Cyber Security/SOC Analyst; Weekend Nights
Newport News, Virginia, 23601, USA
Listed on 2026-10-03
-
IT/Tech
Cybersecurity
At phia we hire talented and passionate people who are focused on collaborative, meaningful work, providing technical and operational subject matter expertise and support services to our partners and clients.
phia is hiring a Cyber Operations Analyst (SOC Threat Management) to support 24x7 operations in a large Federal agency Cyber Security Operations Center (CSOC). This role focuses on advanced cyber threat monitoring & detection, incident analysis and management, and leveraging AI/ML and automation to enhance SOC efficiency. The ideal candidate will have expertise in IT and cyber incident management, cyber threat intelligence and intrusion analysis, and hands-on experience with modern security tools and cloud environments.
This shift-based position offers REMOTE work flexibility. Qualified candidates will be U.S. Citizens and located in the United States, able to achieve Public Trust security vetting approval.
Weekday Night shift positionThis position will have the following primary work hours:
- Initial Temporary Orientation &
Qualification:
Monday
- Friday, 7:00am-3:30pm (ET) - Final Assigned
Shift:
Monday
- Friday, 11:00pm-7:30am (ET)
- Support 24x7 monitoring, detection, and management of advanced cyber threats.
- Execute operational processes in support of response efforts to identified security incidents.
- Perform deep-dive incident analysis by correlating data from multiple sources to determine impact on critical systems or datasets.
- Interpret output from the SIEM, incident reporting platforms and mailboxes, and phone calls to identify potential security incidents.
- Handle incidents as defined in Playbooks and SOPs.
- Identify security problems which may require mitigating controls, and advise on remediation actions.
- Analyze threat intelligence to assess risk and adapt defenses.
- Provide subject matter expertise on network-based attacks, intrusion methodologies, and threat management.
- Escalate complex incidents for further investigation and collaborate with other Threat Management team members.
- Utilize AI/ML-based tools to detect anomalies, automate triage, and improve threat intelligence.
- Provide input and analysis on how to leverage Artificial Intelligence, Machine Learning, and SOAR capabilities to improve CSOC efficiency and accuracy.
- Stay current on cybersecurity trends, threat actors, and AI/ML advancements relevant to SOC operations.
- Tune security policies, maintain visibility into cloud and endpoint environments, and support continuous improvement of the organization's security posture.
- Identify and support automation use cases, including the use of AI/ML to enhance SOC capabilities.
- Collaborate across the larger organization to provide SOC enhancement capabilities through the use of automation and AI.
- Experienced in cyber/IT security with at least 3 years of experience in IT and/or SOC operations.
- Familiar with both command and sophisticated threat actor tools and techniques.
- Skilled in network traffic analysis and threat detection methodologies.
- Strong understanding of Boolean logic, TCP/IP fundamentals, network-level exploits, and IDS/IPS technologies and signature development & optimization.
- Familiar with IT control frameworks, risk management techniques, and cloud security (AWS, Azure, GCP).
- Hands-on experience with cybersecurity automation and SIEM/SOAR platforms.
- Proficient in using ML frameworks for anomaly detection, threat intelligence and behavioral analysis.
- Skills in data analysis and feature engineering, with the ability to process and transform large datasets from various sources (e.g., logs, network traffic) to extract relevant features for machine learning models aimed at identifying security incidents and vulnerabilities.
- Familiarity with the application of AI/ML…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).