
SOC Analyst
- ๐บ๐ธ United States
- Remote
- 19 hours ago
- Secret Clearance
- Risk Management Framework
- RMF
- Vulnerability Management
- Incident Response
- SIEM
- triage
- CCNP
- CISA
- CISSP
- GCIH
- CCSP
- CEH
- CCNA
- CySA+
- GCIA
- Microsoft Sentinel
SOC Analyst
Location: Remote | Night and Weekend Shifts Required
Active Secret Clearance Required
ASRC Federal is seeking aSOC Analyst to support the Department of Defense Education Activity (DoWEA) Enterprise Cyber Program. This role supports enterprise cybersecurity operations, including Risk Management Framework (RMF) compliance, vulnerability management, security monitoring, and incident response, in collaboration with other cybersecurity personnel.
This is a remote position requiring scheduled night and weekend shifts in support of SOC operations.
Key Responsibilities:
Monitor and analyze network traffic, system logs, and other security data for signs of malicious activity.
Use Security Information and Event Management (SIEM) tools to investigate security alerts and notable events.
Manage incidents throughout their lifecycle, including analysis, triage, containment, and remediation.
Recommend improvements to prevent future incidents and expedite response based on lessons learned.
Communicate effectively and promptly with technical and nontechnical stakeholders.
Prepare situational awareness reports for the customer and management.
Develop and maintain manual and automated incident response playbooks.
Support the development of SIEM detection and data ingestion strategies to improve SOC visibility.
Conduct host and log forensic analysis and malware analysis as needed.
Perform threat hunting based on emerging adversary tactics, techniques, and procedures.
Develop and implement security procedures to prevent future incidents.
Provide technical support to other members of the security team.
Stay current on cybersecurity threats and trends.
Required Skills, Certifications, and Qualifications:
Minimum offive years of relevant cybersecurity experience, including SOC operations, security monitoring, and incident response.
Must hold and maintain required cybersecurity certifications, including one certification from each of the following groups:
CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, or CCSP.
CEH, CFR, CCNA Cyber Ops, CCNA-Security, CySA+, GCIA, GCIH, GICSP, Cloud+, SCYBER, or PenTest+.
Experience with SIEM tools, such as Microsoft Sentinel.
Experience leading and managing SOC operations.
Expertise in analyzing network packets, SIEM alerts, and server and application logs to investigate anomalous or malicious activity.
Experience tracking incidents using frameworks such as MITRE ATT&CK or the Cyber Kill Chain.
Ability to analyze advanced persistent threats and map the threat lifecycle.
Ability to work scheduled night and weekend shifts remotely.
Active Secret security clearance.
Desired Skills:
Experience with Microsoft Sentinel.
Forensic investigation and malware analysis experience.
Strong curiosity and problem-solving skills.
Proactive approach and a strong sense of ownership.
SOC Analyst ยท ASRC Federal