Local Defender SOC Analyst

Oasys Inc.
McAlester, OK, United States
15 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours

Tech stack

Data Analysis Software System Penetration Testing Cyber Security Linux Disaster Recovery Failover Monitoring of Systems OSI Models Network Security Network Administration Network Protocols Security Information and Event Management
+7 more
Network Routers Mitre Att&ck Firewalls (Computer Science) Juniper Process Control Systems Operational Systems Cisco

Job description

OASYS, INC., a Leading-Edge Government contractor, is seeking applicants for a Local Defender SOC Analyst position to support our Army customer at the McAlester Army Ammunition Plant (MCAAP), McAlester, Oklahoma.

Job Responsibilities include: Supports our Army customer to perform system monitoring and analysis support for the detection of cyber incidents and provides recommendations on how to correct findings. Perform tasks in a variety of areas to include:

Submits and tracks all service tickets submitted internally and externally for Operational Technology (OT) systems.

Monitors/logs SOC Request/CNOC actions and response.

Assists in OT investigations of significant incidents and reporting.

Submits and tracks all service tickets submitted on behalf of customer internally and to external organizations.

Provides timely acknowledgement of SOC service requests, problem identification, root cause analysis, escalation, resolution, and closure for all SOC service requests in accordance with SLAs and OLAs.

Escalates OT cyber incidents that require further in-depth analysis.

Categorizes and prioritizes OT cyber events and other SOC service requests.

Documents and tracks incidents in accordance with the reporting procedure and archives historical OT SOC data.

Provides situational awareness on OT cybersecurity-related issues impacting enterprise policies and procedures.

Provides monitoring and analysis of OT SIEM events to identify potential security risks and vulnerabilities.

Triages events and investigates to identify OT security incidents.

Manages OT security incidents throughout their lifecycle to closure.

Coordinates with other, remote technical teams to investigate, document, and resolve issues.

Makes recommendations for ongoing tuning and updates to the SIEM system.

Receives input from threat intelligence sources and analyzes events to identify threats and risks.

Supports ad-hoc data and investigation requests.

Conducts security and vulnerability scans as directed using established processes.

Requirements

Bachelors Degree or higher, additional years of experience may be substituted for degree

Minimum of 10 years of work-related experience.

A high-level performer with the ability to be proactive and respond rapidly to changing conditions in a fast-paced environment

DoD 8570/8140 IAT Level II certification.

Ability to work on-site daily.

Familiarity with backup operations and processes for data protection, disaster recovery, and failover procedures (COOP/DR).

Familiarity with MITRE Att&ck Framework.

Strong understanding of OSI model, network security concepts, security classification guides, and CJCSM 6510.01B concepts and activities.

Familiarity with backup operations and processes for data protection, disaster recovery, and failover procedures (COOP/DR).

Preferred Requirements:

Experience with DoD.

Tenable.SC Specialist Certification, Tenable.OT Specialist Certification, Dragos Platform Certified User (DPCU), Dragos ICS-OT Cybersecurity Training, or ICS/OT penetration testing experience.

System administration experience and IT certifications in Linux or Microsoft.

Experience with networking protocols, design (switches, routers, firewalls, etc.) and terminology, and network administration (Cisco, Juniper, Ubiquiti etc.).

Understanding of the Purdue model, industrial control systems, and operational technology.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

3:09 min

Balancing data science skillings alongside systems engineering rigor

Nico Schmidt · LIVE

3:45 min

Prototyping deterministic agents with n8n and PyATS

Alfonso Sandoval Rosas Alfonso Sandoval Rosas · Europe 2026 Virtual

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all