Cyber Security Analyst, Incident Response & SOC
Overview
You will own security event correlation and incident triage across enterprise networks, detecting and responding to threats in real time. You will work within a 24x7 SOC team, analyzing alerts from Windows and Linux systems and coordinating remediation. You hold IAT Level II certification (Security+ or equivalent) and thrive in high-stakes environments. This role offers direct exposure to COTS security tools and a clear path to advanced cyber roles.
What You'll Do6
- 1Correlate security events from Splunk, ArcSight, and other COTS tools to identify potential incidents.
- 2Triage cyber incidents within 15 minutes of alert, determining scope, urgency, and impact.
- 3Track incident response actions from detection to resolution, updating ServiceNow tickets.
- 4Assess damage to affected data and infrastructure, documenting forensic evidence.
- 5Generate trend analysis reports on attack patterns and communicate findings to leadership.
- 6Support 24x7 shift operations, including Panama schedule rotations.
Requirements6
- 14+ years of work experience in cybersecurity or a Bachelor's degree.
- 2IAT Level II certification (Security+, SSCP, CCNA-Security, or GSEC).
- 3Hands-on experience with Windows and Linux operating systems.
- 4Familiarity with COTS cybersecurity technologies such as Splunk or FireEye.
- 5Knowledge of database and OS security principles.
- 6Active TS/SCI with Polygraph clearance.
Salary Insight
Salary not disclosed in listing
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.
631 Booz Allen Hamilton_United States
VerifiedCyber Security Analyst, SOC Tier 2
You will own threat detection and incident response for critical infrastructure, monitoring and mitigating attacks in real time as a Tier 2 SOC analyst. You will join a security operations team using state-of-the-art tools to analyze logs, investigate alerts, and escalate incidents. You will work with intelligence sources to identify patterns and stop attackers, directly impacting mission success. This role offers hands-on experience in threat assessment and incident response, with clear paths for growth.
00100 LEIDOS, INC.
VerifiedSOC Analyst, Incident Response & Threat Detection
You will own threat detection and incident response for customer networks at Leidos' Digital sector in Alexandria, VA. With 2+ years of SOC experience, you will triage alerts from endpoints, IDS/IPS, NetFlow, and custom sensors, and perform intermediate-level log analysis. You will work shift rotations in a 24/7 mission-essential environment, supporting a team that protects critical infrastructure. This role moves beyond monitoring: you will document findings, craft incident reports, and grow into senior-level investigations. Expect to work weekends and in bad weather, with an active Top Secret clearance and ability to obtain SCI.

BCforward
VerifiedCyber Security Engineer, SOC & Incident Response
Own security monitoring and incident response for a Fortune 500 client in Phoenix, AZ. You will join BCforward's security operations team, working onsite to detect, investigate, and mitigate threats across a hybrid cloud and on-premise environment. This role demands hands-on expertise with SIEM platforms and EDR tools, with a direct impact on the client's security posture.

System One
VerifiedMid-Level Cybersecurity Incident Response Analyst
Own security alert investigation and response at scale. Deliver actionable insights within 90 days. Differentiate through proactive threat hunting and cross-functional collaboration.
SPAHR SOLUTIONS GROUP LLC
VerifiedCyber Security Operations Jr Analyst
Lead 24x7x365 cybersecurity monitoring and threat detection for DTRA's enterprise network. Work shift nights weekends and holidays. Must be SCI eligible Top Secret clearance. Collaborate with CSSP analysts engineers and agency stakeholders to protect national security interests.
SAIC
VerifiedCyber Defense Analyst SAIC Washington DC
SAIC seeks a Cyber Defense Analyst on a joint Contractor Government Cyber Protection Team at Fort Meade Maryland. This full-time day shift role requires on-site presence 10 percent of the time. Candidates must hold a TS.SCI_wPoly clearance and possess relevant technical expertise.