Jobs and Careers
LA
SENIOR CYBERSECURITY OPERATIONS ANALYST (INFORMATION SECURITY)
LA MetroLos Angeles, United Statesfull_timeVerifiedPosted 15 Jul 2026
💰 $164,195/yr($109,470/yr – $164,195/yr)
About the role
Posting number: 2401258.2
Department: INFORMATION TECHNOLOGY AND SERVICES
Division: 3198 - INFORMATION SECURITY
Job classification: SENIOR CYBERSECURITY OPERATIONS ANALYST
Posting type: Open
Categories: IT and Computers, Security
Summary
Monitors, detects, and responds to security incidents and collaborates with various security, crisis and emergency management teams to ensure the safety of Metro’s digital and physical assets.
Recruitment Timelines: Interviews are projected to be scheduled for the week of August 10, 2026. These dates are subject to change. We encourage you to monitor your governmentjobs.com profile and emails for the latest updates.
Examples of duties
- Monitor cybersecurity events across assigned environment using advanced Security Information, Threat Intelligence, and Security Information and Event Management (SIEM) tools to detect and respond to security threats and incidents.
- Identify, analyze, and respond to security incidents, coordinating with teams to contain, mitigate, and recover from such breaches.
- Maintain awareness of local, national, and global threats and vulnerabilities and develop mitigation strategies to protect critical networks and assets.
- Analyze security data to identify potential security incidents, conduct root cause analysis, and offer actionable recommendations to prevent future occurrences.
- Identify and remediate vulnerabilities within assigned environments.
- Collaborate with Information Security and Information Technology Services (ITS) teams to implement security patches and updates.
- Maintain detailed and accurate records of security incidents, including timelines, actions taken, and outcomes.
- Prepare and furnish reports for management and relevant stakeholders on Cyber Security Operations Center (CSOC) activities and incident response metrics.
- Work closely with ITS, and other technical and security teams to ensure effective communication and coordination during security incidents.
- Participate in cross-functional security initiatives and projects and take responsibility for associated tasks.
- Address relevant maintenance and tuning of CSOC tools, including SIEM, IDS/IPS, firewalls, and other security technologies.
- Address improvement plans to the development and enhancement of CSOC processes, playbooks, and procedures.
- Identify areas for improvement in incident response and threat detection capabilities.
- Address innovative ideas to security awareness campaigns, based on operations and incident response activities.
May be required to perform other related job duties
Qualifications
A combination of education and/or experience that provides the required knowledge, skills, and abilities to perform the essential functions of the position. Additional experience, as outlined below, may be substituted for required education on a year-for-year basis. A typical combination includes:
Education:
- Bachelor’s Degree in Information Technology, Cybersecurity, Computer Science, or a related field
- Five years of relevant experience performing information security, security monitoring, and incident response; some positions in this class may require specialized experience in area of assignment
- A valid California Class C Driver License or the ability to utilize an alternative method of transportation when needed to carry out job-related essential functions
- Certification in one or more areas of cyber security specialization: Certified Information Systems Security Professional (CISSP), GIAC Certified Incident Handler (GCIH), Certified Ethical Hacker (CEH), or equivalent preferred
- Ability to work in a secure CSOC environment, which may require extended periods of time sitting and working at a computer
- This is a 24/7 operation, and the role may require working in shifts, including nights, weekends, and holidays, to ensure continuous monitoring and response.
Preferred Qualifications
Preferred Qualifications (PQs) are used to identify relevant knowledge, skills, and abilities (KSAs) as determined by business necessity. These criteria are considered preferred qualifications and are not intended to serve as minimum
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s