Security Analyst I at Cyderes
Bentonville, AR
—
Jul 20, 2026
Bentonville, AR
Jul 22, 2026
What this job asks for AI summary
A hybrid, entry-to-mid-level security operations role based in northwest Arkansas, focused on monitoring and investigating threats within client environments. Day-to-day work involves threat hunting, incident scoping, log analysis through SIEM platforms, and applying the MITRE ATT&CK framework, with Google SecOps SOAR used to automate response workflows. The role also includes participation in an after-hours on-call rotation and suits candidates with at least a year of IT security experience and familiarity with EDR tools.
Junior level · 1+ years · Fayetteville-Springdale-Rogers, AR · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 25 people in the Fayetteville-Springdale-Rogers, AR area plausibly meet what this posting asks for (information security analysts). range 10–55
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $108,535 (middle half $86,358–$136,998).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
The role is titled 'Security Analyst I', which is an entry-level designation; combined with the 1+ year experience minimum and the scope of responsibilities (threat hunting, incident response, SIEM/SOAR usage), this maps to Junior seniority.
The EDR requirement names Cortex XDR, SentinelOne, CrowdStrike, and Microsoft Defender as explicit alternatives — experience with any one of them satisfies the gate.
The SIEM requirement names Google SecOps, Microsoft Sentinel, Splunk, Elastic, IBM QRadar, and Chronicle as explicit alternatives — experience with at least one is required.
Google SecOps SOAR is listed both as a required skill and referenced in the responsibilities section; it is treated as a hard gate.
Wiz (CSPM) is listed under requirements but framed with 'familiarity with' — a softer qualifier — so it is marked as preferred.
The scripting/programming requirement names Python, JavaScript, PowerShell, and Bash as interchangeable options; 'basic' experience is the stated bar.
Industry certification (Security+, CEH, OSCP, GCIH, GCIA, GSEC, GMON) is required or actively being pursued; this is a soft gate and not a named technology, so it is not emitted as a skill.
No compensation figures are provided in the posting.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.