Security Operations Center Analyst - Mid
Listed on 2026-07-30
-
IT/Tech
Cybersecurity, Security Management & Operations
Security Operations Center Analyst - Mid
Washington, DC, USA
Job DescriptionKoniag Data Solutions, a Koniag Government Services company, is seeking a skilled Mid-Level Security Operations Center (SOC) Analyst to support the U.S. Small Business Administration (SBA). The ideal candidate is an experienced cybersecurity professional with a solid foundation in security event monitoring, threat detection, and incident response within a SOC environment.
The Mid-Level SOC Analyst will serve as an experienced cybersecurity operations professional responsible for monitoring, detecting, analyzing, and supporting the response to cybersecurity threats targeting SBA's enterprise IT environment. Working under the guidance of the Cybersecurity Operations Technical Lead and Senior Cyber Defense Analysts, this individual will contribute meaningfully to all aspects of SOC operations while continuing to develop and refine their technical skills and expertise.
Principal responsibilities will include but are not limited to:
- Perform continuous monitoring of SBA networks, systems, endpoints, and cloud environments using SIEM platforms, IDS/IPS tools, EDR solutions, and other security technologies to detect and identify potential threats, anomalies, and indicators of compromise.
- Conduct analysis and triage of security events and alerts generated by SOC monitoring tools, determining the validity, scope, and severity of potential security incidents and escalating confirmed or suspected incidents to senior analysts and the Technical Lead in accordance with established procedures.
- Support incident response activities, including initial containment actions, evidence preservation, and coordination with senior analysts and the Technical Lead during active security incidents, following SBA's incident response policies and NIST SP 800-61 guidelines.
- Investigate security events and incidents by analyzing network traffic, system logs, endpoint telemetry, and other relevant data sources to identify the root cause, scope, and impact of potential security issues.
- Document security events, incidents, and investigative findings accurately and thoroughly in SBA's ticketing and case management systems, maintaining detailed records of all SOC activities in accordance with established documentation standards.
- Assist in the development and refinement of SIEM detection rules, correlation logic, and alerting thresholds under the guidance of senior analysts and the Technical Lead, contributing recommendations based on observed alert patterns and false positive analysis.
- Support threat hunting activities by executing predefined hunt playbooks and assisting senior threat hunters in the identification of indicators of compromise and malicious activity within SBA's environment.
- Monitor and analyze threat intelligence from government and commercial sources, including US-CERT, CISA, and relevant ISACs, to stay current on emerging threats and incorporate relevant intelligence into daily SOC monitoring and analysis activities.
- Assist in the development and maintenance of SOC Standard Operating Procedures (SOPs), incident response playbooks, and runbooks, contributing updates and improvements based on operational experience and lessons learned.
- Collaborate effectively with SBA IT teams, system owners, and other stakeholders to communicate security findings, support remediation coordination, and contribute to the improvement of SBA's overall security posture.
- Support vulnerability management activities by reviewing and analyzing vulnerability scan results, assisting with the identification of high-priority vulnerabilities, and coordinating with system owners on remediation tracking and follow-up.
- Participate in after‑action reviews (AARs) and lessons learned sessions following significant security incidents, contributing observations and recommendations to improve SOC processes, procedures, and capabilities.
- Prepare and contribute to the development of security incident reports, shift handover reports, and other SOC documentation, ensuring accuracy, completeness, and adherence to established reporting standards.
- Participate in SOC team training activities, tabletop exercises, and professional development opportunities to continuously expand technical knowledge and skills in cybersecurity operations and threat analysis.
- Ensure all SOC activities comply with applicable federal cybersecurity frameworks, policies, and regulations, including NIST, FISMA, and DHS/CISA directives and guidance.
Education and Experience:
Required:
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field from an accredited college or university.
- 3+ years of experience in cybersecurity operations, security event monitoring, or a related field, with demonstrated experience working within a SOC or cyber defense environment.
- Demonstrated experience working with SIEM platforms and security monitoring tools in an operational environment.
- One or more of the following…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).