> Markdown version of [/jobs/ext/1788865-shift-lead-master-level-cyber-defense-analyst-intrusion-detection-team](https://www.wearedevelopers.com/jobs/ext/1788865-shift-lead-master-level-cyber-defense-analyst-intrusion-detection-team). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Shift Lead (Master Level Cyber Defense Analyst / Intrusion Detection Team - **Company:** GLOBAL INSIGHTS LLC - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Computer Networks, Web Servers, Intrusion Detection and Prevention, Intrusion Detection Systems, Python (Programming Language), Log Analysis, Packet Analyzer, Security Information and Event Management, Snort (Software), Scripting, Cyber Threat Analysis, Firewalls (Computer Science), Cybercrime, Grep, Epic ECSA, Cyber Warfare, Splunk - **Published:** July 2, 2026 - **Apply:** https://careersingovernment.com/job/1917760/soc-site-lead-with-security-clearance/ ## About the Role Shift 3: 11:00 PM - 7:30 AM, Bachelor's degree + 8 years of intrusion detection experience 7+ years of hands-on intrusion detection across security technologies (IDS/IPS, HIPS, WAN monitoring) 5+ years performing senior-level log analysis (SIEM, Splunk, server logs, network traffic) 2+ years of leadership experience as a SOC or cybersecurity shift lead Strong experience with Splunk SIEM (including advanced query creation) Experience analyzing: Firewall ACLs Snort-based IDS events PCAPs and packet analysis Web server logs and raw log data One required certification (minimum): GCIA, ECSA, GPPA, GCED, SSCP, or CISSP Splunk Fundamentals I & II certification Plusses: Deep threat intelligence background (TTP analysis, threat actor tracking) Experience briefing executive leadership Advanced scripting or automation skills (e.g., Python, advanced GREP) Experience in high-security federal or government SOC environments ## Description Familiarity with 24x7x365 enterprise SOC operations Responsibilities Insight Global is seeking a Shift Lead (Master Level Cyber Defense Analyst / Intrusion Detection Team) for a top cybersecurity and federal services client. This candidate will lead a team within a 24/7 Security Operations Center, overseeing real-time threat detection, analysis, and response. They will combine deep technical expertise with leadership capabilities to guide analysts, assess cyber threats, and deliver actionable intelligence to stakeholders. The ideal candidate thrives in a fast-paced, high-stakes environment and brings strong experience with SIEM tools, intrusion detection technologies, and advanced cyber threat analysis. Lead and mentor a team of intrusion analysts on overnight SOC shift Monitor, detect, and respond to cyber threats in real time Correlate threat intelligence with network/system activity Analyze intrusion signatures and attacker TTPs Produce actionable intelligence reports for incident response teams Conduct deep-dive investigations using logs, SIEM, and packet data Provide security posture assessments and recommendations Deliver briefings and reports to leadership on threat landscape Shifts Available, Shift 1: 7:00 AM - 3:30 PM Shift 2: 3:00 PM - 11:30 PM, Familiarity with 24x7x365 enterprise SOC operations Responsibilities Insight Global is seeking a Shift Lead (Master Level Cyber Defense Analyst / Intrusion Detection Team) for a top cybersecurity and federal services client. This candidate will lead a team within a 24/7 Security Operations Center, overseeing real-time threat detection, analysis, and response. They will combine deep technical expertise with leadership capabilities to guide analysts, assess cyber threats, and deliver actionable intelligence to stakeholders. The ideal candidate thrives in a fast-paced, high-stakes environment and brings strong experience with SIEM tools, intrusion detection technologies, and advanced cyber threat analysis. Lead and mentor a team of intrusion analysts on overnight SOC shift Monitor, detect, and respond to cyber threats in real time Correlate threat intelligence with network/system activity Analyze intrusion signatures and attacker TTPs Produce actionable intelligence reports for incident response teams Conduct deep-dive investigations using logs, SIEM, and packet data Provide security posture assessments and recommendations Deliver briefings and reports to leadership on threat landscape ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)