> Markdown version of [/jobs/ext/2103234-associate-cyber-operations-analyst-soc-threat-management](https://www.wearedevelopers.com/jobs/ext/2103234-associate-cyber-operations-analyst-soc-threat-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Associate Cyber Operations Analyst - SOC Threat Management - **Company:** phia, LLC - **Location:** Fairfax, VA, United States (Remote available) - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Data Analysis, Microsoft Antivirus, Microsoft Azure, Boolean Algebra, Cloud Computing Security, CompTIA Security+, Cyber Security, Information Security Management, Intrusion Detection and Prevention, Intrusion Detection Systems, Information Systems Security Architecture Professional, Machine Learning, Network Forensics, Tensorflow, Security Information and Event Management, Google Cloud, Cloud Platform System, Feature Engineering, Cyber Threat Analysis, Information Technology, Cybercrime, Firepower, Cyber Warfare, Splunk, SentinelOne Expertise, Cisco - **Published:** August 18, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17976946?backUrl=%2Fcareer%2F17976946%2FAssociate-Cyber-Operations-Analyst-Soc-Threat-Management-Virginia-Fairfax ## About the Role * Experienced in cyber/IT security with at least 1 year of experience in IT and/or SOC operations. * Familiarity with Artificial Intelligence / Machine Learning (AI/ML) capabilities, and their application to cyber analysis and SOC operations. * Skilled in network traffic analysis and threat detection methodologies. * Strong understanding of Boolean logic, TCP/IP fundamentals, network-level exploits, and IDS/IPS technologies. * Familiar with control frameworks, risk management techniques, and cloud security (AWS, Azure, GCP). * Hands-on experience with cybersecurity automation and SIEM/SOAR platforms. * Proficient in using ML frameworks for anomaly detection, threat intelligence, and behavioral analysis. * Excellent communication, organizational, and interpersonal skills. Preferred Skills: * Experience with Splunk, ProofPoint, Cisco FirePower, SentinelOne, and Microsoft Defender suite. * Expertise with IDS/IPS architectures, signature creation, and anomaly-based detection. * Strong data analysis and feature engineering skills for ML-based security models. * Direct experience with AI/ML applications in SOC environments, including automated threat detection and predictive analytics. Required Education + Experience: * BA/BS in Computer Science, IT, or related field (or equivalent experience) with 1+ years of direct experience in cybersecurity and SOC analysis & operations * ...or... * 5+ years of experience in cybersecurity and IT and SOC analysis & operations Certifications (desired, or similar): * CompTIA Security+ * Certified Ethical Hacker (CEH) * GIAC Certified Enterprise Defender (GCED) * GIAC Certified Intrusion Analyst (GCIA) * GIAC Certified Detection Analyst (GCDA) * GIAC Certified Incident Handler (GCIH) * GIAC Defending Advanced Threats (GDAT) * GIAC Security Operations Certified (GSOC) * Certified Information Systems Security Professional (CISSP) Security Clearance/Vetting: * U.S. Citizenship required * Ability to obtain Public Trust clearance ## Description At phia we hire talented and passionate people who are focused on collaborative, meaningful work, providing technical and operational subject matter expertise and support services to our partners and clients. phia is hiring a Cyber Operations Analyst (SOC Threat Management) to support 24x7 operations in a large Federal agency Cyber Security Operations Center (CSOC). This role focuses on advanced cyber threat monitoring & detection, incident analysis and management, and leveraging AI/ML and automation to enhance SOC efficiency. The ideal candidate will have expertise in IT and cyber incident management, cyber threat intelligence and intrusion analysis, and hands-on experience with modern security tools and cloud environments. This shift-based position offers REMOTE work flexibility. Qualified candidates will be U.S. Citizens and located in the United States, able to achieve Public Trust security vetting approval. What You'll Do: * Support 24x7 monitoring, detection, and management of advanced cyber threats. * Execute operational processes in support of response efforts to identified security incidents. * Interpret output from the SIEM, incident reporting platforms and mailboxes, and phone calls to identify potential security incidents. * Perform incident analysis by correlating data from multiple sources to determine impact on critical systems or datasets. * Identify security problems which may require mitigating controls. * Analyze threat intelligence to assess risk and adapt defenses. * Provide subject matter expertise on network-based attacks, intrusion methodologies, and threat management. * Escalate complex incidents for further investigation and collaborate with other Threat Management team members. * Utilize AI/ML-based tools to detect anomalies, automate triage, and improve threat intelligence. * Stay current on cybersecurity trends, threat actors, and AI/ML advancements relevant to SOC operations. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Your Infrastructure Is Not a Playground: AI Agents for Infra Done Right](https://www.wearedevelopers.com/videos/2084-your-infrastructure-is-not-a-playground-ai-agents-for-infra-done-right) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)