1

Internship Microsoft Security Operations Analyst Jobs in Virginia

Overview The Enterprise Security Analyst II is a hands-on Security Operations Center (SOC) role ... Relevant certifications such as CompTIA Security+, GCIH, GCED, GCIA, GCFA, GCTI, CTIA, or Microsoft ...

New

The Enterprise Security Analyst II is a hands-on Security Operations Center (SOC) role responsible ... Relevant certifications such as CompTIA Security+, GCIH, GCED, GCIA, GCFA, GCTI, CTIA, or Microsoft ...

Posted today

Security Operations Analyst

Vienna, VA · On-site

$70K - $114K/yr

Overview The Enterprise Security Analyst II is a hands-on Security Operations Center (SOC) role ... Relevant certifications such as CompTIA Security+, GCIH, GCED, GCIA, GCFA, GCTI, CTIA, or Microsoft ...

New

... operational activities. • Mentor junior analysts and provide guidance during incident ... Security+, CySA+, CISSP, GIAC, Microsoft Security certifications, or equivalent. Company : Bowman ...

Microsoft security certifications such as: * SC-200 (Security Operations Analyst Associate) * AZ-500 (Azure Security Engineer Associate) * Experience supporting federal agencies The salary range for ...

next page

Showing results 1-20

Internship Microsoft Security Operations Analyst information

What is the difference between Internship Microsoft Security Operations Analyst vs Security Analyst?

AspectInternship Microsoft Security Operations AnalystSecurity Analyst
CredentialsBasic knowledge of cybersecurity, certifications like CompTIA Security+ beneficialMore advanced certifications often required, such as CISSP or GIAC
Work EnvironmentInternship setting, learning-focused, often in large tech companiesFull-time or part-time roles in various organizations, more responsibility
Employer & IndustryPrimarily in tech companies, especially Microsoft or similar firmsAcross industries including finance, healthcare, and tech

The Internship Microsoft Security Operations Analyst is an entry-level, learning-focused role designed for students or recent graduates. In contrast, a Security Analyst is a more experienced professional responsible for ongoing security monitoring and incident response. The internship provides foundational skills, while the Security Analyst role involves applying those skills in real-world scenarios.

What cities in Virginia are hiring for Internship Microsoft Security Operations Analyst jobs?

Cities in Virginia with the most Internship Microsoft Security Operations Analyst job openings:

Infographic showing various Internship Microsoft Security Operations Analyst job openings in Virginia as of August 2026, with employment types broken down into 86% Full Time, 11% Part Time, 1% Temporary, and 2% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution.

Security Operations Analyst

Esri

Vienna, VA • On-site

Full-time

Posted 2 days ago

New


Esri rating

9.6

Company rating: 9.6 out of 10

Based on 14 frontline employees who took The Breakroom Quiz

6th of 247 rated software companies


Job description

Overview

The Enterprise Security Analyst II is a hands-on Security Operations Center (SOC) role responsible for monitoring alerts, investigating security events, supporting incident response, and improving security operations. This role also applies cyber threat intelligence and threat hunting practices to add context to investigations, identify emerging threats, and strengthen detection and response capabilities. Primary schedule is business hours, Monday through Friday. Participation in an after-hours on-call rotation is expected after onboarding and demonstrated familiarity with systems, tools, and response procedures.

Responsibilities

Security Operations and Incident Response

  • Monitor and manage the SOC alert queue across endpoint, identity, network, email, cloud, and log monitoring platforms
  • Independently triage and investigate security alerts and events, distinguishing confirmed threats from benign activity using available evidence and telemetry
  • Support the full incident lifecycle, including investigation, escalation, containment support, remediation follow-up, documentation, and closure
  • Escalate incidents with clear evidence, impact assessment, and recommended next steps
  • Apply playbooks and runbooks while identifying opportunities to improve alert quality, response consistency, automation, and analyst enablement

Threat Intelligence and Threat Hunting

  • Analyze relevant threat intelligence to identify threats, campaigns, vulnerabilities, and adversary behaviors that may affect the organization
  • Enrich alerts and investigations with context about threat actors, malware, indicators, vulnerabilities, and attack techniques
  • Assist with threat hunts across endpoint, identity, network, cloud, and application telemetry
  • Use MITRE ATT&CK to support investigations, communicate adversary behavior, and identify detection gaps
  • Partner with security engineers and analysts to turn relevant intelligence into detections, hunts, watchlists, playbooks, blocking recommendations, or response improvements

Requirements

  • 2+ years of cybersecurity experience with hands-on involvement in security monitoring, alert triage, and incident investigation
  • Experience analyzing endpoint, identity, network, cloud, email, and log data to identify suspicious or malicious activity
  • Working knowledge of SIEM and EDR platforms, common triage workflows, and security telemetry analysis
  • Strong understanding of networking, operating systems, identity and access concepts, cloud security fundamentals, and core security protocols
  • Working knowledge of cyber threat intelligence concepts, including indicators, threat actors, campaigns, vulnerabilities, and adversary tactics, techniques, and procedures
  • Ability to write clear investigation notes, incident records, intelligence summaries, and recommendations for technical and non-technical audiences
  • U.S. citizenship is mandatory
  • Ability and willingness to obtain security clearance
  • Bachelors in Cybersecurity, Information Technology, Computer Science, or a related STEM degree

Recommended Qualifications

  • Experience performing threat intelligence analysis, threat hunting, incident response, or security engineering in an enterprise environment
  • Experience converting threat intelligence into detections, hunts, watchlists, playbooks, response actions, or mitigation recommendations
  • Experience researching threat actors, malware, ransomware activity, vulnerability exploitation, or emerging attack techniques
  • Familiarity with SOAR platforms, detection engineering practices, automation, scripting, or query languages such as PowerShell, Python, KQL, or SPL
  • Relevant certifications such as CompTIA Security+, GCIH, GCED, GCIA, GCFA, GCTI, CTIA, or Microsoft security certifications

#LI-TM1

#LI-onsite


What Esri employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


ESRI logo

About ESRI

Sourced by ZipRecruiter

Our passion for improving quality of life through geography is at the heart of everything we do. Esri's geographic information system (GIS) technology inspires and enables governments, universities, and businesses worldwide to save money, lives, and our environment through a deeper understanding of the changing world around them.

Industry

Scientific research and development services

Company size

1,001 - 5,000 Employees

Headquarters location

Redlands, CA, US

Year founded

1969