsOriginal contract set for 5 months with the opportunity to extendWe are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global\u0027s Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.","Title":"Senior Security Analyst - Detection Engineering - VAN OR SEA","City":"Vancouver","ExpirationDate":null,"PriorityOrder":0,"Requirements":"Senior Security Analyst - Detection EngineeringDetection Engineering Experience?8+ years of experience in cybersecurity, with at least 3+ years focused on detection engineering, threat detection, or security analytics?Proven experience designing, implementing, and maintaining high fidelity security detections across multiple telemetry sources?Strong understanding of how attacker behaviors manifest in logs, events, and telemetry across enterprise environmentsDetection Design \u0026 Framework Alignment?Demonstrated experience building detections aligned to MITRE ATT\u0026CK, focusing on behavior based rather than signature only detection?Ability to perform detection gap analysis and systematically improve coverage, quality, and resilience of detection content?Experience validating detections through testing, simulation, or retrospective analysis [Security O...n Engineer | Word]Security Tooling \u0026 Query Languages?Hands on experience with SIEM and EDR platforms, including ingesting and querying large volumes of security telemetry?Strong proficiency writing detection logic using KQL and working with Microsoft Sentinel/Defender?Experience using scripting languages such as Python, PowerShell, Bash, or JavaScript to support detection and automation workflowsAutomation \u0026 SOAR?Experience designing and implementing security automation using SOAR platforms to reduce manual effort and improve response consistency?Ability to automate alert enrichment, triage, IOC lookups, and ticketing workflows using Logic Apps?Experience integrating SIEM, EDR, threat intelligence, and case management systems into cohesive workflowsOperational Collaboration?Strong collaboration with SOC analysts, Incident Response, and Threat Intelligence teams to ensure detections are actionable and operationally effective?Ability to support incident response by providing deep technical insight into detections, telemetry, and attacker behaviorsOriginal contract set for 5 months with the opportunity to extend","Skills":"","Industry":"Security Engineering","Country":"Canada","Division":"IT","Office":null,"IsRemoteJob":false,"IsInternalJob":false,"ExtraValues":null,"__RecordIndex":0,"__OrdinalPosition":0,"__Timestamp":0,"Status":null,"ApplicantCount":0,"SubmittalCount":0,"ApplicationToHireRatio":0,"JobDuration":null,"SalaryHigh":56.0000,"SalaryLow":44.8000,"PayRateOvertime":0,"PayRateStraight":0,"Filled":0,"RemainingOpenings":0,"TotalOpenings":0,"Visa":null,"ClearanceType":null,"IsClearanceRequired":false,"IsHealthcare":false,"IsRemote":false,"EndClient":null,"JobCreatedDate":"\/Date(-62135578800000)\/","JobModifiedDate":"\/Date(-62135578800000)\/"}

Senior Security Analyst - Detection EngineeringDetection Engineering Experience?8+ years of experience in cybersecurity, with at least 3+ years focused on detection engineering, threat detection, or... security analytics?Proven experience designing, implementing, and maintaining high fidelity security detections across multiple telemetry sources?Strong understanding of how attacker behaviors manifest in logs, events, and telemetry across enterprise environmentsDetection Design & Framework Alignment?Demonstrated experience building detections aligned to MITRE ATT&CK, focusing on behavior based rather than signature only detection?Ability to perform detection gap analysis and systematically improve coverage, quality, and resilience of detection content?Experience validating detections through testing, simulation, or retrospective analysis [Security O...n Engineer | Word]Security Tooling & Query Languages?Hands on experience with SIEM and EDR platforms, including ingesting and querying large volumes of security telemetry?Strong proficiency writing detection logic using KQL and working with Microsoft Sentinel/Defender?Experience using scripting languages such as Python, PowerShell, Bash, or JavaScript to support detection and automation workflowsAutomation & SOAR?Experience designing and implementing security automation using SOAR platforms to reduce manual effort and improve response consistency?Ability to automate alert enrichment, triage, IOC lookups, and ticketing workflows using Logic Apps?Experience integrating SIEM, EDR, threat intelligence, and case management systems into cohesive workflowsOperational Collaboration?Strong collaboration with SOC analysts, Incident Response, and Threat Intelligence teams to ensure detections are actionable and operationally effective?Ability to support incident response by providing deep technical insight into detections, telemetry, and attacker behaviorsOriginal contract set for 5 months with the opportunity to extendWe are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Mar 06, 2026

Vancouver, BC

|

Security Engineering

|

Contract

|

$45 - $56 (hourly estimate)

{"JobID":503530,"JobType":["Contract"],"EmployerID":null,"Location":{"Latitude":0,"Longitude":0,"Distance":null},"State":"British Columbia","Zip":"V6Z 3","ReferenceID":"VAN-4a639bc7-b085-46ff-bf1e-394878ef0c2b","PostedDate":"\/Date(1772823380000)\/","Description":"Senior Security Analyst - Threat HunterWe are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global\u0027s Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.","Title":"Senior Security Analyst - Threat Detection (VAN or SEA)","City":"Vancouver","ExpirationDate":null,"PriorityOrder":0,"Requirements":"Threat Hunting \u0026 Security Operations Experience?8+ years of experience in Security Operations, with hands on experience in threat hunting, SOC analysis, or incident response?Demonstrated experience conducting proactive threat hunts across endpoint, identity, network, cloud, and application telemetry?Strong understanding of adversary behaviors, tactics, and techniques, and how they manifest in enterprise environmentsThreat Intelligence \u0026 Hunting Integration?Experience consuming and operationalizing actionable threat intelligence to drive hypothesis based threat hunts?Ability to collaborate closely with Threat Intelligence, Incident Response, and SOC teams to ensure findings translate into detections, response actions, and defensive improvements?Experience validating intelligence through data driven investigation rather than alert only workflowsDetection \u0026 Investigation Skills?Strong analytical skills with experience investigating complex or low signal security events?Familiarity with detection logic aligned to frameworks such as MITRE ATT\u0026CK?Ability to identify gaps in existing detections and recommend improvements based on hunt outcomesSecurity Tooling \u0026 Data Analysis?Hands on experience querying and analyzing telemetry from security tools such as SIEM, EDR, and logging platforms.?Experience and understanding of KQL, Microsoft Sentinel, Microsoft Defender, AWS, Azure?Ability to work directly with large datasets and telemetry to uncover anomalous or malicious activity?Experience contributing to or refining runbooks, playbooks, and investigation workflowsOperationalization \u0026 Reporting?Experience documenting threat hunt hypotheses, methodologies, findings, and outcomes?Ability to build and maintain metrics and reporting that communicate hunt value, trends, and risk to stakeholders?Comfortable transitioning validated findings into detections, response actions, or strategic improvementsCommunication \u0026 Collaboration?Strong written and verbal communication skills, with the ability to explain technical findings to both technical and non technical audiences?Proven ability to collaborate across Security Operations functions and influence improvements without direct authority","Skills":"","Industry":"Security Engineering","Country":"Canada","Division":"IT","Office":null,"IsRemoteJob":false,"IsInternalJob":false,"ExtraValues":null,"__RecordIndex":0,"__OrdinalPosition":0,"__Timestamp":0,"Status":null,"ApplicantCount":0,"SubmittalCount":0,"ApplicationToHireRatio":0,"JobDuration":null,"SalaryHigh":56.0000,"SalaryLow":44.8000,"PayRateOvertime":0,"PayRateStraight":0,"Filled":0,"RemainingOpenings":0,"TotalOpenings":0,"Visa":null,"ClearanceType":null,"IsClearanceRequired":false,"IsHealthcare":false,"IsRemote":false,"EndClient":null,"JobCreatedDate":"\/Date(-62135578800000)\/","JobModifiedDate":"\/Date(-62135578800000)\/"}

Senior Security Analyst - Threat HunterWe are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal... opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Mar 20, 2026

Jbsa Lackland, TX

|

Computer Engineering

|

Perm

|

$105k - $120k (estimate)

{"JobID":509303,"JobType":["Perm"],"EmployerID":null,"Location":{"Latitude":-98.5,"Longitude":29.45,"Distance":null},"State":"Texas","Zip":"78236","ReferenceID":"SAT-b654e78f-7c64-4906-91bd-b0ad21d1dc22","PostedDate":"\/Date(1774037501000)\/","Description":"Insight Global is seeking a TS/SCI Cyber Defense Operator to support and defend a one of the largest DoD Networks. This is a 24/7/365 mission and will work on base and will sit within a Sensitive Compartmented Information Facility (SCIF). Daily TS/SCI Cyber Defense Operator will:* Review all IDS/IPS alerts per DoD Customer Operating Instruction (OI) and checklists at the AOL, COOP, or Ops Floor. Conduct host security monitoring, alert review, and intrusion detection analysis for the DoD Network-SOC mission.* Comply with 3rd party MOU/MOA monitoring and reporting requirements. Analyze host DCO events to determine the necessity for higher level analysis and conduct an initial assessment of type and extent of intruder activities.* Monitor security sensors to analyze Intrusion Detection Systems (IDS) and Security Information and Event Management (SIEM) to identify and correlate security issues/events and review logs to identify intrusions for remediation. Correlate suspicious events with network events, if possible, and data stored within databases and other external DoD resources, including but not limited to Big Data Platform (BDP).* Record who, what, where, why and when for any identified suspicious activity in case management system (CMS) case to enable additional investigations* Conduct 24x7x365 near real-time network security monitoring and intrusion detection analysis for the networks, systems monitored using DoD CustomWe are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global\u0027s Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.","Title":"TS/SCI Cyber Defense Operator","City":"Jbsa Lackland","ExpirationDate":null,"PriorityOrder":0,"Requirements":"* TS/SCI Clearance* GCFA Certification (GIAC Certified Forensic Analyst)* Ability to work a 24/7/365 support mission* 1-4 years of experience working with DoD customers in Cyber Intrusion or Cyber Defense Operations/Analysis","Skills":"","Industry":"Computer Engineering","Country":"US","Division":"IT","Office":null,"IsRemoteJob":false,"IsInternalJob":false,"ExtraValues":null,"__RecordIndex":0,"__OrdinalPosition":0,"__Timestamp":0,"Status":null,"ApplicantCount":0,"SubmittalCount":0,"ApplicationToHireRatio":0,"JobDuration":null,"SalaryHigh":120000.0000,"SalaryLow":105000.0000,"PayRateOvertime":0,"PayRateStraight":0,"Filled":0,"RemainingOpenings":0,"TotalOpenings":0,"Visa":null,"ClearanceType":null,"IsClearanceRequired":false,"IsHealthcare":false,"IsRemote":false,"EndClient":null,"JobCreatedDate":"\/Date(-62135578800000)\/","JobModifiedDate":"\/Date(-62135578800000)\/"}

Insight Global is seeking a TS/SCI Cyber Defense Operator to support and defend a one of the largest DoD Networks. This is a 24/7/365 mission and will work on base and will sit within a Sensitive... Compartmented Information Facility (SCIF). Daily TS/SCI Cyber Defense Operator will:* Review all IDS/IPS alerts per DoD Customer Operating Instruction (OI) and checklists at the AOL, COOP, or Ops Floor. Conduct host security monitoring, alert review, and intrusion detection analysis for the DoD Network-SOC mission.* Comply with 3rd party MOU/MOA monitoring and reporting requirements. Analyze host DCO events to determine the necessity for higher level analysis and conduct an initial assessment of type and extent of intruder activities.* Monitor security sensors to analyze Intrusion Detection Systems (IDS) and Security Information and Event Management (SIEM) to identify and correlate security issues/events and review logs to identify intrusions for remediation. Correlate suspicious events with network events, if possible, and data stored within databases and other external DoD resources, including but not limited to Big Data Platform (BDP).* Record who, what, where, why and when for any identified suspicious activity in case management system (CMS) case to enable additional investigations* Conduct 24x7x365 near real-time network security monitoring and intrusion detection analysis for the networks, systems monitored using DoD CustomWe are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

1 - 6 of 6