SOC Analyst, Incident Response & Threat Detection
Overview
You will own threat detection and incident response for customer networks at Leidos' Digital sector in Alexandria, VA. With 2+ years of SOC experience, you will triage alerts from endpoints, IDS/IPS, NetFlow, and custom sensors, and perform intermediate-level log analysis. You will work shift rotations in a 24/7 mission-essential environment, supporting a team that protects critical infrastructure. This role moves beyond monitoring: you will document findings, craft incident reports, and grow into senior-level investigations. Expect to work weekends and in bad weather, with an active Top Secret clearance and ability to obtain SCI.
What You'll Do8
- 1Triage alerts from IDS/IPS, endpoints, NetFlow, and custom sensors to identify compromises on customer networks.
- 2Review massive log files, pivot between data sets, and correlate evidence for incident investigations.
- 3Pass triaged alerts to senior SOC personnel and assist in identifying malicious actors.
- 4Document analysis, findings, and actions in a case or knowledge management system.
- 5Create and distribute incident reports to customers and higher headquarters.
- 6Perform shift work on site, covering all shifts including weekends and inclement weather.
- 7Apply understanding of network threats, attack vectors, and TTPs to improve detection.
- 8Assist in mentoring junior analysts and maintaining proficiency in cybersecurity domains.
Requirements10
- 12+ years of incident handling and response experience in a SOC environment.
- 2Active DoD Top Secret clearance with ability to obtain SCI.
- 3DoD 8570 IAT II or higher certification (CompTIA Security+ CE, ISC2 SSCP, SANS GSEC, or similar) prior to starting.
- 4Ability to obtain DoD 8570 CSSP-Analyst certification (CEH, CySA+, GCIA, or similar) within 6 months.
- 5Bachelor's degree and 4+ years of relevant experience; military service or work may substitute for degree.
- 6Sound understanding of TCP/IP, common ports, protocols, OSI model, and defense-in-depth.
- 7Knowledge of network threat lifecycle, attack vectors, and TTPs.
- 8Strong analytical skills and ability to write complex technical reports.
- 9Demonstrated commitment to mentoring, training, and self-study.
- 10Willingness to work shift work on site, including weekends and inclement weather.
Salary Insight
Salary not disclosed in listing
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.
MANTECH
VerifiedCyber Security Analyst, Incident Response & SOC
You will own security event correlation and incident triage across enterprise networks, detecting and responding to threats in real time. You will work within a 24x7 SOC team, analyzing alerts from Windows and Linux systems and coordinating remediation. You hold IAT Level II certification (Security+ or equivalent) and thrive in high-stakes environments. This role offers direct exposure to COTS security tools and a clear path to advanced cyber roles.
631 Booz Allen Hamilton_United States
VerifiedCyber Security Analyst, SOC Tier 2
You will own threat detection and incident response for critical infrastructure, monitoring and mitigating attacks in real time as a Tier 2 SOC analyst. You will join a security operations team using state-of-the-art tools to analyze logs, investigate alerts, and escalate incidents. You will work with intelligence sources to identify patterns and stop attackers, directly impacting mission success. This role offers hands-on experience in threat assessment and incident response, with clear paths for growth.
SAIC
VerifiedCyber Defense Analyst SAIC Washington DC
SAIC seeks a Cyber Defense Analyst on a joint Contractor Government Cyber Protection Team at Fort Meade Maryland. This full-time day shift role requires on-site presence 10 percent of the time. Candidates must hold a TS.SCI_wPoly clearance and possess relevant technical expertise.
SPAHR SOLUTIONS GROUP LLC
VerifiedCyber Security Operations Jr Analyst
Lead 24x7x365 cybersecurity monitoring and threat detection for DTRA's enterprise network. Work shift nights weekends and holidays. Must be SCI eligible Top Secret clearance. Collaborate with CSSP analysts engineers and agency stakeholders to protect national security interests.
Armada Ltd
VerifiedSSOC Operator, Security Systems Monitoring
You will monitor and support SSOC operations in Washington DC, ensuring continuous compliance with physical security requirements. You will execute established alarm and event response workflows, document incidents accurately, and coordinate with the Site Lead. This role demands a sharp eye for detail and the ability to act decisively under pressure. You will maintain situational awareness and escalate issues promptly. This position offers the chance to work on-site at a high-stakes facility with a clear chain of command.
00100 LEIDOS, INC.
VerifiedSenior Industrial Security Representative Leidos
Leidos seeks a proven security professional to lead SCI program security for the Intelligence Community. This role offers a unique chance to apply expertise and drive impactful outcomes. The ideal candidate will oversee SCI initiatives ensuring compliance and effective communication across teams.