Logo for Ardent

Detection & Monitoring Analyst

Role overview

Qualifications

  • Bachelor’s degree in cybersecurity, information assurance, computer science, or related field, or equivalent SOC experience.
  • Proof of relevant professional certifications such as CISSP, CISA, PMP, CEH, or other relevant certifications.
  • 4 years of hands-on SOC, detection engineering, intrusion analysis, continuous monitoring, incident response, network security, or threat-hunting experience.
  • Experience with SIEM and EDR/XDR platforms, log query languages, network telemetry, MITRE ATTCK mapping, case management, and incident escalation.

Responsibilities

  • Monitor approved testing activity across SIEM, EDR/XDR, identity, endpoint, network, cloud, and ticketing systems.
  • Validate whether expected signals are generated, correlated, enriched, prioritized, and represented accurately in alerts.
  • Trace analyst triage, escalation, communications, and handling timelines against OCIG-approved criteria and documented agency expectations.
  • Perform alert investigation, packet and network traffic analysis, log correlation, IOC review, malware or phishing analysis, and event-timeline reconstruction.

Key facts

  • Remote from: United States
  • Full time
  • Mid-level (2-5 years)
  • English

Hard skills

Other skills

  • Knowledge Transfer

About the company

Ardent logo

Ardent

IT Services & IT Consulting

For over 15 years, Ardent has served this country by delivering award-winning security and defense technology solutions. Our clients'​ missions range from medical evacuation in overseas theaters to border protection to port security. They trust Ardent to guarantee quality, reliability, and responsiveness. The Ardent Team is the underpinning of our success. Our IT professionals specialize in large-scale situational awareness, geographic visualization, cloud, and information sharing technologies. Ardent inspires its employees to love their jobs. We can help you grow your career by connecting you with our top-notch professionals on challenging projects. We actively mentor and equip our employees to be thought leaders in their fields, and we offer competitive salaries and benefits, including financial rewards for excellence. If you like a fast-paced environment where insights are valued and innovations encouraged, then we want to meet you. Please visit our Career Portal [url: http://www.ardentmc.com/careers] to discover opportunities at Ardent.

Company details

Company typeSME
IndustryIT Services & IT Consulting
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Ardent is seeking a Detection & Monitoring Analyst to join our team.  

This is a remote position with expected travel to Tallahassee, FL. 

Position Description:

Ardent is seeking a Detection & Monitoring Analyst that validates whether authorized test activity generates accurate security telemetry and whether agency detection processes identify, triage, escalate, and document events according to approved criteria. The analyst serves as the defender-side specialist connecting simulated activity to SIEM, EDR, network, identity, and ticketing evidence across a potentially broad multi-agency environment.

Responsibilities and Duties:

  • Monitor approved testing activity across SIEM, EDR/XDR, identity, endpoint, network, cloud, and ticketing systems.
  • Validate whether expected signals are generated, correlated, enriched, prioritized, and represented accurately in alerts.
  • Trace analyst triage, escalation, communications, and handling timelines against OCIG-approved criteria and documented agency expectations.
  • Perform alert investigation, packet and network traffic analysis, log correlation, IOC review, malware or phishing analysis when in approved scope, and event-timeline reconstruction.
  • Develop or recommend detection logic improvements, use cases, correlation rules, dashboards, and tuning actions while clearly separating recommendations from factual test results.
  • Preserve screenshots, alerts, queries, logs, timestamps, ticket records, analyst actions, and annotations in controlled evidence packages.
  • Identify telemetry gaps, blind spots, false negatives, inaccurate severity, weak correlation, and broken escalation paths.
  • Support vulnerability, remediation, and incident-specific reviews requested through OCIG.
  • Help deliver knowledge-transfer sessions on detection validation and evidence interpretation.

Requirements:

  • Bachelor’s degree in cybersecurity, information assurance, computer science, or related field, or equivalent SOC experience.
  • Proof of relevant professional certifications such as CISSP, CISA, PMP, CEH, or other relevant certifications.
  • 4 years of hands-on SOC, detection engineering, intrusion analysis, continuous monitoring, incident response, network security, or threat-hunting experience.
  • Experience with SIEM and EDR/XDR platforms, log query languages, network telemetry, MITRE ATT&CK mapping, case management, and incident escalation.
  • Ability to document expected versus observed results precisely and maintain evidence integrity.
  • Knowledge of NIST CSF Detect outcomes and access-control telemetry.

Preferred Qualifications:

  • SIEM content development, detection-as-code, or security analytics experience.
  • Experience with cloud-native logging, identity telemetry, SOAR, packet capture, threat intelligence, and forensic investigation.
  • Zero Trust monitoring or FedRAMP continuous-monitoring experience.
  • Government SOC or regulated-sector experience.

Due to the nature of the work we support, all candidates in consideration for this role must be willing to undergo the government issued background investigation process.

Ardent is an equal opportunity employer. We will not discriminate in employment, recruitment, advertisements for employment, compensation, termination, upgrading, promotions, and other conditions of employment against any employee or job applicant on the bases of race, color, gender, national origin, age, religion, creed, disability, veteran's status, sexual orientation, gender identity, gender expression, or any other basis protected by state, local, or federal law.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Related jobs

Other jobs at Ardent

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.