The Enterprise Security Analyst II is a hands-on Security Operations Center (SOC) role responsible for monitoring alerts, investigating security events, supporting incident response, and improving security operations.
Key Responsibilities
Security Operations and Incident Response
Monitor and manage the SOC alert queue across endpoint, identity, network, email, cloud, and log monitoring platforms
Independently triage and investigate security alerts and events, distinguishing confirmed threats from benign activity using available evidence and telemetry
Support the full incident lifecycle, including investigation, escalation, containment support, remediation follow-up, documentation, and closure
Escalate incidents with clear evidence, impact assessment, and recommended next steps
Apply playbooks and runbooks while identifying opportunities to improve alert quality, response consistency, automation, and analyst enablement
Threat Intelligence and Threat Hunting
Analyze relevant threat intelligence to identify threats, campaigns, vulnerabilities, and adversary behaviors that may affect the organization
Enrich alerts and investigations with context about threat actors, malware, indicators, vulnerabilities, and attack techniques
Assist with threat hunts across endpoint, identity, network, cloud, and application telemetry
Use MITRE ATT&CK to support investigations, communicate adversary behavior, and identify detection gaps
Partner with security engineers and analysts to turn relevant intelligence into detections, hunts, watchlists, playbooks, blocking recommendations, or response improvements
Requirements
2+ years of cybersecurity experience with hands-on involvement in security monitoring, alert triage, and incident investigation
Experience analyzing endpoint, identity, network, cloud, email, and log data to identify suspicious or malicious activity
Working knowledge of SIEM and EDR platforms, common triage workflows, and security telemetry analysis
Strong understanding of networking, operating systems, identity and access concepts, cloud security fundamentals, and core security protocols
Working knowledge of cyber threat intelligence concepts, including indicators, threat actors, campaigns, vulnerabilities, and adversary tactics, techniques, and procedures
Ability to write clear investigation notes, incident records, intelligence summaries, and recommendations for technical and non-technical audiences
U.S. citizenship is mandatory
Ability and willingness to obtain security clearance
Bachelors in Cybersecurity, Information Technology, Computer Science, or a related STEM degree
Experience performing threat intelligence analysis, threat hunting, incident response, or security engineering in an enterprise environment
Experience converting threat intelligence into detections, hunts, watchlists, playbooks, response actions, or mitigation recommendations
Familiarity with SOAR platforms, detection engineering practices, automation, scripting, or query languages such as PowerShell, Python, KQL, or SPL
Relevant certifications such as CompTIA Security+, GCIH, GCED, GCIA, GCFA, GCTI, CTIA, or Microsoft security certifications
#LI-TM1
#LI-onsite
Benefits & Perks
Esri’s competitive total rewards strategy includes industry-leading health and welfare benefits: medical, dental, vision, basic and supplemental life insurance for employees (and their families), 401(k) and profit-sharing programs, minimum accrual of 80 hours of vacation leave, twelve paid holidays throughout the calendar year, and opportunities for personal and professional growth. Base salary is one component of our total rewards strategy. Compensation decisions and the base range for this role take into account many factors including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs.