> Markdown version of [/jobs/ext/254150-security-operations-center-analyst](https://www.wearedevelopers.com/jobs/ext/254150-security-operations-center-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Operations Center Analyst - **Company:** Everforth Ecs - **Location:** Fairfax, VA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, CompTIA Security+, Cyber Security, Identity and Access Management, NIPRNet, Microsoft SharePoint, Security Information and Event Management, Software Vulnerability Management, Mitre Att&ck, Cyber Threat Analysis, Cybercrime, Cyber Warfare, Splunk, Servicenow - **Published:** May 31, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=8f55840580b5ec75 ## About the Role Do you have experience in Stakeholder management?, * Current Secret security clearance with the ability to obtain and maintain a Top Secret (TS) security clearance. * A minimum of 3 years of experience in security operations, cyber threat analysis, or incident response within a federal, defense, or intelligence community environment, with demonstrated hands-on proficiency performing continuous monitoring and structured incident investigations using enterprise SIEM platforms such as Splunk or Elastic across multi-enclave network environments. * Active IAM Level I certification, satisfied by one of the following: CompTIA Security+ CE, ISC² CAP, ISC² SSCP, or GIAC GSLC. * Strong problem-solving and decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution. * Highly developed interpersonal and oral/written communication skills, with the ability to effectively and professionally interact with a diverse set of stakeholders (from peers to end-users to executive management). ## Description The Security Operations Center Analyst supports WDP's 24/7 continuous monitoring mission by performing structured threat detection, incident investigation, and response operations across NIPRNet, SIPRNet, and JWICS. This role operates within an integrated SOC environment leveraging Splunk SIEM, SOAR-driven automation, and AI-assisted triage capabilities to identify adversary behavior, contain incidents, and sustain cyber defense resilience across WDP's classified and unclassified mission enclaves. * Executes continuous security monitoring operations across classified and unclassified DoW networks, supporting mission systems operating on NIPRNet, SIPRNet, and JWICS. * Analyzes security events generated by enterprise Security Information and Event Management platforms including Splunk and Elastic, correlating host, network, and application telemetry to identify anomalous activity and potential adversary behavior. * Conducts structured incident investigations using established incident response playbooks aligned to DoW Cyber Incident Handling Program guidance, documenting findings within ServiceNow and SharePoint tracking repositories. * Performs proactive threat hunting activities leveraging MITRE ATT&CK mappings, endpoint telemetry, network flow data, and log analytics to detect previously unidentified threats. * Coordinates containment and remediation actions with system administrators, ISSOs, and vulnerability management teams, supporting rapid mitigation of malware, unauthorized access, and policy violations. * Maintains detailed incident records, forensic timelines, and evidentiary artifacts supporting after-action reporting and continuous monitoring requirements under the Risk Management Framework. * Tunes detection logic, refines correlation rules, and contributes to improvement of SOC use cases to reduce false positives and increase detection fidelity. * Provides technical mentorship to junior analysts through peer review of investigations and collaborative shift handovers. * Delivers operational reporting products including incident summaries, alert trend analysis, and threat activity assessments supporting operational readiness, cyber defense resilience, and mission assurance across combat support and intelligence environments. * Performs other duties as assigned. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)