Cyber Monitoring Analyst

CACI

Hampton (VA)

On-site

USD 110,000 - 140,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

CACI seeks a Cyber Monitoring Analyst to join the Cyber Security Incident Response Team supporting the AF DCGS program at Langley AFB, VA. The role requires intermediate skills in Windows, Linux, and cloud environments, with SIEM experience for real-time threat detection and log analysis.

You will work in a shift-based 24/7 environment with minimal oversight. You will utilize ELK/Elastic Stack, document incidents, and coordinate with T1–T3 analysts and external stakeholders, following IRP SOPs

Qualifications

  • Active TS/SCI clearance is required.
  • Bachelor's degree in IT/CS or related field with 5 years of cyber operations or monitoring experience, or equivalent.
  • DOD 8140/8570 IAT Level II (Security+ or equivalent).
  • Experience with Elastic Stack for log analysis and real-time monitoring.
  • Ability to follow IRP playbooks and SOPs.

Responsibilities

  • Continuously monitor security alerts and logs to identify threats across the OA DCGS weapon system.
  • Use ELK/Elastic Stack for real-time log analysis and dashboard maintenance.
  • Escalate security events using ticketing systems and coordinate with tiers T1–T3 and external stakeholders.
  • Maintain incident records and post-incident documentation for compliance.
  • Collaborate with incident response, threat hunting and vulnerability teams.
  • Operate independently during assigned shifts in a 24/7 environment.

Skills

TS/SCI clearance
Incident Response
Log analysis
Problem solving
Communication
Independent work

Education

Bachelor's degree in IT/CS or related field

Tools

Elastic Stack
SIEM
Security tools

Job description

Job Title: Cyber Monitoring Analyst
Job Category: Information Technology
Time Type: Full time
Minimum Clearance Required to Start: TS/SCI
Employee Type: Regular
Percentage of Travel Required: Up to 10%
Type of Travel: Local

The Opportunity:

Our client is seeking a highly motivated Cyber Monitoring Analyst that will join the Cyber Security Incident Response Team supporting the AF DCGS program located onsite at Langley AFB, Va. The ideal candidate will have intermediate-level skills in Windows, Linux, and Cloud environments, supported by a background in system administration or security monitoring. They should be experienced in using SIEMs or other cyber monitoring tools for real-time threat detection and log analysis. In addition, the candidate must be capable of executing monitoring and escalation procedures in alignment with the established Incident Response Plan (IRP), with minimal oversight. This position is embedded within a high-tempo operational environment and demands a proactive approach to monitoring, alert triage, and escalation. Candidates must be comfortable working independently during shift rotations and contributing to a shift-based 24/7 monitoring environment, including weekends and holidays.

Shift: Swings/Night 1600-0200 (Wednesday - Saturday)

Responsibilities:
  • Continuously monitor security alerts and system logs to identify potential threats and anomalous activity across the OA DCGS weapon system, ensuring its confidentiality, integrity, and availability.
  • Utilize ELK/Elastic Stack to conduct real-time log analysis, detect threats, and support investigations; maintain dashboards and incident records for visibility and reporting.
  • Escalate and document security events using established ticketing systems, ensuring timely and accurate reporting to internal cyber analyst tiers (T1-T3) and appropriate external stakeholders beyond the Incident Response (IR) team.
  • Follow and maintain cybersecurity standard operating procedures (SOPs) and incident response playbooks to ensure consistent and effective monitoring practices.
  • Maintain detailed documentation of monitoring activities, incident timelines, and case notes to support post-incident reviews and compliance requirements.
  • Contribute to proactive threat detection by reviewing SIEM alerts and security dashboards to identify indicators of compromise (IOCs) and anomalous activity, supporting early escalation through behavioral analysis and correlation techniques.
  • Monitor threat intelligence feeds and security news for emerging threats, including Zero-Day vulnerabilities and CVEs, and escalates relevant findings to senior analysts for integration into detection workflows.
  • Collaborate with incident response, threat hunting, and vulnerability management teams to ensure seamless handoff and resolution of detected threats.
  • Operate independently during assigned shifts, responding to alerts with urgency and precision to minimize potential impact.
  • Support penetration testing evaluations by responding to simulated threats in real time, enabling measurement of key performance indicators (KPIs) such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR)
Qualifications:
Required:
  • Active Top Secret/SCI security clearance.
  • Bachelor's degree in IT Technology, Computer Science, or related field with 5 years of experience in cyber operations or monitoring. Degree may be substituted with equivalent experience.
  • DOD 8140 (8570) IAT Level II (Security+ or equivalent).
  • Deep understanding of the Incident Response lifecycle, especially in detection and escalation phases.
  • Proficiency in Elastic Stack (Elasticsearch, Logstash, Kibana) for log analysis.
  • Familiarity with cyber security tools and monitoring procedures
  • Excellent problem-solving and analytical skills to identify and respond to threats in real time.
  • Effective written and verbal communication skills for documentation and collaboration
  • Ability to work independently in a shift-based 24/7 monitoring environment, including weekends and holidays.
Desired:
  • Experience supporting AF DCGS systems or similar military ISR platforms.
  • Proficiency in using the Elastic Stack (Elasticsearch, Logstash, Kibana)
  • Experience with AWS or other cloud security platforms
What You Can Expect:

A culture of integrity.

At CACI, we place character and innovation at the center of everything we do. As a valued team member, you'll be part of a high-performing group dedicated to our customer's missions and driven by a higher purpose - to ensure the safety of our nation.

An environment of trust.

CACI values the unique contributions that every employee brings to our company and our customers - every day. You'll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality.

A focus on continuous growth.

Together, we will advance our nation's most critical missions, build on our le

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Monitoring Analyst
Cyber Monitoring Analyst

Socket.dev • Hampton (VA)

On-site
USD 75,000 - 158,000
Cyber Monitoring Analyst
Cyber Monitoring Analyst

CACI International Inc • Hampton (VA)

On-site
USD 75,000 - 158,000
Flexible time off
Learning resources
Healthcare benefits
+1
Cyber Monitoring Analyst Hampton, VA, US
Cyber Monitoring Analyst Hampton, VA, US

CACI International Inc. • Hampton (VA)

On-site
USD 75,000 - 158,000
Flexible time off
Robust learning resources
Healthcare benefits
Cyber Incident Response Analyst
Cyber Incident Response Analyst

CACI International Inc • Hampton (VA)

On-site
USD 75,000 - 158,000
Cyber Incident Response Analyst
Cyber Incident Response Analyst

CACI International Inc. • Hampton (VA)

On-site
USD 75,000 - 158,000
Cyber Data Analyst Engineer
Cyber Data Analyst Engineer

CACI • St. Louis (MO)

On-site
USD 120,000 - 160,000
24/7 Cyber Monitoring Analyst (TS/SCI)
24/7 Cyber Monitoring Analyst (TS/SCI)

Socket.dev • Hampton (VA)

On-site
USD 75,000 - 158,000
Night-Shift Cyber Monitoring Analyst | 24/7 Ops
Night-Shift Cyber Monitoring Analyst | 24/7 Ops

CACI International Inc. • Hampton (VA)

On-site
USD 75,000 - 158,000
Flexible time off
Robust learning resources
Healthcare benefits
Cyber Data Analyst Engineer
Cyber Data Analyst Engineer

CACI International Inc. • St. Louis (MO)

On-site
USD 75,000 - 158,000
24/7 Cyber Monitoring Analyst — TS/SCI Clearance & Elastic Stack
24/7 Cyber Monitoring Analyst — TS/SCI Clearance & Elastic Stack

CACI • Hampton (VA)

On-site
USD 110,000 - 140,000