> Markdown version of [/jobs/ext/2016124-cybersecurity-engineer-soc-analyst](https://www.wearedevelopers.com/jobs/ext/2016124-cybersecurity-engineer-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Engineer - SOC Analyst - **Company:** QUANTUM SKY LLC - **Location:** Fort Lee, VA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Apple Mac Systems, Microsoft Azure, Border Gateway Protocol, Cyber Security, Computer Networks, Computer Forensics, Dynamic Host Configuration Protocol, Linux, Domain Name System (DNS), Event Logging, Hypertext Transfer Protocols (HTTP), Internet Control Message Protocol, Networking Hardware, Intrusion Detection and Prevention, Intrusion Detection Systems, Multi-protocol Systems, Pcap, Simple Mail Transfer Protocols, NetFlow, Routing, Packet Analyzer, Pattern Recognition, Security Information and Event Management, SQL Databases, Transmission Control Protocol (TCP), Web Applications, Computer Networking Systems, Malware, Splunk - **Published:** August 10, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9085057/cybersecurity-engineer-soc-analyst ## About the Role Required: * 3-7 years' of experience in a relevant field * Ensure personnel are compliant with DoDI 8140.02 Identification, Tracking, and Reporting of Cyberspace Workforce Requirements as set forth in the DoD Cyber Workforce Framework (DCWF). Personnel must hold required certifications at time of hire and must maintain certifications for the entire performance period. * Ensure Incident Response & Analysis personnel also assigned as forensic analysts also hold and maintain an industry-recognized Computer Forensics certification such as the GIAC GCFE, GCFA, or EC-Council CHFI. * Ensure Incident Response & Analysis personnel are knowledgeable of industry-standard methods and practices concerning the use and monitoring of intrusion detection products in a production network. ## Description * Lead efforts in Incident Handling (Detection, Analysis, Triage), Hunting (anomalous pattern detection and content management) and Malware Analysis * Analyze information technology cybersecurity events to discern events that qualify as legitimate security incidents as opposed to non-incidents. * Conduct security event triage, incident investigation, implement countermeasures, and conduct computer incident response. * Monitor customer's Security Information and Event Monitoring (SIEM) platforms and/or log management systems that perform log collection, analysis, correlation, and alerting (i.e. Splunk, Azure Sentinel). * Analyze security events (i.e. windows event logs, network traffic, IDS events for malicious intent) * Track cyber activities within various SOC workflows. * View alerts and system logs from various operating systems (e.g. Windows, OS X, Linux, etc.) commonly deployed in enterprise networks. * View and analyze NetFlow data and packet capture (PCAP). * View logs derived from network devices and routing protocols (e.g. TCP, UDP, ICMP, BGP, MPLS, etc.) and common internet applications and standards (e.g. SMTP, DNS, DHCP, SQL, HTTP, HTTPS, etc.) * Assist with preparing, validating, and maintaining security documentation including, but not limited to cybersecurity incident response plan, risk assessments, legal investigations. * Conduct SOC level 1tasks and duties, when needed. * Escalate when necessary to Level 3 support, SOC lead, or watch officer. * Other services and support as needed or directed by the government. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)