SOC Analyst; Night Shift
Listed on 2026-09-03
-
IT/Tech
Cybersecurity, Security Management & Operations, Network Security
Cyber Security Analyst (SOC)
Join a long-term cybersecurity program supporting a critical Department of Defense mission in a fast-paced 24/7 Security Operations Center (SOC) environment. This role focuses on Cyber Network Defense (CND), threat detection, incident analysis, vulnerability management, and continuous monitoring across enterprise networks. Analysts will leverage industry-leading platforms including Splunk, Trellix, and ACAS to identify, investigate, and respond to cyber threats while helping maintain the security and integrity of mission-critical systems.
This opportunity offers long-term stability on a five-year contract supporting a high-visibility federal customer.
Key Responsibilities
- Monitor and analyze security events from SIEM, EDR, IDS/IPS, and vulnerability management platforms.
- Perform real-time cyber threat detection, triage, investigation, and escalation activities within a 24/7 SOC.
- Conduct Cyber Network Defense (CND) operations to identify malicious activity, anomalous behavior, and indicators of compromise.
- Investigate network traffic using packet capture (PCAP) data to identify intrusion attempts, malware activity, and unauthorized communications.
- Analyze alerts and logs generated from Splunk, Trellix, ACAS, and other cybersecurity tools.
- Utilize IDS/IPS technologies to identify threats, validate alerts, and support incident response efforts.
- Perform threat hunting activities using log analysis, endpoint telemetry, network traffic analysis, and threat intelligence.
- Conduct vulnerability assessments and track remediation activities using ACAS and related vulnerability management tools.
- Correlate events from multiple data sources to determine root cause, scope, and impact of security incidents.
- Develop and maintain incident documentation, shift reports, and operational metrics.
- Coordinate with engineering, network, and system administration teams to support containment and remediation efforts.
- Support continuous monitoring initiatives and compliance with DoD cybersecurity requirements.
- Participate in daily shift handoffs to ensure seamless 24/7 operational coverage.
Required Qualifications
- Experience supporting a Security Operations Center (SOC), Cyber Defense Team, or Incident Response function.
- Hands-on experience with Splunk for log analysis, correlation, alert investigation, and reporting.
- Experience with Trellix security products and endpoint security monitoring.
- Experience utilizing ACAS for vulnerability scanning, analysis, and remediation tracking.
- Strong understanding of Cyber Network Defense (CND) principles and security monitoring methodologies.
- Experience performing packet analysis using PCAP data.
- Knowledge of IDS/IPS technologies and network-based threat detection.
- Understanding of TCP/IP, network protocols, and common attack methodologies.
- Experience analyzing security alerts, events, and indicators of compromise.
- Strong troubleshooting, documentation, and communication skills.
- Ability to work rotating shifts in a 24x7 operational environment.
Preferred Qualifications
- Experience supporting DoD or Federal cybersecurity programs.
- Familiarity with MITRE ATT&CK, Cyber Kill Chain, and threat hunting methodologies.
- Experience with incident response, malware analysis, or digital forensics.
- Knowledge of STIGs, vulnerability management processes, and security compliance frameworks.
- Experience with threat intelligence integration and IOC analysis.
- Understanding of Windows, Linux, and enterprise networking environments.
Certifications (One or More Preferred)
- Security+
- CySA+
- CASP+
- GCIH
- GCIA
- CEH
- CISSP
Why Apply?
- Long-term five-year program supporting a critical defense mission
- High-visibility cybersecurity operations environment
- Opportunity to work with leading security technologies including Splunk, Trellix, and ACAS
- Multiple shift options available
- Exposure to advanced cyber threat detection, network defense, and incident response operations
- Strong career growth potential within enterprise cybersecurity and SOC operations group
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).