CybersecurityJobs.io
← Back to all jobs

Job Description

Make an impact on cyber defense by supporting day-to-day operations in a customer-focused CSOC environment. This on-site role in Chantilly, VA helps drive proactive detection and timely response across Microsoft Sentinel and Splunk Enterprise Security, with hands-on opportunities to refine hunts, validate detections, and improve visibility through telemetry pipeline analysis.

What you’ll do

The CSOC Hunt Analyst will monitor and triage security activity, perform initial investigations, and maintain situational awareness across the monitored enterprise. You’ll contribute to both day-to-day alert handling and ongoing detection improvement, including query development and validation of analytics.

  • Monitor, acknowledge, investigate, and triage incidents and alerts across Microsoft Sentinel and Splunk Enterprise Security.
  • Write and modify SPL and KQL queries to hunt for suspicious activity, support investigations, and analyze time-based security data.
  • Support legacy Splunk operations while assisting with migration efforts for use cases, detections, telemetry, dashboards, and workflows to Microsoft Sentinel.
  • Analyze telemetry flows through pipeline platforms such as Cribl Stream or Cribl Edge into SIEM systems, including identifying missing or malformed telemetry.
  • Support detection engineering by testing correlation searches and analytic rules, validating expected results, and documenting false positives and false negatives.
  • Participate in threat hunts, cyber exercises, tabletop events, and detection-validation activities, using approved AI-assisted tools to enhance research and workflows.
  • Maintain system baselines and configuration management items, including security event monitoring policies, standard operating procedures, and playbooks.

Required qualifications

  • Bachelor’s degree in Computer Science, Information Technology, or Cybersecurity, plus 5+ years of related technical experience. Alternatively, High School/GED with 7+ years of related technical experience.
  • Experience performing alert triage, initial incident investigation, and writing or troubleshooting basic-to-intermediate SPL and KQL queries.
  • Demonstrated ability to filter, summarize, correlate, and analyze time-based security data across endpoint, identity, network, and cloud audit logs.
  • Understanding of telemetry pipeline concepts including onboarding, normalization, parsing, routing, enrichment, and field mapping.
  • Experience creating, maintaining, and communicating complex technical documentation, including standard operating procedures, investigation notes, and playbooks.
  • Must meet applicable DoD 8140/8570 workforce requirements, including an active IAT Level II certification (examples: Security+ CE, CySA+, GSEC, CCNA Security, CASP+ CE).
  • Active TS/SCI with Polygraph is required.
  • Physical requirements: remain stationary 50% of the time, occasionally move about inside the office to access file cabinets and office machinery.
  • Frequent communication with coworkers, management, and customers, which may include delivering presentations, with the ability to exchange accurate information.

Preferred qualifications

  • Working knowledge of Microsoft Sentinel (incidents, analytics rules, workbooks, KQL) and Splunk Enterprise Security (notable events, SPL, dashboards).
  • Experience supporting an operational transition or migration from Splunk to Microsoft Sentinel, including work with Cribl Stream/Edge.
  • Relevant technical certifications such as Microsoft SC-200, Splunk Core/Enterprise Security, Cribl certification, or advanced cyber certifications.
  • Familiarity with MITRE ATT&CK, threat-informed defense, adversary emulation, automated workflows, and AI-enabled cybersecurity tooling.

Technologies you’ll work with

  • Microsoft Sentinel
  • Splunk Enterprise Security
  • Search Processing Language (SPL)
  • Kusto Query Language (KQL)
  • Cribl Stream
  • Cribl Edge
  • SIEM

Similar Jobs