TS Cleared -Senior SOC Analyst - ONSITE -Top SECRET
Listed on 2025-12-30
-
IT/Tech
Cybersecurity, Security Manager
TS Cleared - Senior SOC Analyst (100% ONSITE, Top SECRET is a MUST)
Location:
Federal Intel Agency, Huntsville, AL. Shift time:
Various shifts.
Seniority level:
Mid‑Senior level.
Employment type:
Full‑time. Job function:
Information Technology.
The Senior SOC Analyst is a second‑tier escalation analyst supporting Information Assurance Engineers and the Shift Team Lead. The analyst monitors and responds to alerts from the SIEM tool, investigates incidents, recommends actions, and documents incidents with clear narratives.
Responsibilities- Act as second‑tier escalation for security incidents.
- Support detailed discovery and analysis of intrusion detection events across the agency network.
- Respond aggressively to alerts triggered in the SEIM tool or from customer requests.
- Use tools such as Splunk ES, Splunk SIEM, Fire Eye, Wireshark, Snort, PCAP analysis, and awareness of OWASP Top 10 vulnerabilities to investigate incidents and recommend actions.
- Document all incidents and create clear narratives supporting conclusions.
- Construct email notification messaging for incident reports.
- 8+ years of SOC analyst experience in intrusion detection, network IPS/IDS, log analysis, and threat detection.
- Proficiency with Splunk ES, Splunk SIEM, Fire Eye, Wireshark, Snort, PCAP analysis, and other cyber‑security technology tools.
- Active TOP SECRET clearance with ability to obtain SCI
. - Strong written and oral communication skills.
- Bachelor’s degree in Computer Science, Information Technology, or related field.
Standard benefits include 3 weeks PTO (including sick leave), 2 floating holidays, 8 public holidays, 50% coverage of health and dental insurance for full‑time employees (coverage begins after 30 days), life insurance, 401(k) with 4% company match, and profit sharing. No parking, commuting, or relocation expenses are covered.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).