Local Defender - Cybersecurity (SOC Analyst & Threat Analyst)

Colsa-5

California

On-site

USD 139,000 - 150,000

Full time

41 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

COLSA Corporation in San Miguel, California, seeks a Local Defender - Cybersecurity (SOC Analyst & Threat Analyst) to protect critical assets. You will monitor logs, analyze incidents, review CVEs, and implement CTO-driven mitigations in a demanding, on-site environment.

The role requires a DoD Secret clearance (Top Secret eligibility preferred), 12+ years of cybersecurity experience including SOC work, and proficiency with SIEM, threat intel, and OT sensors.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field
  • 12+ years of work experience including 2+ years in SOC/cybersecurity
  • CompTIA Security+ certification (DOD 8140 IAT Level II)
  • Active DoD Secret Security Clearance with eligibility for Top Secret
  • Proficient in analyzing security events/logs/alerts from SIEM, firewalls, IDS/IPS
  • Familiarity with CVEs, MITRE ATT&CK, and vulnerability management
  • Knowledge of NETCOM policies and CTOs
  • Strong analytical and problem-solving skills
  • Willingness to travel CONUS/OCONUS

Responsibilities

  • Monitor security events and alerts from SIEM, firewalls, IDS/IPS, and EDR to identify threats
  • Perform basic sensor-related system administration tasks
  • Analyze OT sensor data for trends and health reporting
  • Investigate security incidents to determine scope, root cause, and remediation
  • Triage incidents and recommend mitigations
  • Review SIEM reports for patterns and vulnerabilities
  • Develop actionable mitigation recommendations based on SIEM data
  • Escalate incidents with detailed summaries to leadership
  • Maintain documentation of security events and procedures
  • Ensure CTO compliance and timely mitigations
  • Collaborate with government customer to integrate threat intelligence
  • Produce leadership reports with threats and remediation steps
  • Support configuration and tuning of monitoring tools

Skills

Analytical skills
Problem solving
SIEM analysis
Python
PowerShell
Threat intelligence
CTO knowledge

Education

Bachelor's degree in Cybersecurity/CS/IT or related field
CompTIA Security+ (DOD 8140 IAT Level II)

Tools

Dragos OT Sensor Equipment
OT Tenable

Job description

Local Defender - Cybersecurity (SOC Analyst & Threat Analyst)
Tracking Code

9762-987

Posted Date

9/3/2026

Job Location

San Miguel, California

Location of Position

San Miguel, California

Work Arrangement

On Site: 100%

Position Type

Full-Time/Regular

Clearance Required?

Yes

Level of Clearance Required

Secret

The Local Defender is a critical cybersecurity role responsible for protecting the organization's digital assets through proactive monitoring, analysis, and response to cyber threats. This role combines the duties of a Security Operations Center (SOC) Analyst and Threat Analyst to ensure an holistic defense against emerging threats. Key responsibilities include monitoring security logs, analyzing and reporting cyber incidents, reviewing Common Vulnerabilities and Exposures (CVEs), and implementing directives from NETCOM (e.g., Cyber Tasking Orders – CTO). Work is performed on-site with occasional on-call duties for critical incidents in a collaborative, demanding environment requiring attention to emerging threats and vulnerabilities.

The preferred candidate will be well-versed in common cyber threats, vulnerabilities, and adversarial tactics, techniques, and procedures (TTPs). In this role, the candidate is expected to work with minimal guidance, in a cross-functional team, ensuring reports and recommendations are effectively communicated and actioned to support the Government customer and mission requirements.

Principal Duties and Responsibilities (Essential functions):

  • Monitor and analyze security events and alerts generated by SIEM platforms, firewalls, IDS/IPS, and endpoint detection tools to identify potential threats and anomalous behavior.
  • Perform basic system administration functions on the sensor capability systems and components, such as applying patches and updates if touch labor is required.
  • Analyze data from installed OT sensors to identify patterns and trends and assist with the reports generated regarding system performance and health.
  • Diagnose and resolve issues related to sensor data, including malfunctioning sensors, communication problems, and data integrity problems if necessary.
  • Analyze potential security incidents and investigate to determine the scope, impact, root cause, and recommend effective remediation strategies.
  • Perform triage on security incidents to identify root causes and recommend appropriate mitigation measures.
  • Conduct regular reviews of SIEM reports to identify patterns, trends, and potential vulnerabilities within the organization's infrastructure.
  • Develop actionable recommendations based on SIEM data analysis to enhance detection capabilities, optimize alert configurations, and address identified gaps.
  • Escalate critical incidents to senior leadership or appropriate teams and provide detailed incident summaries with proposed mitigation actions.
  • Maintain accurate documentation of security events and incident-handling procedures.
  • Monitor and evaluate Cyber Tasking Orders (CTOs) and other directives from NETCOM, ensuring compliance and timely implementation of mitigations.
  • Conduct research on the latest organization’s environment threat vectors, attack methodologies, and adversarial tactics, techniques, and procedures (TTPs).
  • Collaborate with other cybersecurity team members and the government customer to integrate threat intelligence into incident detection and response processes.
  • Analyze CVEs, security bulletins, threat intelligence feeds, and security advisories to assess their relevance and potential impact to the mission and the organization’s environment.
  • Correlate threat intelligence with SIEM findings to identify and assess emerging threats.
  • Develop and communicate proactive mitigation strategies based on threat landscape trends and adversary tactics.
  • Generate detailed and actionable reports for leadership from SIEM platforms summarizing identified threats, incidents, and remediation steps.
  • Provide recommendations for improving the organization’s cybersecurity posture based on incident trends and threat intelligence.
  • Maintain clear communication with cross-functional teams to ensure alignment with security objectives and protocols.
  • G enerate detailed reports on threats, false positives, and actionable insights.
  • P rovide the Government customer and leadership with concise, data-driven recommendations for enhancing the organization’s cybersecurity defenses based on SIEM trends and incident analysis.
  • Prepare summaries and status updates of security posture improvements resulting from SIEM data analysis and implemented recommendations.
  • Support the configuration, tuning, and optimization of security monitoring tools, including SIEM and threat detection platforms.
  • Work with the team to improve the accuracy, reliability, and efficiency of OT sensor data collection and analysis.
  • Conduct periodic reviews and updates of security tools to address gaps or inefficiencies.
  • Participate in the testing and implementation of new security technologies as required.
  • Collaborate with the team and the stakeholder community to fine-tune SIEM configurations, including custom rule creation and log source integration, to improve threat detection accuracy.
  • Conduct periodic evaluations of SIEM and related tools, providing recommendations for feature enhancements or additional capabilities.
  • Support the testing and deployment of security solutions to ensure seamless integration with the existing monitoring infrastructure.

At COLSA, people are our most valuable resource and centered at our core value. We invite you to unite your talents with opportunity and be a part of our “Family of Professionals!” Learn about our employee-centric culture and benefits here: https://www.colsa.com/culture_benefits

Required Experience
  • Bachelor's degree preferably in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent experience).
  • Minimum of 12 plus years of work related experience including 2+ years of experience in a SOC, cybersecurity, or related role.
  • Must have a minimum of a CompTIA Security+ certification or equivalent (DOD 8140 IAT Level II).
  • Active DoD Secret Security Clearance with the ability to obtain a Top Secret Security Clearance; US Citizenship required.
  • Proficiency in analyzing security events, logs, and alerts from various security tools (e.g., SIEM, firewalls, IDS/IPS).
  • Familiarity with CVEs, threat intelligence frameworks (e.g., MITRE ATT&CK), and vulnerability management practices.
  • Knowledge of NETCOM policies, Cyber Tasking Orders (CTOs), and cybersecurity compliance requirements.
  • Strong analytical and problem-solving skills with attention to detail.
  • May require CONUS and/or OCONUS travel to customer sites.

Preferred Qualifications:

  • Either a GIAC Penetration Tester (GPEN) or Offensive Security Certified Professional (OSCP) certification.
  • Experience with scripting languages (e.g., Python, PowerShell) for automating security tasks.
  • Previous experience with Dragos OT Sensor Equipment Preferred.
  • Previous experience with OT Tenable Preferred.
  • Understanding of advanced threat detection methodologies and incident response processes.
  • E xcellent verbal and written communication skills for creating technical reports and presentations.

Applicant selected will be subject to a government security investigation and must meet eligibility requirements for access to classified information. COLSA Corporation is an Equal Opportunity Employer, Minorities/Females/Veterans/Disabled. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, or national origin.

Minimum Salary

$139,000.00

Maximum Salary

$150,000.00

Salary Type

Annually

The salary range, if referenced, represents a good faith estimate. COLSA considers various factors when determining base salary offers, but not limited to, location, the role, function and associated responsibilities, a candidate’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements.

COLSA offers a comprehensive and customizeable benefits program which includes Medical, Dental, Vision, Life Insurance, Short-Term Disability, Long-Term Disability, Accidental Death & Dismemberment, Supplemental Income Protection Programs, 401(k) with company match, Flexible Spending Accounts, Employee Assistance Program, Education & Certification Reimbursement, Employee Discount Program, Paid Time Off and Holidays.

This position will be posted for a minimum of 3 business days. If a candidate has not been selected at that time, it will continue to be posted until a suitable candidate is selected or the position is closed.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Local Defender - Cybersecurity (SOC Analyst & Threat Analyst)
Local Defender - Cybersecurity (SOC Analyst & Threat Analyst)

Colsa • Northern (KY)

Hybrid
USD 139,000 - 150,000
Medical benefits
401(k) with company match
Paid time off
Local Defender - Cybersecurity (SOC Analyst & Threat Analyst)
Local Defender - Cybersecurity (SOC Analyst & Threat Analyst)

Colsa-5 • Concord (CA)

On-site
USD 139,000 - 150,000
Medical coverage
401(k) with company match
Paid time off
Local Defender - Cybersecurity (SOC Analyst & Threat Analyst)
Local Defender - Cybersecurity (SOC Analyst & Threat Analyst)

COLSA • Concord (CA)

On-site
USD 139,000 - 150,000
Medical
Dental
Vision
+6
Local Defender Cybersecurity SOC Analyst Threat Analyst
Local Defender Cybersecurity SOC Analyst Threat Analyst

COLSA Corporation • California

On-site
USD 180,000 - 230,000
Cybersecurity Operations Analyst (CSSP)
Cybersecurity Operations Analyst (CSSP)

Colsa • Huntsville (AL)

On-site
USD 90,000 - 130,000
Cybersecurity Operations Analyst (CSSP)
Cybersecurity Operations Analyst (CSSP)

Colsa-5 • Huntsville (AL)

On-site
USD 90,000 - 120,000
Medical
Dental
Vision
+3
OT/ICS Analyst
OT/ICS Analyst

Colsa-5 • Huntsville (AL)

On-site
USD 95,000 - 130,000
Medical, Dental, Vision insurance
401(k) with company match
Paid time off
Cybersecurity Analyst IAM I (Basic)
Cybersecurity Analyst IAM I (Basic)

COLSA • Dahlgren (VA)

On-site
USD 100,000 - 110,000
Medical, Dental, Vision
401(k) with company match
Paid Time Off
Cybersecurity Program Manager
Cybersecurity Program Manager

Colsa-5 • Albany (GA)

On-site
USD 110,000 - 160,000
Medical benefits
Dental benefits
Vision benefits
+6
Cybersecurity Program Manager
Cybersecurity Program Manager

COLSA • Albany (GA)

On-site
USD 120,000 - 180,000