> Markdown version of [/jobs/ext/570911-tier-i-soc-analyst](https://www.wearedevelopers.com/jobs/ext/570911-tier-i-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Tier I SOC Analyst - **Company:** CGI Technologies and Solutions, Inc. - **Location:** Knoxville, TN, United States - **Experience:** Experienced - **Salary:** $56,600.0 - $139,300.0 - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Microsoft Windows, Cloud Computing Security, Cyber Security, Linux, Issue Tracking Systems, Intrusion Detection and Prevention, Python (Programming Language), Networking Basics, Security Information and Event Management, Working Model 2D, Data Logging, Cyber Threat Analysis, Information Technology, Cybercrime, Programming Languages - **Published:** June 12, 2026 - **Apply:** https://www.juju.com/job/00000000g7ffkr ## About the Role Exposure to cybersecurity, information security, or information technology. Understanding of network fundamentals, Windows/Linux systems and security tools Excellent verbal and written communication skills. Ability to remain calm and effective in a fast-paced, team-oriented environment. Demonstrated analytical and problem-solving skills. US Citizenship, with eligibility to obtain a public trust clearance. BA/BS or equivalent IT industry experience (2+ years) Desired qualifications: Experience or exposure to SOC monitoring, incident response or threat analysis. Exposure or experience with one or more programming languages, such as python, JavaScript Security certifications such as Security+, CySA+, SC-200 Due to the nature of this government contract, US Citizenship and the ability to obtain a Public Trust clearance is required., + Operational Security + Security Analysis + Cyber + Security Architecture + Threat Risk Assessment ## Description CGI Federal is expanding its Security Operations Center (SOC) capabilities in Knoxville, TN. As cyber threats become more advanced, our analysts play a critical role in protecting federal systems and sensitive information. This role is ideal for someone early in their cybersecurity journey who is looking to build hands-on skills and progress into more specialized areas whether in threat intelligence, automation, incident response or cloud security. You will gain broad exposure to tools, technologies and real-world incidents, with support from experienced analysts and clear pathways to grow your career in cyber. This position is located in our Knoxville, TN office; however, a hybrid working model is acceptable. This role requires shift work, operating on 12-hour shifts on the Panama 2-2-3 Rotation: Teams work 2 days, off 2 days, work 3 days, off 2 days, work 2 days, off 3 days. Your future duties and responsibilities: Monitor and triage security events using playbooks, SIEM tools, and case management systems. Respond to alerts, identify false positives, and escalate incidents for deeper analysis and resolution. Collaborate with senior analysts and subject matter experts to resolve incidents and enhance detection capabilities. Incident Documentation: Logging detailed findings of investigations in a ticketing system for tracking and reporting. Escalation: Escalating valid, complex, or high-severity security incidents to Tier 2 analysts. Gathering context on alerts (e.g., threat intelligence, user information, endpoint data) to aid in analysis. Security Tool Operation: Navigating tools like EDR (Endpoint Detection and Response), SIEM (Security Information and Event Management), and firewalls ## Related Videos - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)