Cybersecurity Analyst, Security Operations Center (SOC) Analyst

Digital-Global-Connectors

McLean (VA)

Hybrid

USD 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Digital Global Connectors (DGC) seeks a Cybersecurity Analyst – Tier 1 (SOC Analyst) to monitor, analyze, and respond to cybersecurity events within a federal program. The role requires collaboration with Tier 2 responders and security engineers to maintain enterprise security posture and timely reporting.

The ideal candidate has 2+ years in a SOC, strong analytical skills, and experience with SIEM/EDR/XDR tools, plus a willingness to operate in a hybrid environment in Bethesda, MD or

Qualifications

  • Bachelor's degree in cybersecurity, computer science, IT, information systems, or a related field.
  • Minimum two years supporting cybersecurity operations or an SOC.
  • Experience monitoring SIEM, EDR, or related security technologies.
  • Understanding of networking concepts, operating systems, and attack techniques.
  • Experience documenting security events and supporting investigations.
  • Strong analytical, organizational, and communication skills.

Responsibilities

  • Monitor enterprise security monitoring platforms for events and alerts.
  • Analyze security events to determine severity, priority, and impact.
  • Escalate suspicious activity for advanced investigation.
  • Maintain monitoring across networks, systems, endpoints, and cloud.
  • Support Tier 2 responders and collect preliminary evidence.
  • Create and maintain incident tickets and documentation.
  • Prepare incident reports and logs; assist in post-incident reviews.
  • Coordinate with engineers, ISSOs, and stakeholders.
  • Stay current with threats and refine detection rules.

Skills

SOC operations
Security Monitoring
Analytical skills
Communication skills

Education

Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related discipline

Tools

Microsoft Sentinel
Splunk Enterprise Security
Microsoft Defender XDR
Microsoft Defender for Endpoint
Microsoft Defender for Identity
Microsoft Defender for Cloud
CrowdStrike Falcon
Palo Alto Cortex XDR
Trellix
Cisco Secure
SIEM
EDR
XDR

Job description

Cybersecurity Analyst – Tier 1 (Security Operations Center Analyst)

Location: Bethesda, MD (Hybrid; On‑site as Required)

Clearance: Tier 2 Public Trust (Required)

Employment Type: Full‑Time

Position Summary

Digital Global Connectors (DGC) is seeking a motivated Cybersecurity Analyst – Tier 1 (Security Operations Center Analyst) to support a Federal information security program. The Tier 1 SOC Analyst serves as the first line of defense in monitoring, detecting, analyzing, documenting, and escalating cybersecurity events affecting enterprise information systems and networks.

This position is responsible for continuous monitoring of security tools, initial incident triage, alert validation, event correlation, ticket management, and coordination with higher‑tier cybersecurity personnel. The analyst helps identify potential threats, supports incident response activities, and contributes to maintaining a strong enterprise cybersecurity posture through proactive monitoring and timely reporting.

The successful candidate will possess strong analytical skills, experience working within a Security Operations Center (SOC), and a solid understanding of cybersecurity principles, network operations, and security monitoring technologies.

Essential Duties and Responsibilities:
Security Monitoring
  • Monitor enterprise security monitoring platforms for cybersecurity events and alerts.
  • Identify, review, and validate potential security incidents.
  • Analyze security events to determine severity, priority, and potential business impact.
  • Continuously monitor enterprise networks, systems, endpoints, cloud environments, and applications.
  • Escalate suspicious activity requiring advanced investigation.
  • Maintain situational awareness of the organization's security posture.
Event Analysis and Triage
  • Perform initial analysis of security alerts generated by SIEM, EDR, IDS/IPS, and other security technologies.
  • Correlate alerts from multiple security platforms.
  • Distinguish false positives from legitimate security events.
  • Categorize and prioritize security events based on established procedures.
  • Document findings and recommended actions.
  • Initiate incident response procedures when appropriate.
Incident Response Support
  • Support Tier 2 Incident Responders during security investigations.
  • Collect preliminary evidence supporting incident analysis.
  • Preserve relevant logs and security artifacts.
  • Assist with containment activities under senior analyst guidance.
  • Update incident records throughout the investigation lifecycle.
  • Participate in post‑incident documentation and lessons learned.
Security Tool Operations

Operate and monitor technologies including:

  • Microsoft Sentinel
  • Splunk Enterprise Security
  • Microsoft Defender XDR
  • Microsoft Defender for Endpoint
  • Microsoft Defender for Identity
  • Microsoft Defender for Cloud
  • CrowdStrike Falcon
  • Palo Alto Cortex XDR
  • Trellix
  • Cisco Secure
  • Security Information and Event Management (SIEM)
  • Endpoint Detection and Response (EDR)
  • Extended Detection and Response (XDR)
  • Intrusion Detection and Prevention Systems (IDS/IPS)

Assist in identifying operational issues affecting monitoring platforms and coordinate with engineering teams as needed.

Threat Detection
  • Monitor indicators of compromise (IOCs) and indicators of attack (IOAs).
  • Identify suspicious user activity, anomalous network behavior, and unauthorized access attempts.
  • Recognize malware infections, phishing attempts, credential misuse, and policy violations.
  • Review threat intelligence provided by internal and external sources.
  • Support implementation of updated detection rules and monitoring use cases.
Ticket and Case Management
  • Create, update, and maintain incident tickets.
  • Document investigation activities, findings, and recommendations.
  • Track incidents through resolution.
  • Ensure complete and accurate case documentation.
  • Escalate unresolved issues according to established procedures.
  • Maintain audit‑ready documentation supporting security operations.
Reporting and Documentation

Develop and maintain:

  • Incident Reports
  • Alert Summaries
  • Daily Operations Reports
  • Shift Handover Reports
  • Security Event Logs
  • Investigation Notes
  • Trend Reports
  • Metrics Dashboards
  • Lessons Learned Documentation
  • Standard Operating Procedures

Ensure documentation is complete, accurate, and supports operational continuity.

Collaboration
  • Coordinate with Tier 2 Incident Responders, Threat Hunters, Security Engineers, ISSOs, Vulnerability Management personnel, and technical support teams.
  • Participate in operational briefings and shift turnover meetings.
  • Communicate security findings clearly to technical and non‑technical stakeholders.
  • Support cross‑functional cybersecurity initiatives.
  • Maintain effective working relationships across cybersecurity disciplines.
Continuous Improvement
  • Stay current with emerging cyber threats, attack techniques, and defensive technologies.
  • Recommend improvements to monitoring procedures and operational workflows.
  • Participate in tabletop exercises, incident response drills, and training events.
  • Assist in refining detection logic and operational playbooks.
  • Pursue professional development and relevant cybersecurity certifications.
Minimum Qualifications
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related discipline.
  • Minimum two (2) years of experience supporting cybersecurity operations or a Security Operations Center (SOC).
  • Experience monitoring SIEM, EDR, or related cybersecurity technologies.
  • Understanding of networking concepts, operating systems, common attack techniques, and cybersecurity fundamentals.
  • Experience documenting security events and supporting incident investigations.
  • Strong analytical, organizational, and communication skills.
  • Ability to work rotating shifts, evenings, weekends, holidays, or on‑call schedules as required.
  • U.S. Citizenship required.
  • Ability to obtain and maintain a Tier 2 Public Trust.
Preferred Qualifications
  • Experience supporting a Federal civilian agency.
  • Experience using Microsoft Sentinel, Splunk Enterprise Security, Microsoft Defender XDR, or comparable enterprise security platforms.
  • Experience supporting incident response or vulnerability management activities.
  • Familiarity with the MITRE ATT&CK Framework.
  • CompTIA Security+
  • CompTIA CySA+
  • GIAC Security Essentials (GSEC)
  • Microsoft Certified: Security Operations Analyst Associate (SC‑200)
  • Splunk Core Certified User or Power User
  • Cisco CyberOps Associate (preferred)
Knowledge, Skills, and Abilities
  • Security Operations Center (SOC) Operations
  • Security Monitoring
  • Security Information and Event Management (SIEM)
  • Microsoft Sentinel
  • Splunk Enterprise Security
  • Endpoint Detection and Response (EDR)
  • Extended Detection and Response (XDR)
  • Microsoft Defender XDR
  • Microsoft Defender for Endpoint
  • Microsoft Defender for Cloud
  • Incident Triage
  • Event Correlation
  • Log Analysis
  • Threat Detection
  • Malware Identification
  • Phishing Analysis
  • Network Security
  • TCP/IP
  • Windows Security
  • Linux Security
  • MITRE ATT&CK Framework
  • NIST Cybersecurity Framework
  • NIST Risk Management Framework (RMF)
  • Ticket Management
  • Technical Documentation
  • Microsoft Office Suite
  • ServiceNow
  • Jira
Security Requirements
  • Ability to successfully obtain and maintain a Tier 2 Public Trust investigation.
  • Compliance with all applicable Federal security, privacy, ethics, and information assurance training requirements before receiving system access.
  • Ability to support 24x7 cybersecurity operations, emergency response activities, scheduled maintenance windows, continuity of operations (COOP), and surge support as required.
  • Must maintain strict confidentiality while handling sensitive security events, log data, investigation records, and Federal information systems.
  • Ability to work effectively in a fast‑paced Security Operations Center environment while providing timely monitoring, accurate incident documentation, and responsive support to Government stakeholders and cybersecurity teams.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Analyst, Security Operations Center (SOC) Analyst
Cybersecurity Analyst, Security Operations Center (SOC) Analyst

Digital Global Connectors • McLean (VA)

Hybrid
USD 70,000 - 110,000
Cybersecurity Analyst, Incident Responder
Cybersecurity Analyst, Incident Responder

Digital-Global-Connectors • McLean (VA)

Hybrid
USD 110,000 - 150,000
Cybersecurity Analyst, Incident Responder
Cybersecurity Analyst, Incident Responder

Digital Global Connectors • McLean (VA)

Hybrid
USD 90,000 - 130,000
Cyber Threat Intelligence Analyst
Cyber Threat Intelligence Analyst

Digital Global Connectors • McLean (VA)

Hybrid
USD 120,000 - 170,000
Senior Security Analyst – Security Operations Center
Senior Security Analyst – Security Operations Center

Jobtailor • Town of Florida (NY)

On-site
USD 120,000 - 180,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Ampcus Inc • Washington

On-site
USD 90,000 - 120,000
SOC Analyst
SOC Analyst

Tactibit • Suitland (MD)

On-site
USD 85,000 - 110,000
Security Operation Center (SOC) Analyst II
Security Operation Center (SOC) Analyst II

General Dynamics Information Technology • Colorado Springs (CO)

On-site
USD 112,000 - 138,000
Medical plan options
Dental and Vision plan options
401(k) plan with company match
SOC Analyst - Tier 1
SOC Analyst - Tier 1

Evans & Chambers • Maryland

On-site
USD 88,000 - 118,000
SOC Analyst - Tier 1
SOC Analyst - Tier 1

Evans & Chambers • Fort Meade (MD)

On-site
USD 88,000 - 118,000