> Markdown version of [/jobs/ext/2595472-csoc-analyst-t1-nc](https://www.wearedevelopers.com/jobs/ext/2595472-csoc-analyst-t1-nc). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # CSOC Analyst T1 - NC - **Company:** NIGHTWING LLC - **Location:** Morrisville, NC, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Boolean Algebra, Cyber Security, Computer Networks, Computer Engineering, Electronic Mailing, Intrusion Detection Systems, Information Systems Security Engineering Professional, Log Analysis, Network Forensics, Regular Expressions, TCP/IP, EndPointSecurity, Cloud Monitoring, Information Technology, Splunk - **Published:** August 11, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9090201/csoc-analyst-t1-nc ## About the Role This position is CONTINGENT upon funding, an open position, customer approval, completion of a favorable background investigation, and the ability to obtain and maintain our customer's sensitive clearance., * Must be eligible to obtain a sensitive clearance - Position of Public Trust - and may be required to obtain a higher security clearance * Must have 2+ years of relevant work experience * Must have experience in: + Endpoint Detection and analysis + Sysmon log analysis + IT security + Network traffic analysis * Strong working knowledge of: + Boolean Logic + TCP/IP Fundamentals + Network Level Exploits + Threat Management + Regular Expressions * Knowledge of Control Frameworks and Risk Management techniques * Excellent oral and written communication skills * Excellent interpersonal and organizational skills * Strong understanding of IDS/IPS technologies, trends, vendors, processes and methodologies * Strong understanding of common IDS/IPS architectures and implementations * Strong understanding of IDS/IPS signatures, content creation and signature characteristics including both signature and anomaly-based analysis and detection Desired Skills * Splunk experience, developing queries, data models, and dashboards * Cloud monitoring experience is a plus * Excellent writing skills Required Education Bachelor of Science Degree with a major in Computer Science/Computer Engineering, Engineering, Science or a related field. Two years of related work experience may be substituted for each year of degree-level education. Certifications (one or more desired) DOD 8570.1-M Compliance at IAT Level II; CISSP, Certified Ethical Hacker (C|EH), Sec+, SFCP, GCIA, ISSEP, ISSMP, GCIH, GCFA, CSLC, CISM, or CCNA The ability to obtain and maintain a U.S. government issued security clearance is required. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance. ## Description * Identification of Cybersecurity problems which may require mitigating controls * Analyze network traffic to identify exploit or intrusion related attempts * Recommend detection mechanisms for exploit and or intrusion related attempts * Provide subject matter expertise on network based attacks, network traffic analysis, and intrusion methodologies * Escalate items which require further investigation to other members of the Threat Management team * Execute operational processes in support of response efforts to identified security incidents * Participates in a team of Security operations engineers investigating alerts, anomalies, errors, intrusions, malware, etc. to identify the responsible, determine remediation, and recommend security improvements * Follows precise analytical paths to determine the nature and extent of problems being reported by tools, e-mails, etc * Follows strict guidance on reporting requirements * Keeps management informed with precise, unvarnished information about security posture and events * Promotes standards-based workflow both internally and in coordinating with US-CERT * Engages with other internal and external parties to get and share information to improve processes and security posture * Supervises and guide team efforts * Communicates to CISO leadership * Produces design documentation * Leads analyzing/investigating reports or anomalies ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf)