> Markdown version of [/jobs/ext/2184560-cysoc-analyst](https://www.wearedevelopers.com/jobs/ext/2184560-cysoc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # CYSOC Analyst - **Company:** Peraton Inc - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $112,000.0 - $179,000.0 - **Contract:** Permanent contract - **Skills:** CompTIA Security+, Cyber Security, Computer Networks, Domain Name System (DNS), Federal Information Processing Standards (FIPS), Network Security, Pcap, Log Analysis, NetFlow, Routing, Packet Analyzer, Remote Access Technology, Security Information and Event Management, TCP/IP, Workflow Management Systems, Mitre Att&ck, Malware, Cyber Threat Analysis, Tanium Platform Expertise, Cybercrime, Cyber Warfare, Splunk, Vulnerability Analysis - **Published:** August 22, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9111757/cysoc-analyst ## About the Role * Active TS/SCI or Q/SCI clearance required. * Minimum of 8 years with BS/BA; Minimum of 6 years with MS/MA; Minimum of 3 years with PhD., 12 years with a HS diploma * Experience supporting Security Operations Center (SOC), Computer Network Defense (CND), or cyber operations environments. * Hands-on experience with: * Splunk Enterprise Security (ES) * CrowdStrike Falcon * Tanium * SIEM and log aggregation platforms * Endpoint Detection and Response (EDR) tools * Security ticketing and workflow management systems Experience performing: * Incident response * Threat hunting * Malware analysis * Alert triage and escalation * Log correlation and forensic analysis Strong understanding of: * TCP/IP protocol suite * DNS * Routing and switching concepts * Network security architecture * Remote access security technologies * Enterprise security monitoring Experience analyzing: * NetFlow data * Packet captures (PCAP) * Security event logs * Indicators of compromise (IOCs) Knowledge of: * MITRE ATT&CK framework * Threat actors and adversary campaigns * Cyber kill chain methodologies * Intelligence Community cybersecurity operations Ability to communicate technical findings clearly through written reports and verbal briefings.Preferred Qualifications * Prior experience supporting Intelligence Community (IC), Department of Defense (DoD), or other Federal Government cybersecurity programs. * Familiarity with CDOC/SOC operational environments and federal cybersecurity compliance frameworks. * Experience with classified network environments and cross-domain security operations. * Industry certifications such as: * CompTIA Security+ * CySA+ * CEH * GCIH * GCIA * CISSP ## Description We are seeking a highly skilled Cybersecurity/SOC Analyst to support mission-critical cybersecurity operations for an IC customer. This position supports 24x7x365 Computer Network Defense (CND), threat monitoring, incident response, and cyber threat analysis activities within a classified enterprise environment. The ideal candidate will possess experience supporting Security Operations Center (SOC) operations, advanced threat detection, and incident response functions within government or national security environments. Candidates should have a strong understanding of cyber adversary tactics, techniques, and procedures (TTPs), threat actor methodologies, malware analysis, and enterprise security monitoring technologies. This role requires the ability to analyze complex security events, investigate anomalous activity, and coordinate rapid response actions to protect sensitive government systems and networks., * Provide continuous 24x7x365 monitoring, analysis, and response support for enterprise cyber defense operations. * Conduct Computer Network Defense (CND) activities in support of Intelligence Community (IC) mission requirements. * Monitor, analyze, triage, and respond to security events and cyber threats targeting enterprise infrastructure, networks, and endpoints. * Perform incident handling, malware analysis, and threat investigations utilizing tools including Splunk Enterprise Security (ES), CrowdStrike Falcon, Tanium, and enterprise eDiscovery platforms. * Validate security alerts through real-time log analysis and correlation to determine true positive incidents and initiate containment procedures. * Escalate and document incidents in accordance with established SOC/CDOC operational procedures and federal reporting requirements. * Analyze NetFlow data, packet captures (PCAP), DNS activity, and network traffic patterns to identify indicators of compromise (IOCs) and malicious behavior. * Conduct intrusion analysis and support advanced threat detection efforts involving nation-state and advanced persistent threat (APT) actors. * Track incidents and investigative activities within Security Operations Center workflows and ticket management systems. * Develop and maintain detailed incident reports, threat summaries, and operational documentation for leadership and cybersecurity stakeholders. * Collaborate with cyber defense, engineering, and intelligence teams to identify vulnerabilities and improve enterprise security posture. * Assist with vulnerability assessments, remediation efforts, and implementation of defensive security measures. * Support continuous monitoring initiatives and evaluate effectiveness of enterprise-wide information security controls. * Maintain awareness of emerging cyber threats, Intelligence Community security directives, and evolving adversarial TTPs. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Debunking the Top 10 Myths about Web 3](https://www.wearedevelopers.com/videos/634-debunking-the-top-10-myths-about-web-3) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)