Cyber Security Analyst - SOC Threat Analyst

Savannah River National Laboratory

Aiken (SC)

On-site

USD 120,000 - 180,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, Dental, and Vision options, H
Disability insurance (short & long‑ten
Life Insurance
AD&D coverage
Relocation assistance

Job summary

Savannah River National Laboratory seeks a Senior Cyber Security Analyst with expertise in Threat Analysis and SOC duties to monitor, detect, and respond to complex cyber threats in real-time. You will lead investigations, hunt for adversaries, and help implement Zero Trust protections across enterprise assets.

The role emphasizes hands-on incident response, threat hunting, and development of automated playbooks, with mentorship of junior analysts and coordination with security teams.

Qualifications

  • BS/BA in Cybersecurity, Computer Science, Information Technology, or equivalent practical experience.
  • 7-9 yrs of dedicated experience in SOC or Threat/IR role with Zero Trust experience.
  • Complies with all policies and standards.
  • Maintain appropriate government security clearance.
  • US Citizenship required.

Responsibilities

  • Alert Monitoring & Escalation Management: Monitor network security alerts and perform real-time log reviews to identify and escalate incidents proactively.
  • Tooling Maintenance & Support: Maintain and support core cyber security toolsets for effective operation and policy alignment.
  • Incident Response & Threat Hunting: Lead advanced incident investigations, coordinate containment strategies, and remediate high-priority alerts.
  • Threat Intelligence Monitoring: Hunt for undetected threats and evaluate threat intel to configure defenses.
  • Zero Trust Architecture: Assist design, implement, and verify Zero Trust principles across enterprise assets.
  • Alert Verification & Analysis: Analyze malicious activity across endpoints, apps, and logs; final escalation tier.
  • Playbook Development: Design and automate response playbooks (SOAR) and write detections for SOC operations.
  • Mentorship: Guide and train junior/mid-level SOC analysts to raise team capabilities.

Skills

Threat Analysis
Incident Response
Zero Trust
SOC Operations
Security Monitoring

Education

Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent

Tools

Splunk Enterprise Security
Splunk SOAR
Tenable Security Center
Proofpoint Email Gateways
Microsoft Defender
SCUBA

Job description

Job Description

We are seeking a highly experienced, vigilant, and proactive Senior Cyber Security Analyst with a specialized focus on Threat Analysis and Security Operations Center (SOC) duties. In this role, you will serve in tactical defense initiatives, monitoring, detecting, and responding to complex cyber threats in real-time. You will analyze sophisticated security events, lead incident investigations, hunt for undetected adversaries.

Job Description

We are seeking a highly experienced, vigilant, and proactive Senior Cyber Security Analyst with a specialized focus on Threat Analysis and Security Operations Center (SOC) duties. In this role, you will serve in tactical defense initiatives, monitoring, detecting, and responding to complex cyber threats in real-time. You will analyze sophisticated security events, lead incident investigations, hunt for undetected adversaries.

Responsibilities
Key Responsibilities
  • Alert Monitoring & Escalation Management: Monitor network security alerts and perform continuous log reviews in real time, analyzing events to identify, elevate, and assist in responding to potential security incidents proactively.
  • Tooling Maintenance & Support: Maintain and support core cyber security toolsets, ensuring their effective operation, health, and policy alignment across the enterprise.
  • Incident Response & Threat Hunting: Lead advanced incident investigations, coordinate threat containment strategies, and execute remediation steps for high-priority alerts.
  • Threat Intelligence Monitoring: Hunt for undetected threats within our networks and evaluate threat intelligence to proactively configure defensive postures.
  • Zero Trust Architecture: Assist in the design, implementation, and continuous verification of Zero Trust Architecture (ZTA) principles, ensuring that device health, identity, and context-aware access policies are strictly enforced across enterprise assets.
  • Alert Verification & Analysis: Deeply analyze malicious activity across endpoints, applications, and logs, acting as the final escalation tier before senior management notification.
  • Playbook Development: Design and automate response playbooks (SOAR) and write custom detections to streamline SOC operations.
  • Mentorship: Provide guidance, technical support, and training to junior and mid-level SOC analysts to elevate overall team capabilities.
Qualifications
Minimum Qualifications
  • BS/BA in Cybersecurity, Computer Science, Information Technology, or equivalent practical experience
  • 7-9 yrs of dedicated experience working within a Security Operations Center (SOC) or in a dedicated Threat Analyst/Incident Response role, with practical experience implementing or defending Zero Trust environments.
  • Complies with all policies and standards.
  • Maintain appropriate level government security clearance.
  • US Citizenship required
Preferred Qualifications
  • Certifications (Highly Desired): CISSP, GCIA, GCIH, GCDA, OSCP, CySA+, Zero Trust certifications (e.g., Forrester Zero Trust, ZTX, or Microsoft SC-100), or advanced platform-specific certifications (Splunk Enterprise Certified Admin, Microsoft SC-200, etc.).
  • Architecture & Methodology: Strong foundational understanding and hands‑on familiarity with Zero Trust Architecture (ZTA) frameworks (e.g., NIST SP 800-207, CISA Zero Trust Maturity Model), specifically focusing on micro‑segmentation, identity‑centric access control, and assuming breach posture.
  • SIEM & Analytics: Advanced proficiency with Splunk Enterprise Security/Splunk SOAR (complex SPL query development, dashboard creation, detection rule tuning, and correlation model design).
  • Vulnerability Management: Proven experience managing and configuring Tenable Security Center (Nessus) for enterprise‑scale vulnerability scanning, prioritization, and executive reporting.
  • Email Security: Deep experience managing and configuring Proofpoint email gateways, analyzing targeted email campaigns, and executing URL/attachment analysis.
  • Endpoint & Cloud Security: Expert‑level utilization of Microsoft Defender (Defender for Endpoint/XDR, Identity, and Cloud Apps) for proactive threat hunting, live response, and endpoint isolation. Strong familiarity with Microsoft SCUBA (Secure Cloud Business Applications) for auditing, securing, and maintaining M365 suite security configurations is highly desired.
About Us

"We put science to work!"

Savannah River National Laboratory (SRNL) is a multi-program laboratory applying state of the art science and practical, high-value, cost‑effective solutions to complex technical problems to protect the nation. Located at the U.S. Department of Energy’s (DOE) Savannah River Site (SRS) in Aiken SC, the laboratory develops and deploys innovative technologies to address some of the nation’s environmental, energy, and national security challenges.

Battelle Savannah River Alliance (BSRA) is constantly assessing trends to provide the best possible benefits to our workforce. We also negotiate cost effective premiums that will meet the needs of our evolving workforce.

Some of the *Benefits offered to employees include:

  • Benefits vary based upon employment status
  • Highly competitive Medical, Dental, and Vision options including HSA options with company provided seed
  • Short- & Long-Term Disability (company paid)
  • Life Insurance Non-Contributary 1X salary (company paid)
  • AD&D Non-contributory 1x salary (company paid)
  • Savings & Investment plan:
    • Qualified Non-Elective Company Contribution of 5% each pay period with immediate vesting
    • Company match 50 cents/dollar up to 8% (5 yrs. vesting in company match)
  • Contributory Life Insurance up to 5x Salary with $1M Cap
  • Contributory AD&D (employee, spouse and children)
  • Paid Time Off
  • Employee Assistance Plan
  • SRNL offers a competitive relocation package to ease the transition process. Domestic and international relocation assistance is available for certain positions.

For more information about our benefits, working here, and living here, visit the “About” tab at www.srnl.doe.gov.

BSRA is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or protected veteran status. BSRA is also committed to making our workplace accessible to individuals with disabilities and will provide reasonable accommodations, upon request, for individuals to participate in the application and hiring process. Please email us at SRNLRecruiting@srnl.doe.gov with any questions regarding the hiring process or to request an accommodation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Analyst - SOC Threat Analyst
Cyber Security Analyst - SOC Threat Analyst

Savannah River National Laboratory • South Carolina

On-site
USD 120,000 - 160,000
Medical, Dental, Vision
Disability Insurance
Life Insurance
+4
Cyber Security Analyst- Engineer
Cyber Security Analyst- Engineer

Savannah River National Laboratory • South Carolina

On-site
USD 110,000 - 170,000
Relocation package
Medical, dental, and vision plans with
Life Insurance
+2
Cyber Security Analyst, Intermediate
Cyber Security Analyst, Intermediate

Savannah River National Laboratory • Aiken (SC)

On-site
USD 90,000 - 125,000
Medical/Dental/Vision
Disability insurance
Life Insurance
+5
Senior Cybersecurity Strategist
Senior Cybersecurity Strategist

Savannah River National Laboratory • South Carolina

On-site
USD 140,000 - 210,000
Medical Insurance
Dental Insurance
Relocation package
Senior Cybersecurity Strategist
Senior Cybersecurity Strategist

Savannah River National Laboratory • Aiken (SC)

On-site
USD 140,000 - 190,000
Relocation package
Competitive benefits package
Medical, Dental, Vision
Cyber Security Analyst- Engineer
Cyber Security Analyst- Engineer

SRNL • Aiken (SC), Northern (KY)

Hybrid
USD 120,000 - 150,000
Medical, dental, and vision
Disability insurance
Life Insurance
+2
Cyber Security Analyst- Engineer
Cyber Security Analyst- Engineer

Savannah-River-National-Laboratory • Aiken (SC)

On-site
USD 110,000 - 165,000
Relocation package
Competitive benefits
DOE clearance support
Cyber Security Analyst: Data Sanitization & Spill Cleanup Specialist
Cyber Security Analyst: Data Sanitization & Spill Cleanup Specialist

Savannah River National Laboratory • South Carolina

On-site
USD 90,000 - 130,000
Medical, Dental, Vision
Disability insurance
Pension / 401(k)
Cyber Security Analyst: Data Sanitization & Spill Cleanup Specialist
Cyber Security Analyst: Data Sanitization & Spill Cleanup Specialist

Savannah River National Laboratory • Aiken (SC)

On-site
USD 90,000 - 130,000
Health, dental, vision benefits with H
Disability insurance (short/long-term)
Life insurance
+5
Division Director, Advanced Technology and Analysis
Division Director, Advanced Technology and Analysis

Savannah River National Laboratory • Aiken (SC)

On-site
USD 150,000 - 210,000
Relocation assistance
Competitive benefits package
Disability insurance
+1