SOC Analyst (Night Shift)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+13 more
Job description
Join a long-term cybersecurity program supporting a critical Department of Defense mission in a fast-paced 24/7 Security Operations Center (SOC) environment. This role focuses on Cyber Network Defense (CND), threat detection, incident analysis, vulnerability management, and continuous monitoring across enterprise networks. Analysts will leverage industry-leading platforms including Splunk, Trellix, and ACAS to identify, investigate, and respond to cyber threats while helping maintain the security and integrity of mission-critical systems. This opportunity offers long-term stability on a five-year contract supporting a high-visibility federal customer., * Monitor and analyze security events from SIEM, EDR, IDS/IPS, and vulnerability management platforms.
- Perform real-time cyber threat detection, triage, investigation, and escalation activities within a 24/7 SOC.
- Conduct Cyber Network Defense (CND) operations to identify malicious activity, anomalous behavior, and indicators of compromise.
- Investigate network traffic using packet capture (PCAP) data to identify intrusion attempts, malware activity, and unauthorized communications.
- Analyze alerts and logs generated from Splunk, Trellix, ACAS, and other cybersecurity tools.
- Utilize IDS/IPS technologies to identify threats, validate alerts, and support incident response efforts.
- Perform threat hunting activities using log analysis, endpoint telemetry, network traffic analysis, and threat intelligence.
- Conduct vulnerability assessments and track remediation activities using ACAS and related vulnerability management tools.
- Correlate events from multiple data sources to determine root cause, scope, and impact of security incidents.
- Develop and maintain incident documentation, shift reports, and operational metrics.
- Coordinate with engineering, network, and system administration teams to support containment and remediation efforts.
- Support continuous monitoring initiatives and compliance with DoD cybersecurity requirements.
- Participate in daily shift handoffs to ensure seamless 24/7 operational coverage.
Requirements
- Experience supporting a Security Operations Center (SOC), Cyber Defense Team, or Incident Response function.
- Hands-on experience with Splunk for log analysis, correlation, alert investigation, and reporting.
- Experience with Trellix security products and endpoint security monitoring.
- Experience utilizing ACAS for vulnerability scanning, analysis, and remediation tracking.
- Strong understanding of Cyber Network Defense (CND) principles and security monitoring methodologies.
- Experience performing packet analysis using PCAP data.
- Knowledge of IDS/IPS technologies and network-based threat detection.
- Understanding of TCP/IP, network protocols, and common attack methodologies.
- Experience analyzing security alerts, events, and indicators of compromise.
- Strong troubleshooting, documentation, and communication skills.
- Ability to work rotating shifts in a 24x7 operational environment., * Experience supporting DoD or Federal cybersecurity programs.
- Familiarity with MITRE ATT&CK, Cyber Kill Chain, and threat hunting methodologies.
- Experience with incident response, malware analysis, or digital forensics.
- Knowledge of STIGs, vulnerability management processes, and security compliance frameworks.
- Experience with threat intelligence integration and IOC analysis.
- Understanding of Windows, Linux, and enterprise networking environments.
Certifications (One or More Preferred)
- Security+
- CySA+
- CASP+
- GCIH
- GCIA
- CEH
- CISSP
Benefits & conditions
- High-visibility cybersecurity operations environment
- Opportunity to work with leading security technologies including Splunk, Trellix, and ACAS
- Multiple shift options available
- Exposure to advanced cyber threat detection, network defense, and incident response operations
- Strong career growth potential within enterprise cybersecurity and SOC operations
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Data Analyst Salary in the UK
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Walking Into The Era of Supply Chain Risks