> Markdown version of [/jobs/ext/1483304-mid-level-soc-analyst-hybrid](https://www.wearedevelopers.com/jobs/ext/1483304-mid-level-soc-analyst-hybrid). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Mid-Level SOC Analyst - Hybrid - **Company:** KeyLogic, LLC - **Location:** Alexandria, VA, United States (Remote available) - **Experience:** Experienced - **Salary:** $80,000.0 - **Contract:** Permanent contract - **Skills:** .NET Framework, Microsoft Windows, Active Directory, Data Analysis, Apple Mac Systems, Bash Shell, Border Gateway Protocol, Cyber Security, Computer Networks, Computer Engineering, Dynamic Host Configuration Protocol, Linux, Domain Name System (DNS), Perl (Programming Language), Hypertext Transfer Protocols (HTTP), Internet Control Message Protocol, Intelligence Analysis, Intrusion Detection Systems, Multi-protocol Systems, Python (Programming Language), Simple Mail Transfer Protocols, Routing, Pattern Recognition, Windows PowerShell, Ruby, Security Information and Event Management, Software Engineering, SQL Databases, Transmission Control Protocol (TCP), Web Applications, Scripting, Computer Networking Systems, QRadar, Malware, Tanium Platform Expertise, Information Technology, Cybercrime, Splunk - **Published:** July 29, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/87873089/1 ## About the Role response. A strong work ethic, diligent time and attendance, written and verbal communications skills are a must. The ideal candidate will have a solid understanding of cyber threats and information security in the domains of TTP's, Threat Actors, Campaigns, and Observables. Additionally, the ideal candidate would be familiar with intrusion detection systems, intrusion analysis, security information event management platforms, endpoint threat detection tools, and security operations ticket management. While the position is primarily remote currently, onsite in Alexandria, VA work may be required in the future., * Mid-level analyst requires 3+ years of experience working in network defense environments. * Bachelor's Degree in Information Technology, Cyber Security, Computer Science, Computer Engineering, or Electrical Engineering. * Strong analytical and technical skills in computer network defense operations, ability to lead efforts in Incident Handling (Detection, Analysis, Triage), Hunting (anomalous pattern detection and content management) and Malware Analysis. * Prior experience and ability to with analyzing information technology security events to discern events that qualify as legitimate security incidents as opposed to non-incidents. This includes security event triage, incident investigation, implementing countermeasures, and conducting incident response. * Previous hands-on experience with a Security Information and Event Monitoring (SIEM) platforms and/or log management systems that perform log collection, analysis, correlation, and alerting is required (preferably within IBM Qradar or Splunk). * Strong logical/critical thinking abilities, especially analyzing security events (windows event logs, Tanium queries, network traffic, IDS events for malicious intent). * Strong proficiency Report writing - a technical writing sample and technical editing test will be required if the candidate has no prior published intelligence analysis reporting, excellent verbal and written communications skills and ability produce clear and thorough security incident reports and briefings. * Excellent organizational and attention to details in tracking activities within various Security Operation workflows. * A working knowledge of the various operating systems (e.g. Windows, OS X, Linux, etc.) commonly deployed in enterprise networks, a conceptual understanding of Windows Active Directory is also required, and a working knowledge of network communications and routing protocols (e.g. TCP, UDP, ICMP, BGP, MPLS, etc.) and common internet applications and standards (e.g. SMTP, DNS, DHCP, SQL, HTTP, HTTPS, etc.). * Experience with the identification and implementation of counter-measures or mitigating controls for deployment and implementation in the enterprise network environment. * Ability to support coverage requirements for various shifts during holidays and weekends when required. * Ability to work greater than 40 hours per week as needed (occasional night and weekend work required) and/or 12-hour shift in a single day. Desired Qualifications: * Ability to develop rules, filters, views, signatures, countermeasures and operationally relevant applications and scripts to support analysis and detection efforts. * Familiarity with coding, scripting languages (BASH, Powershell, Python, PERL, RUBY etc.) or software development frameworks (.NET). ## Description KeyLogic is currently seeking a Mid-level Security Operation Center Analysts (SOC) to support a federal SOC program. The program provides comprehensive Security Monitoring and Incident Response support through 24O7O365 monitoring and analysis of potential threat activity targeting the enterprise. The team conducts event triage and security investigations for potential threat activity identified within the organization, conduct deep-dive forensic investigations (host-based and network), identify and implement countermeasures, as well as track and report on incident activity to senior management. To support this vital mission, staff are on the forefront of providing SOC Operations to include the development of advanced analytics and countermeasures to protect critical assets from various cyber threats. To ensure the integrity, security and resiliency of critical operations, we are seeking candidates with diverse backgrounds in cyber security systems operations, analysis and incident, Corporate duties such as solution/proposal development, corporate culture development, mentoring employees, supporting recruiting efforts, will also be required. The program is currently operating remotely but will be performed onsite in Alexandria, VA when directed to do so by the customer. Position is contingent on successfully completing a program-based background investigation. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk)