Security Operations Center Analyst

Everwatch Corp.
Annapolis Junction, MD, United States
20 days ago
Apply on www.techcareers.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$119,995.0 - $139,984.0
Working hours
Regular working hours

Tech stack

Artificial Intelligence Cyber Security Linux Log Analysis Networking Basics Security Information and Event Management Snort (Software) Cybercrime Nessus Firewall Services Module Cyber Warfare Splunk

Job description

EverWatch employees are focused on tackling the most difficult challenges of the US Government. We offer the best salaries and benefits packages in our industry - to identify and retain the top talent in support of our critical mission objectives., Are you ready to take a strategic role in cyber defense for U.S Cyber Command? Do you want to use your experience-based knowledge to protect critical warfighter infrastructure from the constant onslaught of cyber threats? If you want a position that uses your extensive threat analysis skills to perform advanced threat identification and complex incident response, you want to be a SOC analyst. As an analyst on our SOC team, you’ll analyze logs, forensic data, and threat intelligence to find the advanced threats that are escaping detection. Using your deep understanding of your customer’s networks, combined with your cybersecurity experience, you’ll analyze patterns to understand attackers’ goals and stop them from succeeding. Once you find the adversary in the SEIM’s blind spot, you’ll advise on ways to close the gaps and harden their network. Let’s outsmart malicious actors and protect U.S. Cyber Command.

Requirements

You Have:

  • Experience with SIEM Fundamentals, including Splunk
  • Knowledge of basic networking fundamentals
  • Knowledge of the basic functions and configurations of Bro (Zeek)
  • Knowledge of Suricata or Snort
  • Ability to review Nessus scans and Firewall configurations
  • Ability to review Linux hosts for indicators of compromise and hardening of Linux systems
  • Ability to navigate *nix based systems via CLI
  • Ability to find, read, and analyze various logs
  • TS/SCI clearance with a polygraph
  • HS diploma or GED and 6+ years of experience with incident response procedures and analysis, or Bachelor’s degree and 2+ years of experience with incident response procedures and analysis

Nice If You Have:

  • Experience with correlating threat intelligence (INTEL) to determine the threat actor, the attack’s scope, and the affected systems
  • Experience with AI Fundamentals
  • Knowledge of Splunk Phantom or SOAR

Benefits & conditions

Compensation at EverWatch is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $57.69 to $67.30 per hour. The estimate displayed represents the typical compensation range for this position and is just one component of EverWatch’s total compensation package for employees.

About the company

EverWatch is a government solutions company providing advanced defense, intelligence, and deployed support to our country’s most critical missions. We are a full-service government solutions company. Harnessing the most advanced technology and solutions, we strengthen defenses and control environments to preserve continuity and ensure mission success.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.techcareers.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:23 min

Boosting security operations center productivity with intelligent data analysis

Chris Wysopal Chris Wysopal +2 ¡ World Congress 2024

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 ¡ LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard ¡ World Congress 2025

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler ¡ LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 ¡ LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani ¡ Europe 2026 Virtual

Videos

See all

Related articles

See all