About The Position

Join Via Logic supporting U.S. Customs and Border Protection cybersecurity operations. As an Operations Enhancement Analyst, you'll help strengthen and mature Security Operations Center capabilities by identifying opportunities to improve processes, automation, security tooling, detection, and operational visibility. You'll work alongside cybersecurity and government teams to improve how security operations are performed—from automating workflows and refining playbooks to tuning security tools, developing security content, and measuring whether operational improvements are delivering results. This posting covers both Junior and Mid-Level Operations Enhancement Analyst openings. Both levels have a 3+ year hiring threshold for these openings. We'll consider the depth and relevance of your experience against the available positions to determine the appropriate level.

Requirements

  • 3+ years of relevant professional experience supporting cybersecurity, security operations, security engineering, automation, or a related technical area.
  • Experience analyzing operational or technical processes and identifying opportunities to improve effectiveness, efficiency, or visibility.
  • Familiarity with Security Operations Center processes and technologies used for monitoring, detection, and response.
  • Experience developing or maintaining technical documentation such as playbooks, workflows, work instructions, or Standard Operating Procedures.
  • Ability to analyze technical information, troubleshoot issues, and translate findings into practical recommendations.
  • Ability to communicate technical findings clearly and collaborate with security analysts, engineers, government partners, and other technical teams.
  • Be a U.S. citizen.
  • Be able to obtain and maintain the required CBP High Trust background investigation and suitability determination for access to government facilities and systems.

Nice To Haves

  • A bachelor's degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related field.
  • Hands-on experience with SOAR platforms, automation workflows, or scripting.
  • Experience with SIEM, EDR, IDS, DLP, firewall, cloud-security, or related security technologies.
  • Experience creating, modifying, testing, or tuning security alerts, signatures, detection content, or monitoring policies.
  • Experience defining, tracking, and reporting operational metrics and KPIs.
  • Experience researching, testing, or evaluating cybersecurity tools and technologies.

Responsibilities

  • Support the continuous improvement and maturation of Security Operations Center processes, capabilities, and visibility.
  • Help develop, improve, and maintain security operations processes, playbooks, work instructions, and operational workflows.
  • Author and maintain automation scripts and workflows within Security Orchestration, Automation, and Response (SOAR) platforms.
  • Troubleshoot and resolve issues involving SOAR code, integrations, workflows, and supporting infrastructure.
  • Help define and track operational metrics, statistics, and key performance indicators (KPIs) to measure the effectiveness of automation and security-tool tuning.
  • Identify gaps in detection capabilities and contribute strategies and recommendations for improving detection of attacker tactics, techniques, and behaviors.
  • Support baselining of enterprise activity to help distinguish normal from abnormal behavior.
  • Recommend improvements to event-monitoring policies, indicators, and alerts across technologies such as SIEM, firewalls, IDS, cloud services, email, DLP, and EDR.
  • Draft, test, modify, and maintain security content, including signatures and alerts used by security monitoring technologies.
  • Support configuration, tuning, maintenance, and policy management for network, endpoint, and mobile security tools.
  • Review security-tool policies for outdated rules, signatures, and blocks and recommend appropriate updates.
  • Research and test new tools, technologies, and techniques that may improve operational efficiency or enterprise visibility.
  • Help communicate newly created or updated security content to the teams that use it.

Benefits

  • Healthcare coverage
  • Paid time off
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service