> Markdown version of [/jobs/ext/244777-security-operations-center-soc-analyst-senior](https://www.wearedevelopers.com/jobs/ext/244777-security-operations-center-soc-analyst-senior). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SECURITY OPERATIONS CENTER (SOC) ANALYST, SENIOR - **Company:** Peraton Inc - **Location:** Herndon, VA, United States - **Experience:** Expert - **Salary:** $104,000.0 - $166,000.0 - **Contract:** Permanent contract - **Skills:** Challenge-Handshake Authentication Protocol, Cyber Security, Information Systems, Query Languages, Monitoring of Systems, Issue Tracking Systems, Intrusion Detection and Prevention, Network Security, Log Analysis, Comptia Pentest+ CE, Security Information and Event Management, Software Engineering, Computer Network Operations, Information Technology, Cyber Warfare - **Published:** May 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=28bb33f6cf83196b ## About the Role * Minimum of 8 years with BS/BA; Minimum of 6 years with MS/MA; Minimum of 3 years with PhD * Clearance: Active TS/SCI clearance. * Candidate must meet ONE of the following: + Bachelor's degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, Software Engineering, or a related field; OR + Relevant DoD/military training (examples: 4C-255S (CP); M03385G; M10395B; M223854; A-531-0451; A-531-4421; A-531-1900; Cyber Defense Analyst (Intermediate) Playlist; DISA (511) Training); OR + Relevant professional certification or equivalent experience (examples: CEH(P); GMON; GRID; Cloud+; FITSP-O; GCED; GDSA; GSEC; PenTest+; Security+). * Required experience and skills: + SOC, incident detection, or cybersecurity operations experience with substantial Tier-1/Tier-2 monitoring and triage responsibilities. + Hands-on experience with SIEM query languages and workflows, EDR investigation, log forensics, and cross-platform correlation. + Familiarity executing containment actions, documenting chain-of-custody/evidence, and following incident playbooks. + Strong analytical writing for case documentation, escalation summaries, and shift reporting; ability to synthesize technical detail for responders and leadership. + Ability to identify tuning opportunities, manage false positives, and work collaboratively across SOC/CIRT/NOC teams. * Desired: + Prior DoD/ARNG SOC or operations center experience and familiarity with CDAP/CHAP/enterprise monitoring contexts. + Experience mentoring analysts, contributing to SOC tuning programs, and supporting SOC metric/dashboard development. #ENOCS ## Description We are seeking a highly skilled and innovative Security Operations Center (SOC) Analyst Senior to join our team in the greater DMV area, supporting the Army National Guard. Responsibilities * Perform advanced Tier-1 monitoring, triage, and initial alert analysis across SIEM, EDR, network security tools, cloud telemetry, and enterprise monitoring platforms. * Review high-volume alerts, correlate events across multiple data sources, and identify patterns indicative of targeted or multi-stage activity. * Execute Tier-1 containment actions per playbooks (host isolation, account disablement, block rules) and validate immediate mitigations. * Enrich alerts with contextual data, validate IOCs, document detailed case notes, and prepare high-quality escalations for Tier-2/Tier-3 and CIRT teams. * Conduct deeper log analysis, cross-platform correlation, and preliminary threat-hunt queries to surface anomalies requiring escalation. * Coordinate with Tier-2 analysts, CIRT, and network operations to support incident response, provide contextual summaries, and recommend next steps. * Monitor SIEM/tool performance, identify visibility gaps or misconfigurations, and recommend tuning to improve SOC coverage. * Maintain and update Tier-1 checklists, triage procedures, and playbooks; contribute tuning by identifying false-positive patterns and rule adjustments. * Mentor and guide junior analysts on triage best practices, tool usage, and case handling; produce shift summaries, daily operational reports, and incident tracking updates. * Contribute to continuous improvement by refining workflows, adopting new SOC techniques, and enhancing frontline defensive effectiveness. ## Related Videos - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Leveraging Large Language Models for Legacy Code Translation: Challenges and Solutions](https://www.wearedevelopers.com/videos/1157-leveraging-large-language-models-for-legacy-code-translation-challenges-and-solutions) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf)