SOC Analyst

cFocus Software Incorporated
United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Cloud Computing Cloud Computing Security Cyber Security Linux Monitoring of Systems Intrusion Detection Systems Network Monitoring Security Information and Event Management In-Plane Switching (IPS) Mitre Att&ck Information Technology
+2 more
Cybercrime 3-tier Architectures

Job description

cFocus Software seeks a SOC Analyst to join our program supporting the National Institutes of Health (NIH). This position is fully remote. This position requires a Public Trust or the ability to obtain a public trust clearance., * Continuously monitor enterprise security systems and Security Operations Center (SOC) dashboards.

  • Analyze security alerts generated by SIEM, IDS/IPS, EDR, cloud security, and network monitoring platforms.
  • Identify indicators of compromise (IOCs) and suspicious activity.
  • Correlate security events across multiple technologies to identify potential cyber threats.
  • Monitor Windows, Linux, cloud, network, and endpoint environments for malicious activity.
  • Perform initial incident triage and classification.
  • Analyze security events to determine severity, scope, impact, and priority.
  • Validate potential security incidents and reduce false positives.
  • Escalate confirmed incidents to Tier 2 and Tier 3 Incident Response personnel.
  • Maintain incident tickets throughout the incident lifecycle.

Requirements

  • Public Trust Clearance
  • B.S. Computer Science, Information Technology, or a related field
  • Minimum 2 years of Security Operations Center (SOC) or cybersecurity monitoring experience.
  • Experience monitoring enterprise security environments.
  • Experience investigating cybersecurity incidents.
  • Knowledge of SIEM platforms and security monitoring technologies.
  • Understanding of NIST SP 800-61 Computer Security Incident Handling Guide.
  • Knowledge of MITRE ATT&CK Framework.
  • Ability to obtain and maintain NIH suitability/background investigation.

Benefits & conditions

Invitation for Job Applicants to Self-Identify as a U.S. Veteran

  • A ā€œdisabled veteranā€ is one of the following:
  • a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or
  • a person who was discharged or released from active duty because of a service-connected disability.
  • A ā€œrecently separated veteranā€ means any veteran during the three-year period beginning on the date of such veteran’s discharge or release from active duty in the U.S. military, ground, naval, or air service.
  • An ā€œactive duty wartime or campaign badge veteranā€ means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.
  • An ā€œArmed forces service medal veteranā€ means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on cfocussoftware.applytojob.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber Ā· WWC Europe 2026

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa Ā· LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard Ā· WWC 2025

1:45 min

Transitioning from software development to security roles

Stefania Chaplin Ā· WWC 2022

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 Ā· WWC Europe 2026

1:23 min

Understanding the complexity of cybersecurity domains

Jennifer Reif Ā· LIVE

Videos

See all

Related articles

See all