Operations Security Advisor / SOC Analyst

P3S Corporation
United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Compensation
$74,000.0 - $90,000.0
Working hours
Regular working hours
Job source

Tech stack

Multitier Architecture Microsoft Windows Active Directory Antivirus Softwares User Authentication Microsoft Azure CompTIA Security+ Cyber Security Information Systems Computer Networks Linux Multi-Factor Authentication
+31 more
Event Logging Monitoring of Systems Issue Tracking Systems Intrusion Detection Systems Virtual Private Networks (VPN) Linux System Administration Log Analysis Microsoft Security Essentials Microsoft Office Windows Servers Remote Access Technology Phishing Zero Trust Network Access Security Information and Event Management Transmission Control Protocol (TCP) Wireshark EndPointSecurity Computer Networking Systems Cloud Platform System Cyber Threat Analysis Firewalls (Computer Science) SC Clearance Information Technology Cisco Firewalls Nessus Microsoft Sentinel Cyber Warfare Splunk Cisco Vulnerability Analysis Vmware

Job description

Seeking a motivated and mission-focused Operations Security Advisor I / SOC Analyst to support cybersecurity monitoring and defensive cyber operations within a federal government enterprise environment. This role serves as a frontline Security Operations Center (SOC) analyst responsible for monitoring enterprise security tools, identifying suspicious activity, performing initial incident triage, and escalating cybersecurity events in accordance with established federal security procedures and operational playbooks., * Monitor, analyze, and triage cybersecurity alerts generated from Security Information and Event Management (SIEM), Endpoint Detection & Response (EDR), Intrusion Detection Systems (IDS), Intrusion Prevention Systems (IPS), firewalls, and enterprise monitoring tools.

  • Conduct initial investigations involving suspicious network traffic, malware activity, phishing attempts, unauthorized access attempts, anomalous user behavior, and potential indicators of compromise (IOCs).
  • Review and correlate logs from multiple security platforms including Windows Event Logs, Linux systems, Active Directory, VPN solutions, cloud environments, and endpoint security tools.
  • Document investigative findings, incident timelines, escalation actions, and remediation recommendations within ticketing and case management systems.
  • Escalate confirmed or high-risk cybersecurity incidents to Tier II/Tier III analysts, Incident Response teams, engineers, or government stakeholders.
  • Support continuous monitoring requirements aligned with federal cybersecurity standards and operational procedures.
  • Follow established SOC playbooks, incident response procedures, escalation matrices, and operational checklists to ensure consistent and auditable incident handling.
  • Assist with identifying recurring threats, vulnerability trends, suspicious patterns, and operational gaps impacting enterprise security posture.
  • Participate in cybersecurity operations briefings, shift turnover meetings, operational reporting, and knowledge-sharing activities.
  • Maintain awareness of emerging cyber threats, attack methodologies, indicators of compromise, and evolving cybersecurity best practices impacting federal environments.
  • Support compliance initiatives aligned with federal cybersecurity frameworks including:
  • NIST SP 800-53
  • RMF (Risk Management Framework)
  • DISA STIG compliance
  • Zero Trust security principles
  • Federal incident reporting procedures, + Technical Support in enterprise IT environments
  • Experience reviewing and analyzing security alerts, logs, or suspicious activity within enterprise environments.
  • Foundational understanding of:
  • TCP/IP networking, This position supports a federal cybersecurity operations environment requiring professionalism, operational discipline, strict adherence to security procedures, and collaboration within a mission-focused SOC team. Candidates must be comfortable supporting rotational schedules, operational coverage requirements, and time-sensitive cybersecurity response activities.

Requirements

Do you have experience in Windows Server administration?, Do you have a High school diploma or GED?, The ideal candidate will possess foundational cybersecurity knowledge, strong analytical and troubleshooting skills, and the ability to operate effectively within a structured SOC environment supporting enterprise-level systems, applications, cloud environments, and network infrastructures.

This position is ideal for early-career cybersecurity professionals seeking hands-on experience supporting federal cyber defense operations and incident response activities., * High School Diploma or GED required.

  • Associate’s Degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or related technical discipline preferred.
  • Bachelor’s Degree in Cybersecurity, Computer Science, Information Assurance, Network Engineering, or related field highly desired.

Required Experience

  • Approximately 1 year of experience in one or more of the following:
  • Security Operations Center (SOC) operations
  • Cybersecurity monitoring
  • IT Help Desk / Service Desk, + VPN technologies
  • Windows and Linux operating systems
  • Active Directory
  • Authentication and access control concepts
  • Experience working with or exposure to enterprise cybersecurity tools such as:
  • SIEM platforms
  • EDR/XDR tools
  • Antivirus solutions
  • Vulnerability scanning platforms
  • Ticketing systems
  • Ability to communicate technical findings clearly both verbally and in writing.
  • Strong analytical and troubleshooting skills with attention to detail.

Required Certifications

Candidates must possess at least one of the following certifications or obtain within 90 days of hire:

  • CompTIA Security+
  • ISC2 Certified in Cybersecurity (CC)
  • Cisco Certified Support Technician (CCST) Cybersecurity
  • Microsoft SC-900
  • Cisco CyberOps Associate

Preferred Certifications

The following certifications are highly desirable:

  • CompTIA CySA+
  • GIAC Security Essentials (GSEC)
  • Certified Ethical Hacker (CEH)
  • Splunk Core Certified User
  • Microsoft SC-200

Clearance & Federal Requirements

  • U.S. Citizenship required.
  • Ability to successfully pass a federal background investigation.
  • Active Secret Clearance preferred.
  • Candidates with prior Department of Defense (DoD), federal civilian agency, or government contractor experience are highly desired.
  • Familiarity with federal cybersecurity environments, compliance standards, and operational security requirements preferred.

Desired Technical Skills

Experience or familiarity with the following technologies and platforms is highly desirable:

  • Splunk
  • Microsoft Sentinel
  • CrowdStrike Falcon
  • Defender for Endpoint
  • Tenable / Nessus
  • Wireshark
  • Palo Alto or Cisco firewalls
  • Active Directory
  • Office 365 / Azure environments
  • VMware
  • Windows Server environments
  • Linux administration basics
  • Multi-factor authentication solutions
  • Endpoint security and log analysis tools

Benefits & conditions

4.14.1 out of 5 stars United States $74,000 - $90,000 a year - Full-time, Pulled from the full job description

  • 401(k)
  • Health insurance
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Employee assistance program
  • Disability insurance, Compensation is based on experience, certifications, education, technical qualifications, clearance level, and federal contract requirements.

Benefits package that may include:

  • Medical, Dental, and Vision, Life, STD & LTD Insurance
  • 401(k) Retirement Plan
  • Paid Time Off (PTO)
  • Paid Federal Holidays
  • Employee Assistance Program (EAP)

Estimated Salary Range: $74,000 - $90,000 annually

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:40 min

Managing containerized infrastructure with Podman Desktop

Cedric Clyburn Cedric Clyburn +1 · WWC 2025

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

1:41 min

Parallels between cloud and legacy infrastructure lock-ins

Björn Stahl Björn Stahl · WWC 2024

Videos

See all

Related articles

See all