1

Microsoft Security Operations Analyst Jobs in Virginia

Overview The Enterprise Security Analyst II is a hands-on Security Operations Center (SOC) role ... Relevant certifications such as CompTIA Security+, GCIH, GCED, GCIA, GCFA, GCTI, CTIA, or Microsoft ...

Security Operations Analyst

Vienna, VA · On-site

$100 - $125/hr

The Enterprise Security Analyst II is a hands-on Security Operations Center (SOC) role responsible ... Relevant certifications such as CompTIA Security+, GCIH, GCED, GCIA, GCFA, GCTI, CTIA, or Microsoft ...

New

Security Operations Analyst

Vienna, VA · On-site

$70K - $114K/yr

Overview The Enterprise Security Analyst II is a hands-on Security Operations Center (SOC) role ... Relevant certifications such as CompTIA Security+, GCIH, GCED, GCIA, GCFA, GCTI, CTIA, or Microsoft ...

... operational activities. • Mentor junior analysts and provide guidance during incident ... Security+, CySA+, CISSP, GIAC, Microsoft Security certifications, or equivalent. Company : Bowman ...

Microsoft security certifications such as: * SC-200 (Security Operations Analyst Associate) * AZ-500 (Azure Security Engineer Associate) * Experience supporting federal agencies The salary range for ...

next page

Showing results 1-20

Microsoft Security Operations Analyst information

See Virginia salary details

$17

$43

$60

How much do microsoft security operations analyst jobs pay per hour?

As of Sep 8, 2026, the average hourly pay for microsoft security operations analyst in Virginia is $43.77, according to ZipRecruiter salary data. Most workers in this role earn between $34.33 and $54.09 per hour, depending on experience, location, and employer.

What are the typical responsibilities of a Microsoft Security Operations Analyst?

A typical day for a Microsoft Security Operations Analyst involves monitoring security alerts from Microsoft Sentinel and other security platforms, investigating suspicious activities, and responding to potential threats or incidents. Analysts may also conduct vulnerability assessments, review logs, create incident reports, and recommend improvements to security posture. Collaboration is central to the role, as you will often work with IT teams, threat intelligence analysts, and management to coordinate responses and refine security processes. Over time, this position offers opportunities to specialize in advanced threat hunting, security architecture, or leadership within the cybersecurity field.

What are the key skills and qualifications needed to thrive in the Microsoft Security Operations Analyst position, and why are they important?

A Microsoft Security Operations Analyst is responsible for monitoring, detecting, investigating, and responding to security threats within an organization's IT environment. They use Microsoft security solutions, such as Microsoft Defender and Sentinel, to analyze security incidents and mitigate risks. Their role involves threat management, vulnerability assessment, and implementing security best practices to protect organizational assets. Analysts work closely with IT teams to improve security posture and ensure compliance with industry regulations.

Is a Microsoft Security Operations Analyst in high demand?

Microsoft Security Operations Analysts are in high demand due to the increasing frequency and sophistication of cyber threats. Organizations seek professionals skilled in security monitoring, incident response, and tools like Microsoft Defender and Azure Sentinel, often requiring relevant certifications and experience in cybersecurity environments.

What are the most commonly searched types of Microsoft Security Operations Analyst jobs in Virginia?

The most popular types of Microsoft Security Operations Analyst jobs in Virginia are:

What are popular job titles related to Microsoft Security Operations Analyst jobs in Virginia?

For Microsoft Security Operations Analyst jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Microsoft Security Operations Analyst jobs in Virginia look for?

The top searched job categories for Microsoft Security Operations Analyst jobs in Virginia are:

Infographic showing various Microsoft Security Operations Analyst job openings in Virginia as of August 2026, with employment types broken down into 86% Full Time, 12% Part Time, and 2% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $91,034 per year, or $43.8 per hour.

Security Operations Analyst

Esri

Vienna, VA

Full-time

Posted 4 days ago


Esri rating

9.6

Company rating: 9.6 out of 10

Based on 14 frontline employees who took The Breakroom Quiz

6th of 247 rated software companies


Job description

Overview

The Enterprise Security Analyst II is a hands-on Security Operations Center (SOC) role responsible for monitoring alerts, investigating security events, supporting incident response, and improving security operations. This role also applies cyber threat intelligence and threat hunting practices to add context to investigations, identify emerging threats, and strengthen detection and response capabilities. Primary schedule is business hours, Monday through Friday. Participation in an after-hours on-call rotation is expected after onboarding and demonstrated familiarity with systems, tools, and response procedures.

Responsibilities

Security Operations and Incident Response

  • Monitor and manage the SOC alert queue across endpoint, identity, network, email, cloud, and log monitoring platforms
  • Independently triage and investigate security alerts and events, distinguishing confirmed threats from benign activity using available evidence and telemetry
  • Support the full incident lifecycle, including investigation, escalation, containment support, remediation follow-up, documentation, and closure
  • Escalate incidents with clear evidence, impact assessment, and recommended next steps
  • Apply playbooks and runbooks while identifying opportunities to improve alert quality, response consistency, automation, and analyst enablement

Threat Intelligence and Threat Hunting

  • Analyze relevant threat intelligence to identify threats, campaigns, vulnerabilities, and adversary behaviors that may affect the organization
  • Enrich alerts and investigations with context about threat actors, malware, indicators, vulnerabilities, and attack techniques
  • Assist with threat hunts across endpoint, identity, network, cloud, and application telemetry
  • Use MITRE ATT&CK to support investigations, communicate adversary behavior, and identify detection gaps
  • Partner with security engineers and analysts to turn relevant intelligence into detections, hunts, watchlists, playbooks, blocking recommendations, or response improvements

Requirements

  • 2+ years of cybersecurity experience with hands-on involvement in security monitoring, alert triage, and incident investigation
  • Experience analyzing endpoint, identity, network, cloud, email, and log data to identify suspicious or malicious activity
  • Working knowledge of SIEM and EDR platforms, common triage workflows, and security telemetry analysis
  • Strong understanding of networking, operating systems, identity and access concepts, cloud security fundamentals, and core security protocols
  • Working knowledge of cyber threat intelligence concepts, including indicators, threat actors, campaigns, vulnerabilities, and adversary tactics, techniques, and procedures
  • Ability to write clear investigation notes, incident records, intelligence summaries, and recommendations for technical and non-technical audiences
  • U.S. citizenship is mandatory
  • Ability and willingness to obtain security clearance
  • Bachelors in Cybersecurity, Information Technology, Computer Science, or a related STEM degree

Recommended Qualifications

  • Experience performing threat intelligence analysis, threat hunting, incident response, or security engineering in an enterprise environment
  • Experience converting threat intelligence into detections, hunts, watchlists, playbooks, response actions, or mitigation recommendations
  • Experience researching threat actors, malware, ransomware activity, vulnerability exploitation, or emerging attack techniques
  • Familiarity with SOAR platforms, detection engineering practices, automation, scripting, or query languages such as PowerShell, Python, KQL, or SPL
  • Relevant certifications such as CompTIA Security+, GCIH, GCED, GCIA, GCFA, GCTI, CTIA, or Microsoft security certifications

#LI-TM1

#LI-onsite


What Esri employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


ESRI logo

About ESRI

Sourced by ZipRecruiter

Our passion for improving quality of life through geography is at the heart of everything we do. Esri's geographic information system (GIS) technology inspires and enables governments, universities, and businesses worldwide to save money, lives, and our environment through a deeper understanding of the changing world around them.

Industry

Scientific research and development services

Company size

1,001 - 5,000 Employees

Headquarters location

Redlands, CA, US

Year founded

1969