> Markdown version of [/jobs/ext/266014-soc-incident-response-analyst-i-6am-2pm](https://www.wearedevelopers.com/jobs/ext/266014-soc-incident-response-analyst-i-6am-2pm). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SOC Incident Response Analyst I (6am-2pm) - **Company:** General Dynamics Information Technology - **Location:** Lanham, MD, United States - **Experience:** Starter - **Salary:** $72,250.0 - $97,750.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Bash Shell, Cloud Computing Security, CompTIA Security+, Cyber Security, Digital Forensics, Domain Name System (DNS), Hypertext Transfer Protocols (HTTP), Intrusion Detection Systems, Virtual Private Networks (VPN), Python (Programming Language), Networking Basics, Windows PowerShell, ArcSight SIEM Tool, Security Information and Event Management, TCP/IP, Scripting, Mitre Att&ck, QRadar, Cyber Threat Analysis, Firewalls (Computer Science), Information Technology, Cybercrime, Splunk, SentinelOne Expertise, Security Orchestration, Automation & Response - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=46f29832a216dcfe ## About the Role Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related field Minimum 1 year of professional experience in cyber incident response Foundational knowledge of cyber security concepts, such as incident handling lifecycle, threat intelligence, and basic forensics. Familiarity with security tools (SIEM, EDR, SOAR, threat intel feeds) and basic incident response workflows. Hands-on experience with SIEM (e.g., Splunk, QRadar, ArcSight), EDR (e.g., CrowdStrike, Defender, SentinelOne), and basic SOAR concepts. Experience with incident response tooling, digital forensics, and evidence handling. Understanding of networking fundamentals (TCP/IP, DNS, HTTP/S, VPNs, firewalls). Strong analytical and problem-solving skills with a structured, methodical approach. Excellent written and verbal communication; ability to produce clear incident reports and documentation. Ability to work in a fast-paced environment and participate in on-call rotations (as needed). Commitment to continuous learning and professional growth in cybersecurity. Preferred Qualifications Relevant certifications (e.g., CompTIA Security+, CEH, SANS GCIH, GIAC GCIA, or equivalent). Knowledge of MITRE ATT&CK framework and common attacker techniques. Familiarity with cloud security concepts (AWS/Azure/GCP) and cloud incident response considerations. Scripting or automation skills (PowerShell, Python, Bash) a plus., Years of Experience 1 + years of related experience * may vary based on technical training, certification(s), or degree ## Description We are seeking a motivated Incident Response SOC Analyst I to join our SOC team. In this entry-to-mid-level role, you will work under the guidance of senior analysts to monitor security telemetry, triage alerts, perform initial investigations, and assist with containment and remediation activities. This is an excellent opportunity to grow your skills in incident response, threat hunting, forensics, and security tooling., Monitor and triage security alerts from SIEM, EDR, IDS/IPS, and other security telemetry sources. Conduct initial incident validation, categorize incidents, and determine severity levels. Perform basic to intermediate incident response activities, including containment, eradication, and recovery steps under supervision. Gather and preserve digital evidence following standard operating procedures and chain-of-custody requirements. Collaborate with IT and security teams to apply mitigations, patches, and configuration changes. Document investigation steps, findings, and remediation actions in incident tickets. Participate in post-incident reviews (PIR) and help develop lessons learned. Respond to on-call rotations as required. Expand knowledge of MITRE ATT&CK, common attack techniques, and security best practices. Assist with monitoring and improving SOC processes, playbooks, and runbooks. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Debunking the Top 10 Myths about Web 3](https://www.wearedevelopers.com/videos/634-debunking-the-top-10-myths-about-web-3) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)