Shift Lead (Master Level Cyber Defense Analyst / Intrusion Detection Team

GLOBAL INSIGHTS LLC
Washington, DC, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Working hours
Shift work

Tech stack

Cyber Security Computer Networks Web Servers Intrusion Detection and Prevention Intrusion Detection Systems Python (Programming Language) Log Analysis Packet Analyzer Security Information and Event Management Snort (Software) Scripting Cyber Threat Analysis
+6 more
Firewalls (Computer Science) Cybercrime Grep Epic ECSA Cyber Warfare Splunk

Job description

Familiarity with 24x7x365 enterprise SOC operations Responsibilities Insight Global is seeking a Shift Lead (Master Level Cyber Defense Analyst / Intrusion Detection Team) for a top cybersecurity and federal services client. This candidate will lead a team within a 24/7 Security Operations Center, overseeing real-time threat detection, analysis, and response. They will combine deep technical expertise with leadership capabilities to guide analysts, assess cyber threats, and deliver actionable intelligence to stakeholders. The ideal candidate thrives in a fast-paced, high-stakes environment and brings strong experience with SIEM tools, intrusion detection technologies, and advanced cyber threat analysis. Lead and mentor a team of intrusion analysts on overnight SOC shift Monitor, detect, and respond to cyber threats in real time Correlate threat intelligence with network/system activity Analyze intrusion signatures and attacker TTPs Produce actionable intelligence reports for incident response teams Conduct deep-dive investigations using logs, SIEM, and packet data Provide security posture assessments and recommendations Deliver briefings and reports to leadership on threat landscape Shifts Available, Shift 1: 7:00 AM - 3:30 PM Shift 2: 3:00 PM - 11:30 PM, Familiarity with 24x7x365 enterprise SOC operations Responsibilities Insight Global is seeking a Shift Lead (Master Level Cyber Defense Analyst / Intrusion Detection Team) for a top cybersecurity and federal services client. This candidate will lead a team within a 24/7 Security Operations Center, overseeing real-time threat detection, analysis, and response. They will combine deep technical expertise with leadership capabilities to guide analysts, assess cyber threats, and deliver actionable intelligence to stakeholders. The ideal candidate thrives in a fast-paced, high-stakes environment and brings strong experience with SIEM tools, intrusion detection technologies, and advanced cyber threat analysis. Lead and mentor a team of intrusion analysts on overnight SOC shift Monitor, detect, and respond to cyber threats in real time Correlate threat intelligence with network/system activity Analyze intrusion signatures and attacker TTPs Produce actionable intelligence reports for incident response teams Conduct deep-dive investigations using logs, SIEM, and packet data Provide security posture assessments and recommendations Deliver briefings and reports to leadership on threat landscape

Requirements

Shift 3: 11:00 PM - 7:30 AM, Bachelor’s degree + 8 years of intrusion detection experience 7+ years of hands-on intrusion detection across security technologies (IDS/IPS, HIPS, WAN monitoring) 5+ years performing senior-level log analysis (SIEM, Splunk, server logs, network traffic) 2+ years of leadership experience as a SOC or cybersecurity shift lead Strong experience with Splunk SIEM (including advanced query creation) Experience analyzing: Firewall ACLs Snort-based IDS events PCAPs and packet analysis Web server logs and raw log data One required certification (minimum): GCIA, ECSA, GPPA, GCED, SSCP, or CISSP Splunk Fundamentals I & II certification Plusses: Deep threat intelligence background (TTP analysis, threat actor tracking) Experience briefing executive leadership Advanced scripting or automation skills (e.g., Python, advanced GREP) Experience in high-security federal or government SOC environments

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on careersingovernment.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

14:14 min

Addressing audience inquiries on analytical implementation and career growth

Julian Joseph · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

3:21 min

Building a custom bash script to detect secrets

Dwayne Mcdaniel · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

2:45 min

Auditing codebase signals to skip logical CSS conversion

Vidhya Krishnamoorthy Vidhya Krishnamoorthy · Europe 2026 Virtual

Videos

See all

Related articles

See all