> Markdown version of [/jobs/ext/1836940-senior-soc-analyst-back-half-night-shift](https://www.wearedevelopers.com/jobs/ext/1836940-senior-soc-analyst-back-half-night-shift). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior SOC Analyst - Back-Half Night Shift - **Company:** CCS, LLC - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $100,000.0 - $130,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Amazon Web Services, Command-Line Interface, Cloud Computing, Command Prompt, Cyber Security, Linux, Linux Commands, Networking Basics, Windows PowerShell, Scripting, SC Clearance, SolarWinds (Software), Encase, Splunk - **Published:** July 7, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9014111/senior-soc-analyst-back-half-night-shift ## About the Role We are seeking SOC Analyst for multiple opportunities that are 100% onsite in Washington, DC. ALL APPLICANTS MUST HAVE AN ACTIVE TOP-SECRET CLEARANCE. NO EXCEPTIONS!!!!, * Must be currently supporting 24x7x365 SOC or Cyber Watch operations for a Federal Government agency. * Must have the ability to assess complex environments, establish situational awareness, and immediately contribute to mission success. * Must be a self-starter with the ability to quickly assume responsibilities and make an immediate positive impact on team objectives. * Must be able to work with minimal to no supervision. * Must be able to learn new technologies and techniques provided by the SOC Chief as well as "On your own". * Must be able to read, write, and comprehend at the advanced level. * Must be able to read, comprehend, and apply standard operating procedures, playbooks, and directives provided by the SOC Chief. * Must have applied knowledge of the full Triage & incident response process to determine if an event is a true positive or false positive. * Must be able to hypothesize during an event to determine an outcome. * Must have intermediate-advanced understanding of various cyber-attacks (new and old) across various platforms and environments including Active Directory, Windows, Linux. Cloud is a plus. * Must know how to perform and create intermediate-advanced custom Splunk searches in Splunk Enterprise Security to obtain various information for various cyber investigations as needed and/or requested by senior leadership. * Must know how to perform intermediate-advanced threat hunting in Splunk for various cyber-attacks including, but not limited to: Active Directory Attacks, User Behavior Analysis, Privileged User activity, Advanced Persistent Threat (APT) activity, and other ad hoc searches as needed and/or requested * Must be able to perform intermediate-advanced level root-cause analysis using various native and security tools (Splunk Enterprise Security, Trellix, ACAS, SolarWinds, EnCase, AWS Guard Duty, AWS Security Hub) * Must be able to perform intermediate-advanced level host-based log and registry analysis. * Must be able to perform intermediate-advanced level log correlation to investigate various cyber events and incidents using native and security tools (Splunk Enterprise Security, Trellix, ACAS, SolarWinds, EnCase, AWS Guard Duty, AWS Security Hub) * Must have intermediate-advanced understanding and applied knowledge of networking fundamentals to include, but not limited to most common ports and protocols, what they are, and how they work) * Must have an intermediate-advanced understanding and applied knowledge of command line tools to obtain information needed for triage analysis including, but not limited to windows command line, Linux command line, PowerShell, etc. * Must be able to assist junior level analysts with various investigations as needed. * Prior Help desk and system administrators with ticket handling, Active Directory, and command line scripting experience preferred and are encouraged to apply. Education Requirements A bachelors or higher degree is highly preferred and a DOD IAT III certification ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [The best of two worlds - Bringing enterprise-grade Linux to the vehicle](https://www.wearedevelopers.com/videos/67-the-best-of-two-worlds-bringing-enterprise-grade-linux-to-the-vehicle) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Top 6 Hackathons for Developers in 2023](https://www.wearedevelopers.com/magazine/263-top-6-hackathons-for-developers-in-2023) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)