Cybersecurity Analyst, Security Operations Center (SOC) Analyst
Role details
Job location
Tech stack
Job description
Digital Global Connectors (DGC) is seeking a motivated Cybersecurity Analyst - Tier 1 (Security Operations Center Analyst) to support a Federal information security program. The Tier 1 SOC Analyst serves as the first line of defense in monitoring, detecting, analyzing, documenting, and escalating cybersecurity events affecting enterprise information systems and networks., This position is responsible for continuous monitoring of security tools, initial incident triage, alert validation, event correlation, ticket management, and coordination with higher-tier cybersecurity personnel. The analyst helps identify potential threats, supports incident response activities, and contributes to maintaining a strong enterprise cybersecurity posture through proactive monitoring and timely reporting., Security Monitoring
- Monitor enterprise security monitoring platforms for cybersecurity events and alerts.
- Identify, review, and validate potential security incidents.
- Analyze security events to determine severity, priority, and potential business impact.
- Continuously monitor enterprise networks, systems, endpoints, cloud environments, and applications.
- Escalate suspicious activity requiring advanced investigation.
- Maintain situational awareness of the organization's security posture.
Event Analysis and Triage
- Perform initial analysis of security alerts generated by SIEM, EDR, IDS/IPS, and other security technologies.
- Correlate alerts from multiple security platforms.
- Distinguish false positives from legitimate security events.
- Categorize and prioritize security events based on established procedures.
- Document findings and recommended actions.
- Initiate incident response procedures when appropriate.
Incident Response Support
- Support Tier 2 Incident Responders during security investigations.
- Collect preliminary evidence supporting incident analysis.
- Preserve relevant logs and security artifacts.
- Assist with containment activities under senior analyst guidance.
- Update incident records throughout the investigation lifecycle.
- Participate in post-incident documentation and lessons learned.
Security Tool Operations
Operate and monitor technologies including:
- Microsoft Sentinel
- Splunk Enterprise Security
- Microsoft Defender XDR
- Microsoft Defender for Endpoint
- Microsoft Defender for Identity
- Microsoft Defender for Cloud
- CrowdStrike Falcon
- Palo Alto Cortex XDR
- Trellix
- Cisco Secure
- Security Information and Event Management (SIEM)
- Endpoint Detection and Response (EDR)
- Extended Detection and Response (XDR)
- Intrusion Detection and Prevention Systems (IDS/IPS)
Assist in identifying operational issues affecting monitoring platforms and coordinate with engineering teams as needed.
Threat Detection
- Monitor indicators of compromise (IOCs) and indicators of attack (IOAs).
- Identify suspicious user activity, anomalous network behavior, and unauthorized access attempts.
- Recognize malware infections, phishing attempts, credential misuse, and policy violations.
- Review threat intelligence provided by internal and external sources.
- Support implementation of updated detection rules and monitoring use cases.
Ticket and Case Management
- Create, update, and maintain incident tickets.
- Document investigation activities, findings, and recommendations.
- Track incidents through resolution.
- Ensure complete and accurate case documentation.
- Escalate unresolved issues according to established procedures.
- Maintain audit-ready documentation supporting security operations.
Reporting and Documentation
Develop and maintain:
- Incident Reports
- Alert Summaries
- Daily Operations Reports
- Shift Handover Reports
- Security Event Logs
- Investigation Notes
- Trend Reports
- Metrics Dashboards
- Lessons Learned Documentation
- Standard Operating Procedures
Ensure documentation is complete, accurate, and supports operational continuity.
Collaboration
- Coordinate with Tier 2 Incident Responders, Threat Hunters, Security Engineers, ISSOs, Vulnerability Management personnel, and technical support teams.
- Participate in operational briefings and shift turnover meetings.
- Communicate security findings clearly to technical and non-technical stakeholders.
- Support cross-functional cybersecurity initiatives.
- Maintain effective working relationships across cybersecurity disciplines.
Continuous Improvement
- Stay current with emerging cyber threats, attack techniques, and defensive technologies.
- Recommend improvements to monitoring procedures and operational workflows.
- Participate in tabletop exercises, incident response drills, and training events.
- Assist in refining detection logic and operational playbooks.
- Pursue professional development and relevant cybersecurity certifications.
Requirements
The successful candidate will possess strong analytical skills, experience working within a Security Operations Center (SOC), and a solid understanding of cybersecurity principles, network operations, and security monitoring technologies., * Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related discipline.
- Minimum two (2) years of experience supporting cybersecurity operations or a Security Operations Center (SOC).
- Experience monitoring SIEM, EDR, or related cybersecurity technologies.
- Understanding of networking concepts, operating systems, common attack techniques, and cybersecurity fundamentals.
- Experience documenting security events and supporting incident investigations.
- Strong analytical, organizational, and communication skills.
- Ability to work rotating shifts, evenings, weekends, holidays, or on-call schedules as required.
- U.S. Citizenship required.
- Ability to obtain and maintain a Tier 2 Public Trust., * Experience supporting a Federal civilian agency.
- Experience using Microsoft Sentinel, Splunk Enterprise Security, Microsoft Defender XDR, or comparable enterprise security platforms.
- Experience supporting incident response or vulnerability management activities.
- Familiarity with the MITRE ATT&CK Framework.
- CompTIA Security+
- CompTIA CySA+
- GIAC Security Essentials (GSEC)
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Splunk Core Certified User or Power User
- Cisco CyberOps Associate (preferred)
Knowledge, Skills, and Abilities
- Security Operations Center (SOC) Operations
- Security Monitoring
- Security Information and Event Management (SIEM)
- Microsoft Sentinel
- Splunk Enterprise Security
- Endpoint Detection and Response (EDR)
- Extended Detection and Response (XDR)
- Microsoft Defender XDR
- Microsoft Defender for Endpoint
- Microsoft Defender for Cloud
- Incident Triage
- Event Correlation
- Log Analysis
- Threat Detection
- Malware Identification
- Phishing Analysis
- Network Security
- TCP/IP
- Windows Security
- Linux Security
- MITRE ATT&CK Framework
- NIST Cybersecurity Framework
- NIST Risk Management Framework (RMF)
- Ticket Management
- Technical Documentation
- Microsoft Office Suite
- ServiceNow
- Jira
Security Requirements
- Ability to successfully obtain and maintain a Tier 2 Public Trust investigation.
- Compliance with all applicable Federal security, privacy, ethics, and information assurance training requirements before receiving system access.
- Ability to support 24x7 cybersecurity operations, emergency response activities, scheduled maintenance windows, continuity of operations (COOP), and surge support as required.
- Must maintain strict confidentiality while handling sensitive security events, log data, investigation records, and Federal information systems.
- Ability to work effectively in a fast-paced Security Operations Center environment while providing timely monitoring, accurate incident documentation, and responsive support to Government stakeholders and cybersecurity teams.