> Markdown version of [/jobs/ext/2694329-soc-analyst](https://www.wearedevelopers.com/jobs/ext/2694329-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SOC Analyst - **Company:** Booz Allen Hamilton Inc. - **Location:** Fort Meade, MD, United States (Remote available) - **Experience:** Experienced - **Salary:** $69,400.0 - $158,000.0 - **Contract:** Internship / Graduate position - **Skills:** Multitier Architecture, Network Analysis, Cloud Computing Security, Cyber Security, Digital Forensics, Intrusion Detection and Prevention, Python (Programming Language), Performance Tuning, Kusto Query Language, Security Information and Event Management, Scripting, Mitre Att&ck, Malware, Cyber Threat Analysis, SC Clearance, Cybercrime, Process Control Systems, Microsoft Sentinel - **Published:** September 3, 2026 - **Apply:** https://careers.boozallen.com/jobs/JobDetail?jobId=129764 ## About the Role * 3+ years of experience with cybersecurity, including SOC operations, incident response, threat hunting, or detection engineering * Experience with Microsoft Sentinel and KQL * Experience with SIEM detection engineering, tuning, and security investigations * Knowledge of malware analysis, digital forensics, networking, and cloud security concepts * Knowledge of scripting languages such as Python * Knowledge of MITRE ATT&CK, NIST SP 800-53, and NIST SP 800-82 * Secret clearance * HS diploma or GED Nice If You Have: * Experience supporting critical infrastructure, operational technology, or industrial control system environments * Experience with Red Canary or similar MDR capabilities * Microsoft Certified: Security Operations Analyst Associate, GCIH, GSOC, GICSP, GRID, GCIA, CCNA, CISSP, or similar Certification ## Description Are you an experienced cybersecurity analyst who enjoys digging deeper than the alert? Do threat hunting, complex investigations, and finding the activity others miss interest you? Join a team of advanced cybersecurity analysts working to protect the systems that support one of the world's most critical hubs for global trade and supply chain operations. As a Tier III Security Operations Center Analyst, you'll apply deep technical expertise within a 24×7 SOC to identify and respond to sophisticated cyber threats. You'll conduct intelligence-driven threat hunting, investigate complex and high-priority cybersecurity events, and perform advanced technical analysis, including malware triage, digital forensics, network analysis, and investigation of anomalous activity. You'll use Microsoft Sentinel, KQL, threat intelligence, and security telemetry across endpoint, network, cloud, and operational technology environments to understand adversary activity and identify threats that may bypass automated detections. You'll also help continuously improve the SOC's detection and response capabilities by developing and tuning detection use cases, correlation rules, alerts, and queries, identifying false positives and detection gaps, and improving playbooks and investigative processes. As a senior technical member of the SOC, you'll serve as an escalation point and mentor to Tier I and Tier II analysts, collaborate with technical SMEs and client stakeholders during investigations, and translate complex technical findings into clear risks, impacts, and recommended actions. You'll also support structured shift handoffs to maintain situational awareness and operational continuity across the 24×7 SOC. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)