SOC Analyst
Core
Monitor security incidents, triage alerts via SIEM, and investigate threats for US federal government clients.
Role type
SOC Analyst (Incident Response)
Builds
Security incident response workflows and alert notifications for government missions
Domain
Cybersecurity / US Federal Government
Deliverable
client delivery
Required skills
SIEM triage, security incident investigation, log analysis, threat vector identification, incident documentation, escalation procedures
Preferred skills
Security tool integration, Python/PowerShell scripting, networking hardware configuration
Technologies
Splunk, Carbon Black, Cylance, McAfee, Tenable, FireEye, CrowdStrike, ELK, Cisco, Palo Alto, Juniper, GCIH, GREM, GCED, GCDA
Responsibilities
Perform continuous monitoring and security incident triage through SIEM review; Identify and collect data for initial security investigations; Document and track investigations to resolution; Escalate advanced analysis incidents to Tier 2 or responders
Seniority
Junior to Mid-level, hands-on IC