Cybersecurity Engineer - SOC Analyst

QUANTUM SKY LLC
Fort Lee, VA, United States
1 day ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Apple Mac Systems Microsoft Azure Border Gateway Protocol Cyber Security Computer Networks Computer Forensics Dynamic Host Configuration Protocol Linux Domain Name System (DNS) Event Logging Hypertext Transfer Protocols (HTTP)
+18 more
Internet Control Message Protocol Networking Hardware Intrusion Detection and Prevention Intrusion Detection Systems Multi-protocol Systems Pcap Simple Mail Transfer Protocols NetFlow Routing Packet Analyzer Pattern Recognition Security Information and Event Management SQL Databases Transmission Control Protocol (TCP) Web Applications Computer Networking Systems Malware Splunk

Job description

  • Lead efforts in Incident Handling (Detection, Analysis, Triage), Hunting (anomalous pattern detection and content management) and Malware Analysis
  • Analyze information technology cybersecurity events to discern events that qualify as legitimate security incidents as opposed to non-incidents.
  • Conduct security event triage, incident investigation, implement countermeasures, and conduct computer incident response.
  • Monitor customer’s Security Information and Event Monitoring (SIEM) platforms and/or log management systems that perform log collection, analysis, correlation, and alerting (i.e. Splunk, Azure Sentinel).
  • Analyze security events (i.e. windows event logs, network traffic, IDS events for malicious intent)
  • Track cyber activities within various SOC workflows.
  • View alerts and system logs from various operating systems (e.g. Windows, OS X, Linux, etc.) commonly deployed in enterprise networks.
  • View and analyze NetFlow data and packet capture (PCAP).
  • View logs derived from network devices and routing protocols (e.g. TCP, UDP, ICMP, BGP, MPLS, etc.) and common internet applications and standards (e.g. SMTP, DNS, DHCP, SQL, HTTP, HTTPS, etc.)
  • Assist with preparing, validating, and maintaining security documentation including, but not limited to cybersecurity incident response plan, risk assessments, legal investigations.
  • Conduct SOC level 1tasks and duties, when needed.
  • Escalate when necessary to Level 3 support, SOC lead, or watch officer.
  • Other services and support as needed or directed by the government.

Requirements

Required:

  • 3-7 years’ of experience in a relevant field
  • Ensure personnel are compliant with DoDI 8140.02 Identification, Tracking, and Reporting of Cyberspace Workforce Requirements as set forth in the DoD Cyber Workforce Framework (DCWF). Personnel must hold required certifications at time of hire and must maintain certifications for the entire performance period.
  • Ensure Incident Response & Analysis personnel also assigned as forensic analysts also hold and maintain an industry-recognized Computer Forensics certification such as the GIAC GCFE, GCFA, or EC-Council CHFI.
  • Ensure Incident Response & Analysis personnel are knowledgeable of industry-standard methods and practices concerning the use and monitoring of intrusion detection products in a production network.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all