1

Security Operations Analyst Jobs in Virginia (NOW HIRING)

Overview The Enterprise Security Analyst II is a hands-on Security Operations Center (SOC) role responsible for monitoring alerts, investigating security events, supporting incident response, and ...

New

The Enterprise Security Analyst II is a hands-on Security Operations Center (SOC) role responsible for monitoring alerts, investigating security events, supporting incident response, and improving ...

Posted today

Security Operations Analyst

Vienna, VA · On-site

$70K - $114K/yr

Overview The Enterprise Security Analyst II is a hands-on Security Operations Center (SOC) role responsible for monitoring alerts, investigating security events, supporting incident response, and ...

New

next page

Showing results 1-20

Security Operations Analyst information

See Virginia salary details

$17

$43

$60

How much do security operations analyst jobs pay per hour?

As of Sep 6, 2026, the average hourly pay for security operations analyst in Virginia is $43.77, according to ZipRecruiter salary data. Most workers in this role earn between $34.33 and $54.09 per hour, depending on experience, location, and employer.

What is a security operations analyst?

Security Operations Analysts are IT professionals responsible for monitoring, detecting, and responding to cybersecurity threats within an organization. They work in security operations centers (SOCs) to analyze security incidents, investigate suspicious activities, and help implement measures to protect digital assets. Their role often involves using security tools and technologies, collaborating with other IT teams, and ensuring compliance with security policies. By proactively identifying vulnerabilities and responding to incidents, Security Operations Analysts play a critical role in safeguarding an organization's information systems.

What does a security operations analyst do?

A security operations analyst works with a company, organization, or government office to identify and reduce security risks to their computer network. Your duties are to keep records of any suspicious activity, install security measures to prevent breaches, and give the organization suggestions about how to avoid future incidents. As a security operations analyst, your responsibilities also include conducting research on new threats and upgrading software as necessary. You often collaborate with other employees to resolve incidents as quickly as possible.

What are the key skills and qualifications needed to thrive as a security operations analyst, and why are they important?

To thrive as a Security Operations Analyst, you need a strong understanding of cybersecurity principles, incident response, and risk assessment, typically supported by a degree in computer science or related fields. Familiarity with security information and event management (SIEM) tools, intrusion detection systems, and certifications like CompTIA Security+ or CISSP is highly valuable. Analytical thinking, attention to detail, and effective communication are key soft skills that set top analysts apart. These skills and qualifications are essential for quickly identifying, investigating, and mitigating security threats to protect organizational assets.

How does a security operations analyst typically collaborate with other IT and security teams?

Security Operations Analysts work closely with various IT and cybersecurity teams to monitor, detect, and respond to security threats. They regularly interact with network engineers, incident response teams, and system administrators to escalate and resolve security incidents. Effective communication and coordination are crucial, as analysts may need to provide detailed incident reports, share threat intelligence, and participate in post-incident reviews to improve security protocols. This collaborative environment helps ensure a swift response to threats and fosters ongoing professional development through cross-team knowledge sharing.

What is the difference between Security Operations Analyst vs Security Engineer?

AspectSecurity Operations AnalystSecurity Engineer
Primary FocusMonitoring, detecting, and responding to security incidentsDesigning, implementing, and maintaining security systems
CertificationsCompTIA Security+, CISSP, CEHCISSP, GIAC Security Certifications, CISSP
Work EnvironmentSecurity operations centers, incident response teamsSecurity architecture teams, development environments
ResponsibilitiesAnalyzing security alerts, incident response, threat huntingDeveloping security tools, deploying security solutions, system hardening

While both roles focus on cybersecurity, Security Operations Analysts primarily monitor and respond to threats in real-time, whereas Security Engineers design and build security infrastructure to prevent attacks. Both roles often collaborate but serve different functions within an organization's security strategy.

What job categories do people searching Security Operations Analyst jobs in Virginia look for?

The top searched job categories for Security Operations Analyst jobs in Virginia are:

What cities in Virginia are hiring for Security Operations Analyst jobs?

Cities in Virginia with the most Security Operations Analyst job openings:

Infographic showing various Security Operations Analyst job openings in Virginia as of August 2026, with employment types broken down into 86% Full Time, 12% Part Time, and 2% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $91,034 per year, or $43.8 per hour.

Security Operations Analyst

Esri

Vienna, VA • On-site

Full-time

Posted 2 days ago

New


Esri rating

9.6

Company rating: 9.6 out of 10

Based on 14 frontline employees who took The Breakroom Quiz

6th of 247 rated software companies


Job description

Overview

The Enterprise Security Analyst II is a hands-on Security Operations Center (SOC) role responsible for monitoring alerts, investigating security events, supporting incident response, and improving security operations. This role also applies cyber threat intelligence and threat hunting practices to add context to investigations, identify emerging threats, and strengthen detection and response capabilities. Primary schedule is business hours, Monday through Friday. Participation in an after-hours on-call rotation is expected after onboarding and demonstrated familiarity with systems, tools, and response procedures.

Responsibilities

Security Operations and Incident Response

  • Monitor and manage the SOC alert queue across endpoint, identity, network, email, cloud, and log monitoring platforms
  • Independently triage and investigate security alerts and events, distinguishing confirmed threats from benign activity using available evidence and telemetry
  • Support the full incident lifecycle, including investigation, escalation, containment support, remediation follow-up, documentation, and closure
  • Escalate incidents with clear evidence, impact assessment, and recommended next steps
  • Apply playbooks and runbooks while identifying opportunities to improve alert quality, response consistency, automation, and analyst enablement

Threat Intelligence and Threat Hunting

  • Analyze relevant threat intelligence to identify threats, campaigns, vulnerabilities, and adversary behaviors that may affect the organization
  • Enrich alerts and investigations with context about threat actors, malware, indicators, vulnerabilities, and attack techniques
  • Assist with threat hunts across endpoint, identity, network, cloud, and application telemetry
  • Use MITRE ATT&CK to support investigations, communicate adversary behavior, and identify detection gaps
  • Partner with security engineers and analysts to turn relevant intelligence into detections, hunts, watchlists, playbooks, blocking recommendations, or response improvements

Requirements

  • 2+ years of cybersecurity experience with hands-on involvement in security monitoring, alert triage, and incident investigation
  • Experience analyzing endpoint, identity, network, cloud, email, and log data to identify suspicious or malicious activity
  • Working knowledge of SIEM and EDR platforms, common triage workflows, and security telemetry analysis
  • Strong understanding of networking, operating systems, identity and access concepts, cloud security fundamentals, and core security protocols
  • Working knowledge of cyber threat intelligence concepts, including indicators, threat actors, campaigns, vulnerabilities, and adversary tactics, techniques, and procedures
  • Ability to write clear investigation notes, incident records, intelligence summaries, and recommendations for technical and non-technical audiences
  • U.S. citizenship is mandatory
  • Ability and willingness to obtain security clearance
  • Bachelors in Cybersecurity, Information Technology, Computer Science, or a related STEM degree

Recommended Qualifications

  • Experience performing threat intelligence analysis, threat hunting, incident response, or security engineering in an enterprise environment
  • Experience converting threat intelligence into detections, hunts, watchlists, playbooks, response actions, or mitigation recommendations
  • Experience researching threat actors, malware, ransomware activity, vulnerability exploitation, or emerging attack techniques
  • Familiarity with SOAR platforms, detection engineering practices, automation, scripting, or query languages such as PowerShell, Python, KQL, or SPL
  • Relevant certifications such as CompTIA Security+, GCIH, GCED, GCIA, GCFA, GCTI, CTIA, or Microsoft security certifications

#LI-TM1

#LI-onsite


What Esri employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


ESRI logo

About ESRI

Sourced by ZipRecruiter

Our passion for improving quality of life through geography is at the heart of everything we do. Esri's geographic information system (GIS) technology inspires and enables governments, universities, and businesses worldwide to save money, lives, and our environment through a deeper understanding of the changing world around them.

Industry

Scientific research and development services

Company size

1,001 - 5,000 Employees

Headquarters location

Redlands, CA, US

Year founded

1969