Cybersecurity Analyst — SOC, Incident Response and GRC, US Employers

US Security Operations & Managed Detection Teams (Aggregated) United States, Nationwide Full-time

Job Description

Banks, hospitals, government contractors, managed service providers and in-house security teams across the United States hire analysts to watch their systems, work out which alerts matter, and act on the ones that do. The work splits into two quite different shapes: security operations, which is monitoring and incident response and often runs on a shift rota, and governance, risk and compliance, which is assessment and documentation on business hours.

What the work involves

Triaging alerts from a SIEM or an endpoint platform, separating a real intrusion from a misconfigured scanner, escalating with enough evidence for the next tier to act, and writing up what happened afterwards. In GRC roles it is control assessments against a framework, evidence gathering, and explaining to engineering teams why a finding matters.

Requirements

  • A working understanding of networking and operating systems — you cannot judge whether traffic is suspicious without knowing what normal looks like
  • SIEM and endpoint detection tooling, and alert triage against a documented escalation path
  • CompTIA Security+ or an equivalent entry credential for junior roles; senior roles ask for experience first and certification second
  • One compliance framework in depth for GRC work — NIST SP 800-53 or 800-171 are the most requested
  • Cloud platform security on AWS or Azure, increasingly assumed rather than a bonus
  • Scripting, most often Python, for anything you have to do more than twice

How the pay is structured

  • Salaried roles sit against the BLS information security analyst occupation: a $129,180 median as of May 2025, with the lowest tenth under $75,090 and the highest tenth above $199,850
  • Cleared roles pay a premium over uncleared equivalents, because the pool of people eligible for them is small
  • Shift work in a 24x7 operations centre often carries a differential for nights and weekends — ask, because it is not always advertised

Before you apply

Ask whether the role requires a security clearance, and whether the employer sponsors one. A clearance needs US citizenship and an employer to sponsor it; you cannot obtain one yourself. A large share of the postings around Washington DC, Northern Virginia and Fort Meade are cleared roles, and the requirement is often buried well down the advertisement.

Note: pay, shift patterns, clearance requirements and any sponsorship decision are set by each employer — not by JobGader. Confirm the details on the employer's own advertisement before applying.

Ready to apply for this Cybersecurity Analyst — SOC, Incident Response and GRC, US Employers role?

Take the next step in your career — submit your application directly with the employer.

Skills & Keywords

Auto-detected from this job's description. Click any skill to find similar roles.

Start your search

Your next job is one click away

Real openings across the USA, the UK, Australia, Canada, Pakistan, Saudi Arabia, the UAE, Germany, Indonesia, Italy, Japan, Oman, France, Kuwait, Netherlands and Singapore — with straight answers on which visa routes are actually open. Free to apply, and you don't need an account.

16Countries
WeeklyNew Jobs
NoSign-Up
100%Free