Booz Allen Hamilton is an award-winning provider of strategic innovation, management consulting, technology, and engineering services. Founded in 1914, the comp
Security Operations Analyst
Location
Alabama
Posted
2 days ago
Salary
$61.9K - $141K / year
Seniority
Senior
Job Description
Security Operations Analyst
Booz Allen Hamilton
Security Operations Analyst Location: Huntsville United States Job Description: Security Operations Analyst, Mid The Opportunity: Respond to and resolve cybersecurity incidents, and proactively prevent the reoccurrence of these incidents. Apply leading-edge principles, theories, and concepts. Contribute to the development of new principles and concepts. Work on unusually complex problems and provide highly innovative solutions. Operate with substantial latitude for unreviewed action or decision. Mentor or supervise employees and technical competencies. You Have: - 5+ years of experience supporting Information Technology or Intelligence Operations - Experience supporting a Computer Incident Response Team, Cyber Network Operations, or Security Operations Center (SOC) operations for a large and complex enterprise - Experience with Intelligence Driven Defense, Cyber Kill Chain methodology, or MITRE ATT&CK framework - Knowledge of industry-accepted standards for incident response actions and best practices for SOC operations - Knowledge of security operation tools, including SIMs or DCAP analysis - Knowledge of intrusion set tactics, techniques, and procedures - Top Secret clearance - Bachelor's degree Nice If You Have: - Experience with Microsoft Sentinel - Experience with Splunk - TS/SCI clearance with a polygraph - GIAC Continuous Monitoring (GMON) Certification - GIAC Certified Incident Handler (GCIH) Certification - GIAC Certified Forensic Analyst (GCFA) Certification - GIAC Certified Intrusion Analyst (GCIA) Certification - GIAC Network Forensic Analyst (GNFA) Certification - GIAC Cloud Threat Detection (GCTD) Certification - GIAC Cloud Forensics Responder (GCFR) Certification Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Top Secret clearance is required. Compensation At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page. Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $61,900.00 to $141,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees. This posting will close within 90 days from the Posting Date. Identity Statement As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud. Candidate AI Usage Policy AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided. Work Model Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings. - Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility. - Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility. - Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role. Commitment to Non-Discrimination All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
Senior CSOC Engineer
FastlyFounded in 2001, Fastly is a privately-held internet company offering the Fastly Edge Cloud platform, a content delivery network that helps digital businesses s
• Design, develop, and refactor our custom internal security platform across both the backend (FastAPI) and frontend(React). • Partner with security analysts to turn manual workflows into automated, reliable processes. • Integrate and operationalise AI/ML utilities (such as LLMs) into our security platform to assist analysts with threat investigation and incident summarisation. • Work with our infrastructure in GCP, using Kubernetes for orchestration and Terraform for resource management. • Leverage our monitoring and alerting tools (Prometheus/Grafana) to detect failures early and maintain high availability across the internal security platform the team owns. • Build and maintain API integrations that connect our detection tools, ticketing systems, and customer environments. • Champion code quality through code reviews, testing practices and CI/CD pipelines.
Manager, Security Operations
FigmaFigma was founded in 2012 to build a collaborative, professional-grade interface design tool for the digital age. Created specifically for interface design and built entirely in th
Role Description Figma's Security team is growing, and we're looking for a Security Operations Manager to lead the strategy and execution of our security operations program. In this role, you'll build and scale the systems, processes, and tooling that help protect Figma and our community. You'll partner closely with Security Engineering, Platform Security, IT, GRC, and Legal to strengthen our detection and response capabilities, improve operational resilience, and help shape the future of our DART and SOC functions. This is a full-time role that can be held from one of our US hubs or remotely in the United States. What you'll do at Figma: - Own Figma's security monitoring and incident response program, from detection engineering through post-incident review and continuous improvement. - Build and automate security operations workflows, including alert triage, enrichment, investigation, and response actions using SOAR and custom tooling. - Develop and maintain incident response run books, escalation procedures, and communication plans for security events of varying severity. - Lead incident response preparedness initiatives, including tabletop exercises, red team engagements, and response capability assessments. - Improve the effectiveness of our SIEM and SOAR platforms by reducing noise, increasing signal fidelity, and closing detection coverage gaps. - Build and operationalize threat intelligence capabilities to identify adversary behaviors, prioritize investments, and strengthen detection and response programs. - Partner with Legal, Privacy, and Communications teams to support breach notification and regulatory response obligations during significant security incidents. - Drive security operations strategy through vendor management, operational metrics, and cross-functional initiatives spanning IAM, vulnerability management, DLP, and exposure reduction. Qualifications - 7+ years of experience in security operations, incident response, or a related security engineering function. - Hands-on experience building and automating detection and response workflows using scripting, APIs, or security automation platforms. - Deep expertise with SIEM and SOAR technologies in a cloud-native or SaaS environment. - Demonstrated success building, scaling, or significantly improving a detection and response program. - Experience leading complex security incidents and partnering with Legal, Privacy, and business stakeholders during high-impact events. Requirements - While it's not required, it's an added plus if you also have: - Operated in a public company environment with SOX, ISO 27001, SOC 2, or FedRAMP requirements. - Applied AI risk management frameworks such as NIST AI RMF, OECD AI Principles, or ISO 42001. - Utilized AI-powered tools to automate security operations workflows and improve team efficiency. Benefits - Figma offers equity to employees, as well as a competitive package of additional benefits, including: - Health, dental & vision. - Retirement with company contribution. - Parental leave & reproductive or family planning support. - Mental health & wellness benefits. - Generous PTO. - Company recharge days. - Learning & development stipend. - Work from home stipend. - Cell phone reimbursement. - Sales incentive pay for most sales roles. - Annual bonus plan for eligible non-sales roles.
Security Operations Analyst
HuntressManaged endpoint protection, detection and response for the 99% who need it most.
• Triage, investigate, and respond to alerts coming in from the Huntress platform. • Perform tactical review of EDR telemetry, log sources, and forensic artifacts to determine the root cause of attacks, where possible, and provide remediations needed to remove the threat. • Perform tactical malware analysis as part of investigating and triaging alerts. • Investigate suspicious Microsoft M365 activity and provide remediations. • Assist in escalations from the Product Support team for threat-related and SOC-relevant questions. • Contribute to detection engineering creation and tuning efforts. • Contribute to projects focused on driving better outcomes for our analysts and partners • Contribute to our collaboratively mentored team (we're all here to make each other better!).
Security Operations Lead
Digital ScienceAdvancing the research ecosystem. Together, we make open, collaborative and inclusive research possible.
• Work with various stakeholders from across the group, to ensure security operations practices, policies, and systems are robust, pragmatic and aligned with strategic objectives. • Define, build, and maintain a comprehensive security operations architecture that addresses current and emerging threats. • Manage delivery of cyber security projects and co-ordinate business security initiatives to support the organisation’s security posture and strategic goals. • Provide expert consultancy to technology teams on both reactive (day-to-day issues) and proactive (strategic) security matters. • Maintain Security Operations documentation, records and evidence to support security assessments, audits, and compliance with legal, regulatory and customer requirements. • Oversee and enforce adherence to technical security policies, standards, best practices, and customer requirements. • Lead the monitoring, detection, and investigation of security events & alerts; maintain and improve security control automation, logging, alerting, vulnerability scanning and threat detection capabilities. • Own incident response procedures; coordinate incident handling, ensure relevant stakeholders and third parties are engaged, lead follow-up actions until resolution. • Manage and oversee security testing: internal automated technical controls capture and scans, third-party assessments, penetration tests, ensuring findings are tracked and remediated. • Ensure security controls and processes are integrated across systems, applications, and cloud infrastructure. • Develop KPIs, SLAs, dashboards to measure and report performance, including response times, false positives, remediation progress etc. • Stay up-to-date with regulatory/compliance frameworks (e.g. EU Cyber Resilience Act, EU AI Act, ISO 27001, GDPR, PCI-DSS, NIST,NCSC), threat landscape changes and emerging technologies. • Work across the organisation and beyond to promote best practice across Digital Science, making recommendations for improvements to cyber security practices in line with industry standards and learnings from security incidents. • Prepare cyber security responses and evidence for internal and external parties. • Take an active role in information security forums, councils and communities within and outside of the organisation.




