SOC Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
ASRC Federal is seeking a SOC Analyst to support the Department of Defense Education Activity (DoWEA) Enterprise Cyber Program. This role supports enterprise cybersecurity operations, including Risk Management Framework (RMF) compliance, vulnerability management, security monitoring, and incident response, in collaboration with other cybersecurity personnel.
This is a remote position requiring scheduled night and weekend shifts in support of SOC operations., * Monitor and analyze network traffic, system logs, and other security data for signs of malicious activity.
- Use Security Information and Event Management (SIEM) tools to investigate security alerts and notable events.
- Manage incidents throughout their lifecycle, including analysis, triage, containment, and remediation.
- Recommend improvements to prevent future incidents and expedite response based on lessons learned.
- Communicate effectively and promptly with technical and nontechnical stakeholders.
- Prepare situational awareness reports for the customer and management.
- Develop and maintain manual and automated incident response playbooks.
- Support the development of SIEM detection and data ingestion strategies to improve SOC visibility.
- Conduct host and log forensic analysis and malware analysis as needed.
- Perform threat hunting based on emerging adversary tactics, techniques, and procedures.
- Develop and implement security procedures to prevent future incidents.
- Provide technical support to other members of the security team.
- Stay current on cybersecurity threats and trends.
Requirements
- Minimum of five years of relevant cybersecurity experience, including SOC operations, security monitoring, and incident response.
- Must hold and maintain required cybersecurity certifications, including one certification from each of the following groups:
- CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, or CCSP.
- CEH, CFR, CCNA Cyber Ops, CCNA-Security, CySA+, GCIA, GCIH, GICSP, Cloud+, SCYBER, or PenTest+.
- Experience with SIEM tools, such as Microsoft Sentinel.
- Experience leading and managing SOC operations.
- Expertise in analyzing network packets, SIEM alerts, and server and application logs to investigate anomalous or malicious activity.
- Experience tracking incidents using frameworks such as MITRE ATT&CK or the Cyber Kill Chain.
- Ability to analyze advanced persistent threats and map the threat lifecycle.
- Ability to work scheduled night and weekend shifts remotely.
- Active Secret security clearance.
Desired Skills:
- Experience with Microsoft Sentinel.
- Forensic investigation and malware analysis experience.
- Strong curiosity and problem-solving skills.
- Proactive approach and a strong sense of ownership.
Benefits & conditions
We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefits packages. Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law. The salary offered will depend on several factors including, but not limited to, relevant experience, skills, education, geographic location, internal equity, business needs, and other factors permitted by law. Posted pay ranges are a general guideline only and are not a guarantee of compensation or salary.
About the company
Alexandria
Virginia
29779
ASRC Federal, ASRC Federal is a leading government contractor furthering missions in space, public health and defense. As an Alaska Native owned corporation, our work helps secure an enduring future for our shareholders. Join our team and discover why we are a top veteran employer and Certified Great Place to Work
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Loading talks and stories from around this roleβ¦