Security Operations Center Cyber Analyst

ArcfieldMiddletown, RI

About The Position

This role involves monitoring and analyzing security events using tools like Splunk and Airlock Digital. The Analyst on Duty will investigate alerts to determine if they represent a threat or normal activity. The position also includes providing threat detection and incident response to mitigate network risks, and improving security detection analytics by identifying and correcting detection gaps. Proficiency in scripting languages such as PowerShell, Python, and Bash is required.

Requirements

  • BS 2-4 Years, MS 0-2 (Experience)
  • 6+ Years experience in Security Operations Center processes and using SIEM and XDR tools
  • Proficiency in scripting languages (PowerShell, Python, Bash, etc.)
  • Strong background in Security Compliance & Vulnerability Management.
  • Familiarity with adhering to Cybersecurity Standard Operating Procedures.
  • Ability to review and update SOP documents for clarity and accuracy.
  • Prior experience with deploying enterprise tools on Domain Computers, including Antivirus, endpoint protection, and vulnerability scanning.
  • Proficient in Active Directory (AD) & Domain Controller (DC) Administration.
  • Knowledge of Windows Server Administration, including Windows Server 2019/2022/2025 internals, registry, event logs, and system services.
  • Experience with Windows security baselines (CIS, DISA STIG).
  • CompTIA Security+ CE
  • Active Secret DoD Security Clearance required for this role

Responsibilities

  • Monitor and analyze security events in Splunk and Airlock Digital.
  • Investigate alerts triggered in the Splunk Console to determine if a threat or normal activity is allowed in the environment.
  • Provide threat detection and incident response to mitigate risks to the Network.
  • Troubleshoot, improve, and develop security detection analytics.
  • Determine detection gaps and draft analytics to correct them.
  • Interpret activity from various sources (Windows/Linux workstations/servers, Firewall, Switch, Router, Endpoint Security, Wireless Intrusion Detection, other security/application logs) to identify malicious vs. expected behavior.
  • Utilize scripting languages (PowerShell, Python, Bash, etc.).
  • Understand and respond to security detections in a SIEM adhering to Incident Response Processes.
  • Collect relevant information from network and host logs, correlate events to develop incident timelines, and deduce root cause.
  • Collaborate with ISSOs and engineers/developers/admins to resolve security incidents.
  • Deploy enterprise tools on Domain Computers, including Antivirus, endpoint protection, and vulnerability scanning.
  • Administer Active Directory (AD) & Domain Controller (DC).
  • Administer Windows Server, including Windows Server 2019/2022/2025 internals, registry, event logs, and system services.
  • Apply Windows security baselines (CIS, DISA STIG).

Benefits

  • Health Insurance
  • Life Insurance
  • Paid Time Off
  • Holiday Pay
  • Short Term and Long-Term Disability
  • Retirement and Savings
  • Learning and Development opportunities
  • wellness programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service