SOC Analyst (Night Shift)

Kforce Inc.
Arlington, VA, United States
3 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$122,720.0 - $168,480.0
Working hours
Shift work

Tech stack

Microsoft Windows Cyber Security Computer Networks Linux Digital Forensics Intrusion Detection and Prevention Intrusion Detection Systems Network Security Pcap Log Analysis Network Forensics Packet Analyzer
+13 more
Network Protocols Security Software Security Information and Event Management TCP/IP Software Vulnerability Management Mitre Att&ck Software Troubleshooting Malware Cyber Threat Analysis Cybercrime Cyber Warfare Splunk Vulnerability Analysis

Job description

Join a long-term cybersecurity program supporting a critical Department of Defense mission in a fast-paced 24/7 Security Operations Center (SOC) environment. This role focuses on Cyber Network Defense (CND), threat detection, incident analysis, vulnerability management, and continuous monitoring across enterprise networks. Analysts will leverage industry-leading platforms including Splunk, Trellix, and ACAS to identify, investigate, and respond to cyber threats while helping maintain the security and integrity of mission-critical systems. This opportunity offers long-term stability on a five-year contract supporting a high-visibility federal customer., * Monitor and analyze security events from SIEM, EDR, IDS/IPS, and vulnerability management platforms.

  • Perform real-time cyber threat detection, triage, investigation, and escalation activities within a 24/7 SOC.
  • Conduct Cyber Network Defense (CND) operations to identify malicious activity, anomalous behavior, and indicators of compromise.
  • Investigate network traffic using packet capture (PCAP) data to identify intrusion attempts, malware activity, and unauthorized communications.
  • Analyze alerts and logs generated from Splunk, Trellix, ACAS, and other cybersecurity tools.
  • Utilize IDS/IPS technologies to identify threats, validate alerts, and support incident response efforts.
  • Perform threat hunting activities using log analysis, endpoint telemetry, network traffic analysis, and threat intelligence.
  • Conduct vulnerability assessments and track remediation activities using ACAS and related vulnerability management tools.
  • Correlate events from multiple data sources to determine root cause, scope, and impact of security incidents.
  • Develop and maintain incident documentation, shift reports, and operational metrics.
  • Coordinate with engineering, network, and system administration teams to support containment and remediation efforts.
  • Support continuous monitoring initiatives and compliance with DoD cybersecurity requirements.
  • Participate in daily shift handoffs to ensure seamless 24/7 operational coverage.

Requirements

  • Experience supporting a Security Operations Center (SOC), Cyber Defense Team, or Incident Response function.
  • Hands-on experience with Splunk for log analysis, correlation, alert investigation, and reporting.
  • Experience with Trellix security products and endpoint security monitoring.
  • Experience utilizing ACAS for vulnerability scanning, analysis, and remediation tracking.
  • Strong understanding of Cyber Network Defense (CND) principles and security monitoring methodologies.
  • Experience performing packet analysis using PCAP data.
  • Knowledge of IDS/IPS technologies and network-based threat detection.
  • Understanding of TCP/IP, network protocols, and common attack methodologies.
  • Experience analyzing security alerts, events, and indicators of compromise.
  • Strong troubleshooting, documentation, and communication skills.
  • Ability to work rotating shifts in a 24x7 operational environment., * Experience supporting DoD or Federal cybersecurity programs.
  • Familiarity with MITRE ATT&CK, Cyber Kill Chain, and threat hunting methodologies.
  • Experience with incident response, malware analysis, or digital forensics.
  • Knowledge of STIGs, vulnerability management processes, and security compliance frameworks.
  • Experience with threat intelligence integration and IOC analysis.
  • Understanding of Windows, Linux, and enterprise networking environments.

Certifications (One or More Preferred)

  • Security+
  • CySA+
  • CASP+
  • GCIH
  • GCIA
  • CEH
  • CISSP

Benefits & conditions

  • High-visibility cybersecurity operations environment
  • Opportunity to work with leading security technologies including Splunk, Trellix, and ACAS
  • Multiple shift options available
  • Exposure to advanced cyber threat detection, network defense, and incident response operations
  • Strong career growth potential within enterprise cybersecurity and SOC operations

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:23 min

Boosting security operations center productivity with intelligent data analysis

Chris Wysopal Chris Wysopal +2 · World Congress 2024

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all