> Markdown version of [/jobs/ext/33925-security-operations-center-soc-analyst-journeyman](https://www.wearedevelopers.com/jobs/ext/33925-security-operations-center-soc-analyst-journeyman). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SECURITY OPERATIONS CENTER (SOC) ANALYST, JOURNEYMAN - **Company:** Peraton Inc - **Location:** Herndon, VA, United States - **Experience:** Experienced - **Salary:** $80,000.0 - $128,000.0 - **Contract:** Permanent contract - **Skills:** Challenge-Handshake Authentication Protocol, Cyber Security, Information Systems, Query Languages, Windows Communication Foundation, Intrusion Detection and Prevention, Intrusion Detection Systems, Log Analysis, Comptia Pentest+ CE, Security Information and Event Management, Software Engineering, Cyber Threat Analysis, Information Technology, Cyber Warfare - **Published:** May 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=f9f853ec963ca655 ## About the Role * 5 years with BS/BA; 3 years with MS/MA; 0 years with PhD * Clearance: Active TS/SCI clearance. * Candidate must meet ONE of the following: + Bachelor's degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering; OR + Relevant DoD/military training (examples: 4C-255S (CP); M03385G; M10395B; M223854; A-531-0451; A-531-4421; A-531-1900; Cyber Defense Analyst (Intermediate) Playlist; DISA (511) Training); OR + Relevant professional certification or equivalent experience (examples: CEH(P); GMON; GRID; Cloud+; FITSP-O; GCED; GDSA; GSEC; PenTest+; Security+). * Required experience and skills: + SOC, incident response, or detection engineering experience with demonstrated Tier-2 analysis responsibilities. + Proficiency with SIEM query languages and alert investigation workflows, EDR triage, IDS/IPS signature logic, and log forensics. + Experience authoring and tuning detection rules/signatures, validating IOCs, and documenting reproducible investigation artifacts. + Strong analytical writing for incident summaries, technical briefs, and escalation packages; ability to coordinate cross-team remediation actions. * Desired: + Prior DoD/ARNG SOC or detection engineering experience and familiarity with CDAP/CHAP operational contexts. + Experience with threat-hunting techniques, detection metrics (precision/recall), SOAR integrations, and mentoring junior analysts. ## Description We are seeking a highly skilled and innovative Security Operations Center (SOC) Analyst, Journeyman to join our team in the greater DMV area, supporting the Army National Guard. Responsibilities * Perform advanced analysis of security events escalated from Tier 1: correlate SIEM logs, IDS/IPS alerts, EDR/endpoint telemetry, network flows, and threat-intelligence feeds to identify true incidents. * Investigate suspected compromises, conduct risk assessments for access requests, and develop initial countermeasure recommendations in coordination with SOC, CIRT, and RCC-ARNG. * Author, tune, and refine detection content (SIEM rules, IDS/IPS signatures, filters) to improve fidelity and reduce alert noise. * Execute deeper forensic/log analysis, reconstruct timelines, and validate detections to support escalation and remediation workflows. * Document investigation steps, produce incident summaries and technical inputs for SOC reports, and maintain case evidence and tickets. * Coordinate with engineering and sensor owners on tuning, deployment of detection logic, WCF/FPA policy adjustments, and monitoring enhancements. * Contribute to SOC playbook updates, detection engineering backlog, and continuous improvement initiatives to enhance detection and response capabilities. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Leveraging Large Language Models for Legacy Code Translation: Challenges and Solutions](https://www.wearedevelopers.com/videos/1157-leveraging-large-language-models-for-legacy-code-translation-challenges-and-solutions) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)