Cybersecurity Analyst

Saic

Fort Bragg (NC)

On-site

USD 110,000 - 140,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

SAIC seeks a Cybersecurity Analyst to support SITEC 3 EOM at Fort Bragg, NC. The role defends USSOCOM networks, analyzes logs, and coordinates incident response in a 24/7 SOC.

You will mentor junior staff, refine detection logic, and align hunt activities with MITRE ATT&CK across NetOps and critical systems.

Qualifications

  • DoD 8570 IAT II certifications AND CSSP Analyst OR CSSP Incident Responder
  • Strong understanding of cybersecurity concepts including threat detection, malware analysis, and network security
  • Proficiency with SIEM/IDS/IPS, endpoint protection, and forensic tools
  • Excellent analytical and problem‑solving skills with ability to handle complex incidents
  • Effective written and verbal communication and ability to brief stakeholders
  • Ability to work independently and lead initiatives in a fast‑paced environment
  • Must hold DoD security clearance TS/SCI

Responsibilities

  • Identify and analyze sophisticated threats using SIEM, IDS, and advanced tools
  • Correlate data across sources to uncover APTs and complex attack patterns
  • Refine detection rules and lead high‑priority security incidents containment and recovery
  • Deliver actionable recommendations and post‑incident reports
  • Lead audits and assessments to enhance compliance and processes
  • Mentor junior analysts and collaborate with SOC, IT, and stakeholders
  • Map hunt findings to MITRE ATT&CK framework and drive improvements
  • Develop threat hunt playbooks and cross‑functional threat intelligence sharing
  • Operate in a 24/7 SOC environment, including night/weekend shifts

Skills

Threat detection
Malware analysis
Network security

Education

Bachelor's degree in Cybersecurity/ CS/ IT
DoD 8570 IAT II certs

Tools

SIEM platforms
IDS/IPS
Endpoint protection
Forensic analysis tools

Job description

Description

SAIC is seeking a Cybersecurity Analysts to support the Special Operation Command Information Technology Enterprise Contract (SITEC) – 3 EOM. This position is located at Fort Bragg, NC.

The purpose of the Special Operations Forces Information Technology Enterprise Contract (SITEC) 3 Enterprise Operations and Maintenance (EOM) Task Order (TO) is to provide USSOCOM, its Component Commands, its Theater Special Operations Commands (TSOCs), and its deployed forces with Operations and Maintenance (O&M) services to maintain Network Operations (NetOps); maintain systems and network infrastructure; provide end user and common device support; provide configuration, change, license, and asset management; conduct training, and perform Install, Move, Add, Change (IMACs) services. The responsibilities and tasks associated with each requirement play a pivotal role to USSOCOM, the CIO/J6 organization, and ultimately the end-user who operate around the globe 24x7x365.

This position offers an opportunity for experienced cybersecurity professionals to take on advanced responsibilities in defending USSOCOM’s global operations. The Cybersecurity Analyst will play a pivotal role in enhancing SOC capabilities, mentoring junior team members, and ensuring the security and resilience of systems critical to USSOCOM’s mission success.

  • Expertise in identifying and analyzing sophisticated threats using SIEM platforms, intrusion detection systems (IDS), and other advanced tools.
  • Strategic ability to correlate data from multiple sources to uncover advanced persistent threats (APTs) and complex attack patterns.
  • Proficiency in refining detection rules and alerts to enhance threat identification capabilities. Leadership in managing high-priority security incidents, including coordinating containment, eradication, and recovery strategies.
  • Advanced skills in root cause analysis and delivering actionable recommendations for future mitigation.
  • Ability to create detailed post-incident reports to inform organizational strategy and resilience.
  • Ability to lead audits and assessments, providing recommendations to enhance compliance and streamline processes.
  • Advanced skills in securing NetOps and systems/network infrastructure against evolving threats.
  • Leadership in mentoring junior analysts, fostering their growth and technical expertise.
  • Strategic collaboration with SOC team members, IT staff, and stakeholders to develop coordinated threat responses.
  • Ability to contribute to cross-functional discussions and drive improvements in SOC operations.
  • Continuous Improvement and Research:
  • Commitment to staying informed on emerging threats, technologies, and best practices to enhance SOC capabilities.
  • Strategic mindset to research and recommend tools, techniques, and strategies for improved operations.
  • Ability to deliver training sessions to elevate team knowledge and preparedness.
  • Operate within a 24/7 SOC environment, which may require shift work, including nights, weekends, and holidays.
  • Handle sensitive and classified information in compliance with DoD and USSOCOM requirements.
  • Actively perform Cyber, correlate logs, report findings, and coordinate with cyber analysts to contain users/systems and initiate formal CSSP documentation.
  • Analyze network traffic logs and encrypted patterns to identify ongoing threats, anomalous behavior, command-and-control (C2) channels, active exploitation, or data exfiltration attempts.
  • Monitor NSA Pulse investigations related to USASOC assets and brief branch chiefs to coordinate mitigation while preventing duplication of effort with Cyber Analysts.
  • Coordinate with Cyber Operators for threat intelligence sharing, escalation criteria, and remediation plans.
  • Develop threat hunt playbooks based on industry findings, historical trends, or G639 requirements to systematically search for indicators of compromise.
  • Contextualize and aggregate logs between Splunk, MDE environments, and other SIE native tools for data generation.
  • Develop and refine advanced detection logic (e.g., Sigma, YARA, or Splunk SPL signatures) based on emerging TTPs to automate the identification of malicious activity.
  • Map all hunt findings and defensive gaps to the MITRE ATT&CK Framework to prioritize mission focus areas based on adversary trends.
  • Engage in "Purple Team" operations alongside adversary emulation cells to verify that security controls are effectively detecting and blocking known exploit techniques.
Qualifications
Qualifications:
  • DoD 8570 IAT II certifications AND CSSP Analyst OR CSSP Incident Responder
  • Strong understanding of cybersecurity concepts, including threat detection, malware analysis, and network security.
  • Proficiency with one or more tools such as SIEM platforms, IDS/IPS, endpoint protection solutions, and forensic analysis tools.
  • Advanced analytical and problem-solving skills with the ability to handle complex incidents and scenarios.
  • Effective communication skills, including the ability to create detailed reports and brief stakeholders.
  • Ability to work independently and lead initiatives in a fast-paced, team-oriented environment.
  • Must be DoW 8140 compliant under the Work Role Code 531 – Cyber Defense Incident Responder - Intermediate level.
Highly Desired Qualifications:
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent experience).
  • Advanced certifications such as CISSP, GIAC (e.g., GCIA, GCIH), or OSCP.
  • Experience with scripting or automation tools (e.g., Python, PowerShell) and threat hunting techniques.
  • Knowledge of advanced threat intelligence platforms and methodologies.
Education/Years of Experience:
  • Min 12 years with HS Diploma, 10 years with AS/AA degree, or 8 years with BS/BA.
Clearance Requirement:
  • A DoD security clearance at the TS/SCI level is required.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Analyst
Cybersecurity Analyst

Saic • Fayetteville (NC)

On-site
USD 110,000 - 150,000
Security Operations Center Technical Lead
Security Operations Center Technical Lead

invictusic • Colorado Springs (CO)

On-site
USD 120,000 - 180,000
SITEC - Cyber Defense Incident Responder - MacDill AFB
SITEC - Cyber Defense Incident Responder - MacDill AFB

Peraton • Tampa (FL)

On-site
USD 66,000 - 106,000
Security Operations Center Technical Lead
Security Operations Center Technical Lead

Invictus International Consulting, LLC. • Colorado Springs (CO)

On-site
USD 120,000 - 170,000
Security Operations Center Technical Lead
Security Operations Center Technical Lead

Invictus International • Colorado Springs (CO)

On-site
USD 130,000 - 180,000
Local Defender Cybersecurity SOC Analyst Threat Analyst
Local Defender Cybersecurity SOC Analyst Threat Analyst

COLSA Corporation • California

On-site
USD 180,000 - 230,000
Security Operation Center (SOC) Analyst – Level II
Security Operation Center (SOC) Analyst – Level II

TAC Integrated Solutions • United States

On-site
USD 90,000 - 130,000
Cybersecurity Watch Operations Subject Matter Expert IV
Cybersecurity Watch Operations Subject Matter Expert IV

Invictus International Consulting, LLC. • Alexandria (VA)

On-site
USD 150,000 - 190,000
SOC Analyst
SOC Analyst

Tactibit Technologies LLC. • Suitland (MD), Northern (KY)

Hybrid
USD 95,000 - 125,000
Cybersecurity Watch Operations Subject Matter Expert IV
Cybersecurity Watch Operations Subject Matter Expert IV

Invictus International • Alexandria (VA)

On-site
USD 140,000 - 180,000