2

Remote Cyber Defense Analyst Jobs (NOW HIRING)

Deloitte's Cyber Defense and Resilience offering is seeking a SIEM Engineer to support security ... This is a remote role with opportunities to work across distributed teams in a fast-paced ...

Deloitte's Cyber Defense and Resilience offering is seeking a SIEM Engineer to support security ... This is a remote role with opportunities to work across distributed teams in a fast-paced ...

Cyber Analyst

Reston, VA · Remote

$165K - $175K/yr

Senior Cyber Analyst Clearance: Active TS/SCI Clearance Required (CI Polygraph Eligible) Job Type ... Completion of Defense Cyber Investigations Training Academy (DCITA) courses * Advanced ...

Cyber Analyst

Quantico, VA · Remote

$105K - $155K/yr

Completion of Defense Cyber Investigations Training Academy (DCITA) courses * Advanced certifications in cyber security or cyber threat analysis * Current or former Federal Law enforcement of ...

Cyber Analyst

Reston, VA · Remote

$105K - $155K/yr

Completion of Defense Cyber Investigations Training Academy (DCITA) courses * Advanced certifications in cyber security or cyber threat analysis * Current or former Federal Law enforcement of ...

Cyber Threat Analyst

Springfield, VA · Remote

$115K - $135K/yr

Sphinx Counterintelligence Cyber Threat Analysts support sensitive national security investigations and computer network defense operations on behalf of our clients. Sphinx Cyber CI threat Analysts ...

Candidates who live near CB offices have the option of being fully remote or hybrid (Tuesday and ... Success in this role means fewer blind spots, higher fidelity alerts, and a cyber defense program ...

Collect and analyze intrusion artifacts (e.g., malware, source code, trojans) to support mitigation efforts * Coordinate and provide technical support to enterprise-wide cyber defense teams during ...

None Potential for Remote Work: ORA_ON_SITE Description SAIC is seeking qualified applicants to ... Perform Cybersecurity Defense Analysis. * Conduct Incident Response. * Conduct Threat Analysis and ...

Remote Employment Type: Full‑Time Salary Range: $100,000 - $116,000 Work Schedule: 12x5 coverage ... cyber requirements analysis and tracking activities Why Join Us * Work on advanced cyber defense ...

next page

Showing results 1-20

Remote Cyber Defense Analyst information

See salary details

$44.5K

$107.5K

$151K

How much do remote cyber defense analyst jobs pay per year?

As of Jun 15, 2026, the average yearly pay for remote cyber defense analyst in the United States is $107,522.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $126,500.00 per year, depending on experience, location, and employer.

What does a Remote Cyber Defense Analyst do?

A Remote Cyber Defense Analyst is responsible for monitoring, analyzing, and responding to cybersecurity threats and incidents from a remote location. They work with security tools to detect suspicious activities, investigate potential breaches, and implement protective measures to safeguard an organization’s digital assets. Their role often involves collaborating with other IT and security professionals, providing reports, and staying updated on the latest cyber threats and best practices. By working remotely, they utilize secure connections and specialized software to perform their duties without being physically present at the company's location.

What is the difference between Remote Cyber Defense Analyst vs Remote Security Operations Center (SOC) Analyst?

AspectRemote Cyber Defense AnalystRemote Security Operations Center (SOC) Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, CISSP, CEH
Work EnvironmentRemote, often part of cybersecurity teamsRemote, within SOC teams monitoring security alerts
Industry UsageVarious industries including finance, healthcare, techPrimarily in cybersecurity firms and large organizations
Job FocusAnalyzing threats, developing defense strategiesMonitoring security alerts, incident response

The Remote Cyber Defense Analyst and Remote SOC Analyst roles share similar certifications and work environments but differ in focus. The Cyber Defense Analyst emphasizes proactive threat analysis and defense strategy, while the SOC Analyst concentrates on real-time monitoring and incident response within security operations centers.

How do Remote Cyber Defense Analysts typically collaborate with on-site IT teams during a security incident?

Remote Cyber Defense Analysts often work closely with on-site IT teams through secure communication channels like video calls, instant messaging, and incident management platforms. During a security incident, they provide real-time analysis, guide the collection of forensic data, and help coordinate responses such as containment and remediation actions. Effective collaboration relies on clear protocols, regular updates, and thorough documentation to ensure rapid and unified responses. Building strong relationships and maintaining open lines of communication with on-site personnel are essential for seamless teamwork.

What are the key skills and qualifications needed to thrive as a Remote Cyber Defense Analyst, and why are they important?

To thrive as a Remote Cyber Defense Analyst, you need a strong understanding of network security, threat analysis, and incident response, often supported by a degree in cybersecurity or a related field. Familiarity with SIEM tools, intrusion detection systems, and certifications like CompTIA Security+, CEH, or CISSP are typically required. Analytical thinking, attention to detail, and effective communication are essential soft skills for excelling in this role. These skills and qualifications are crucial for proactively identifying and mitigating cyber threats, ensuring the security and resilience of an organization’s digital assets.
More about Remote Cyber Defense Analyst jobs
What cities are hiring for Remote Cyber Defense Analyst jobs? Cities with the most Remote Cyber Defense Analyst job openings:
What are the most commonly searched types of Cyber Defense Analyst jobs? The most popular types of Cyber Defense Analyst jobs are:
What states have the most Remote Cyber Defense Analyst jobs? States with the most job openings for Remote Cyber Defense Analyst jobs include:
What job categories do people searching Remote Cyber Defense Analyst jobs look for? The top searched job categories for Remote Cyber Defense Analyst jobs are:
Infographic showing various Remote Cyber Defense Analyst job openings in the United States as of June 2026, with employment types broken down into 1% Locum Tenens, 65% Full Time, 25% Part Time, and 9% Contract. Highlights an 81% Physical, 8% Hybrid, and 11% Remote job distribution, with an average salary of $107,522 per year, or $51.7 per hour.
Security Engineer III

Security Engineer III

Deloitte

Rosslyn, VA • Remote

Other

Posted 25 days ago


Deloitte rating

8.1

Company rating: 8.1 out of 10

Based on 86 frontline employees who took The Breakroom Quiz

58th of 138 rated financial services


Job description

Deloitte's Cyber Defense and Resilience offering is seeking a SIEM Engineer to support security monitoring, detection engineering, and incident analysis across complex enterprise environments. This role will focus on building and optimizing SIEM content, improving alert fidelity, and helping clients strengthen cyber defense capabilities. The ideal candidate will bring experience with at least one of the following technology areas: Splunk, Palo Alto Networks, or CrowdStrike. This is a remote role with opportunities to work across distributed teams in a fast-paced cybersecurity environment.

Work you'll do

As a SIEM Engineer on the Cyber Defense and Resilience team, you will be responsible for...

  • Configure, maintain, and optimize SIEM content including correlation rules, alerts, dashboards, and reports
  • Analyze security events and log data to identify suspicious activity, support investigations, and improve detection coverage
  • Integrate and normalize log sources from endpoint, network, cloud, identity, and security platforms
  • Partners with cybersecurity teams to support use case development, threat detection, incident triage, and response activities
  • Document detection logic, operational procedures, and monitoring requirements to support consistent service delivery

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to provide clear guidance to others

Qualifications

Required:

  • Bachelor's degree in computer science, Cybersecurity, Information Technology, Engineering, or a degree in related technical field
  • 3+ years of experience in cybersecurity, security operations, or SIEM engineering
  • 3+ years of experience with at least one of the following: Splunk, Palo Alto XSIAM, or Crowdstrike NG SIEM
  • Security certification such as Splunk certification, Palo Alto Networks certification, or CrowdStrike certification is required
  • 2+ years' experience in the following areas:
    •  creating, tuning, and maintaining correlation searches, alerts, dashboards, and reports in a Security Information and Event Management platform
    •  reviewing and analyzing logs from endpoint, network, cloud, identity, and application sources
  • Active Secret clearance or higher
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.

Preferred:

  • 2+ years' experience:
    • supporting enterprise monitoring in a Security Operations Center
    • Experience onboarding and normalizing log sources in a Security Information and Event Management platform
    • Experience mapping detections to MITRE ATT&CK techniques
    • Experience with cloud security monitoring in Amazon Web Services, Microsoft Azure, or Google Cloud Platform
    • Hands-on experience with scripting or query languages used for detection and log analysis
  • Security certification such as CompTIA Security+, or GIAC certification

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $107,925 to $188,900.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Qualifications:

Deloitte's Cyber Defense and Resilience offering is seeking a SIEM Engineer to support security monitoring, detection engineering, and incident analysis across complex enterprise environments. This role will focus on building and optimizing SIEM content, improving alert fidelity, and helping clients strengthen cyber defense capabilities. The ideal candidate will bring experience with at least one of the following technology areas: Splunk, Palo Alto Networks, or CrowdStrike. This is a remote role with opportunities to work across distributed teams in a fast-paced cybersecurity environment.

Work you'll do

As a SIEM Engineer on the Cyber Defense and Resilience team, you will be responsible for...

  • Configure, maintain, and optimize SIEM content including correlation rules, alerts, dashboards, and reports
  • Analyze security events and log data to identify suspicious activity, support investigations, and improve detection coverage
  • Integrate and normalize log sources from endpoint, network, cloud, identity, and security platforms
  • Partners with cybersecurity teams to support use case development, threat detection, incident triage, and response activities
  • Document detection logic, operational procedures, and monitoring requirements to support consistent service delivery

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to provide clear guidance to others

Qualifications

Required:

  • Bachelor's degree in computer science, Cybersecurity, Information Technology, Engineering, or a degree in related technical field
  • 3+ years of experience in cybersecurity, security operations, or SIEM engineering
  • 3+ years of experience with at least one of the following: Splunk, Palo Alto XSIAM, or Crowdstrike NG SIEM
  • Security certification such as Splunk certification, Palo Alto Networks certification, or CrowdStrike certification is required
  • 2+ years' experience in the following areas:
    •  creating, tuning, and maintaining correlation searches, alerts, dashboards, and reports in a Security Information and Event Management platform
    •  reviewing and analyzing logs from endpoint, network, cloud, identity, and application sources
  • Active Secret clearance or higher
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.

Preferred:

  • 2+ years' experience:
    • supporting enterprise monitoring in a Security Operations Center
    • Experience onboarding and normalizing log sources in a Security Information and Event Management platform
    • Experience mapping detections to MITRE ATT&CK techniques
    • Experience with cloud security monitoring in Amazon Web Services, Microsoft Azure, or Google Cloud Platform
    • Hands-on experience with scripting or query languages used for detection and log analysis
  • Security certification such as CompTIA Security+, or GIAC certification

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $107,925 to $188,900.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Education:Bachelor's DegreeEmployment Type:

What Deloitte employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom