Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
E
Esri
Security Operations Analyst
Career Insights for Cyber Security Analyst
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on California data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Cyber Security Analyst works on monitoring, controlling, and maintaining systems that protect the security of large databases, including databases with customer information and patient files. Analyzes the examination of client computer systems, identification of weak points in security, development and implementation of new systems, and monitoring and response to security issues.
$130,852 / year median in California
+5% projected growth
Job Description
Security Operations Analyst Esri - 3.8 Highland, CA Job Details $70,304 - $114,400 a year 2 hours ago Qualifications Endpoint Security Solutions Operating systems Triage Research Endpoint Detection and Response (EDR) IT monitoring tools Cloud security Bachelor's degree Threat intelligence reports Log analysis tools Investigative reports SIEM Cybersecurity investigations Incident report writing Threat intelligence Cloud monitoring Network event correlation IT security monitoring Full Job Description Overview The Enterprise Security Analyst II is a hands-on Security Operations Center (SOC) role responsible for monitoring alerts, investigating security events, supporting incident response, and improving security operations. This role also applies cyber threat intelligence and threat hunting practices to add context to investigations, identify emerging threats, and strengthen detection and response capabilities. Primary schedule is business hours, Monday through Friday. Participation in an after-hours on-call rotation is expected after onboarding and demonstrated familiarity with systems, tools, and response procedures. Responsibilities Security Operations and Incident Response Monitor and manage the SOC alert queue across endpoint, identity, network, email, cloud, and log monitoring platforms Independently triage and investigate security alerts and events, distinguishing confirmed threats from benign activity using available evidence and telemetry Support the full incident lifecycle, including investigation, escalation, containment support, remediation follow-up, documentation, and closure Escalate incidents with clear evidence, impact assessment, and recommended next steps Apply playbooks and runbooks while identifying opportunities to improve alert quality, response consistency, automation, and analyst enablement Threat Intelligence and Threat Hunting Analyze relevant threat intelligence to identify threats, campaigns, vulnerabilities, and adversary behaviors that may affect the organization Enrich alerts and investigations with context about threat actors, malware, indicators, vulnerabilities, and attack techniques Assist with threat hunts across endpoint, identity, network, cloud, and application telemetry Use