1

Intrusion Detection Analyst Jobs (NOW HIRING)

Senior Security Analyst

Troy, AL · On-site

$90K - $117K/yr

... intrusion detection and prevention, threat hunting, security operations, security policy, and ... analysis, management reporting, malware prevention and remediation, encryption, network ...

New

... Intrusion Detection and Prevention Systems (IDS/IPS), proxy security appliances, forensics tools ... Proactively analyze AFCENT network IDS and IPS for evidence of malicious cyber activity and conduct ...

next page

Showing results 1-20

Intrusion Detection Analyst information

See salary details

$31K

$73.3K

$130K

How much do intrusion detection analyst jobs pay per year?

As of Jun 12, 2026, the average yearly pay for intrusion detection analyst in the United States is $73,261.00, according to ZipRecruiter salary data. Most workers in this role earn between $52,500.00 and $87,000.00 per year, depending on experience, location, and employer.

What is an Intrusion Detection Analyst?

An Intrusion Detection Analyst is a cybersecurity professional responsible for monitoring networks and systems to detect suspicious activities and potential security breaches. They analyze security alerts generated by intrusion detection systems (IDS), investigate incidents, and respond to security threats. Their role often involves identifying vulnerabilities, recommending security improvements, and helping organizations protect their data and IT infrastructure from cyberattacks.

What are the typical challenges faced by an Intrusion Detection Analyst during incident response?

Intrusion Detection Analysts often encounter challenges such as rapidly analyzing large volumes of security alerts to distinguish genuine threats from false positives. Coordinating with other IT and security teams under time pressure is also common, especially during active incidents. Additionally, staying updated with evolving attack techniques and ensuring that detection tools are properly tuned can be demanding. These challenges require strong analytical skills, effective communication, and the ability to remain calm and focused under pressure.

What is the difference between Intrusion Detection Analyst vs Network Security Analyst?

AspectIntrusion Detection AnalystNetwork Security Analyst
CertificationsCompTIA Security+, CEH, CISSP (optional)CompTIA Security+, CISSP, Cisco CCNA Security
Work EnvironmentMonitoring security alerts, analyzing intrusion attempts, using IDS/IPS toolsDesigning, implementing, and managing network security measures
Employer & Industry UsageCybersecurity firms, government agencies, large corporationsIT departments across various industries, including finance, healthcare, and tech

While both roles focus on protecting networks, the Intrusion Detection Analyst primarily monitors and analyzes security alerts related to intrusions, whereas the Network Security Analyst develops and manages overall network security strategies. The roles often overlap, but the Intrusion Detection Analyst specializes in identifying and responding to active threats using IDS/IPS tools.

What are the key skills and qualifications needed to thrive as an Intrusion Detection Analyst, and why are they important?

To thrive as an Intrusion Detection Analyst, you need a solid understanding of network security, threat analysis, and incident response, often supported by a degree in cybersecurity or computer science. Familiarity with intrusion detection/prevention systems (IDS/IPS), SIEM tools like Splunk or QRadar, and certifications such as CompTIA Security+ or CISSP are typically required. Analytical thinking, attention to detail, and strong communication skills help you quickly identify, assess, and report threats. These skills are crucial to minimizing security risks, ensuring rapid response to potential breaches, and maintaining organizational resilience against cyberattacks.
More about Intrusion Detection Analyst jobs
What states have the most Intrusion Detection Analyst jobs? States with the most job openings for Intrusion Detection Analyst jobs include:
Infographic showing various Intrusion Detection Analyst job openings in the United States as of June 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $73,261 per year, or $35.2 per hour.
Cybersecurity Analyst - Operations Watch Analyst (Tier 1-3) with Security Clearance

Cybersecurity Analyst - Operations Watch Analyst (Tier 1-3) with Security Clearance

Sentar

Camp H M Smith, HI

Other

Medical, Dental, Vision, Retirement, PTO

Posted 4 days ago


Job description

Sentar is proud to be an employee-owned company, fostering a culture of empowerment, collaboration, and innovation. Sentar is dedicated to developing the critical talent that the connected world demands to create solutions to address the convergence of cybersecurity, intelligence, analytics, and systems engineering. We invite you to join the team where you can build, innovate, and secure your career.

Sentar is seeking a Cybersecurity Analyst - Operations Watch Analyst (Tier 1-3) in Hawaii! Role Description: The Operations Watch Analyst serves as a critical member of the Cybersecurity Operations team, responsible for identifying, investigating, reporting, and mitigating cyber incidents across diverse network environments. This role ensures timely detection, analysis, and response to security events in accordance with Chairman of the Joint Chiefs of Staff Manual (CJCSM) 6510.01B and other applicable Department of Defense (DoD) directives.

The analyst will assess the severity of incidents, document findings, and coordinate appropriate response actions with stakeholders across the DoD Information Network (DoDIN). * Maintain a thorough working knowledge of CJCSM 6510.01B and ensure compliance with related policies and procedures. * Develop, maintain, and continuously improve Standard Operating Procedures (SOPs) for operational watch functions.

* Conduct proactive network intrusion detection, monitoring, correlation, and analysis to identify potential threats. * Validate and assess suspicious events to determine if they meet incident criteria, ensuring accurate and timely entry into designated reporting systems. * Coordinate with Joint Force Headquarters-DoDIN (JFHQ-DoDIN) and supported organizations to ensure appropriate analysis, reporting, and escalation of significant incidents.

* Provide 24/7 incident response coverage, including after-hours and surge support as mission needs dictate. * Perform network and host-based digital forensics across Microsoft Windows and other operating systems to support incident analysis and remediation. * Analyze full packet captures (PCAP) using tools such as Wireshark and other network forensic utilities.

* Correlate system and network activity using Splunk and other log aggregation tools to detect anomalies and potential intrusions. * Develop, tune, and implement Intrusion Detection/Prevention System (IDS/IPS) signatures to enhance detection accuracy and minimize false positives. * Participate in program reviews, product assessments, and on-site certification evaluations to strengthen cyber defense posture.

* Support a rotating shift schedule (4x10-hour workdays), including at least one weekend day. * Work collaboratively in a high-tempo, mission-focused environment requiring flexibility and occasional overtime for surge operations. Key Responsibilities (By Tier) Tier 1 * Monitor network and host-based systems for suspicious activity using approved tools and SOPs.

* Validate security events and escalate potential incidents to Tier 2 analysts per CJCSM 6510.01B. * Enter and maintain accurate incident data in designated reporting systems. * Assist with incident documentation and tracking under supervision.

* Perform basic log correlation using tools such as Splunk, Elastic, or Sentinel. * Support 24/7 watch operations and shift turnovers across multiple ROCs. Tier 2 * Analyze and respond to validated security incidents, determining severity and operational impact.

* Coordinate incident response activities with internal teams, reporting agencies, and subscriber sites. * Perform network and host-based digital forensics on Windows, Linux, and other operating systems. * Conduct log correlation and deeper analysis to identify trends and patterns.

* Update and maintain SOPs to ensure compliance with CJCSM 6510.01B. * Support IDS/IPS tuning and signature implementation. Tier 3 * Lead complex incident response efforts, including analysis, mitigation, and reporting.

* Manage and oversee incident response campaigns and multi-team coordination. * Conduct proactive threat hunting and advanced investigations. * Lead purple team exercises to improve detection and response capabilities.

* Evaluate and refine IDS/IPS signatures, detection logic, and correlation rules. * Perform advanced digital forensics and mentor junior analysts. * Support program reviews, product evaluations, and certification assessments.

Clearance Level: * Secret with upgrade to TS required Education/ Experience: * Bachelor's degree in Cybersecurity, Information Technology, or a related field; or a minimum of three years of directly relevant experience, preferably within a DoD or federal cybersecurity environment. * Willingness to travel up to 15% globally, including short-notice (72-hour) deployments in support of incident response operations. Certifications: * Must hold an IAT Level II (Tier 1 and 2) or IAT Level III (Tier 3) certification (per DoD 8570.01-M) and PWS certification requirements in accordance with DoD cybersecurity workforce requirements.

* CND certification Preferred: * Five or more years of cybersecurity incident response experience. * Strong knowledge of incident response procedures, packet analysis, IDS/IPS technologies, and host-based security tools. * Proficiency in log correlation and analysis using tools such as Splunk, Elastic, or equivalent platforms.

* Familiarity with digital forensics tools and methodologies. * Demonstrated ability to analyze complex issues, think critically, and operate independently under pressure. * Excellent written and verbal communication skills to support operational reporting and coordination.

* In-depth understanding of CJCSM 6510.01B reporting requirements. * Prior experience in DoD environments. * Experience conducting digital forensics and malware analysis.

Benefits at Sentar: Our unique ownership model attracts top talent, giving employees the freedom to take initiative and drive meaningful improvements. In addition to cultivating a thriving and inclusive work environment, Sentar offers an extensive benefits package designed to support the well-being of employees and their families. Employee ownership is the foundation of our culture, promoting participation, teamwork, and accountability while ensuring long-term financial security and a commitment to excellence.

* Voluntary Medical, Dental, Vision, with Health Savings or Flexible Spending Plan options * Voluntary Life, Critical Illness, Accident, and Long Term Care insurance options * Group Term Life, Short-Term and Long-Term Disability is provided by Sentar to all qualifying employees * Generous 401(k) match * Competitive PTO plan that graduates quickly with years of service * Other leave programs; holiday schedule along with bereavement, maternity, jury and military duty * Mental health awareness programs * Tuition reimbursement * Professional development reimbursement * Recognition and Awards programs If you are not ready to apply for this position, submit your resume here to join our talent community We'll keep you updated occasionally on new job opportunities. Sentar is an Affirmative Action and Equal Opportunity Employer M/F/Vets/Persons with Disabilities Our culture is one of inclusivity and support. Sentar is proudly an Equal Opportunity and VEVRAA Federal Contractor Employer M/F/Vets/Persons with Disabilities.

Follow these links to learn more about your rights: EEO Is the Law Poster ; EEO Is Law Supplement ; and Pay Transparency . We want you to build your career at Sentar, so if you are an individual with a disability and require a reasonable workplace accommodation applying for a job or at any point in the employment process, contact the Recruiting Manager at . Please indicate the specifics of the assistance needed.

Thank you for considering Sentar in your employment search. Build, Innovate, Secure Your Career at Sentar.