Security Operations Center Analyst

Everwatch

Corridor North (MD)

On-site

USD 79,000 - 93,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

EverWatch seeks a Security Operations Center Analyst to join its defense-focused team in the Maryland corridor. You will analyze logs, threat intel, and forensic data to identify advanced threats and coordinate incident response for critical government missions.

Applicants should have SIEM experience (Splunk), networking basics, and proficiency with Linux CLI, Nessus, and firewall configurations. TS/SCI with polygraph is required or eligible.

Qualifications

  • Experience with SIEM fundamentals and Splunk.
  • Networking fundamentals and log analysis skills.
  • Experience reviewing Nessus scans and firewall configurations.
  • Proficient with Linux hosts and CLI navigation.
  • TI/IR experience and TS/SCI with polygraph is required or strong eligibility.

Responsibilities

  • Analyze logs, forensic data, and threat intel to identify advanced threats.
  • Perform advanced threat identification and complex incident response.
  • Advise on gaps and hardening to protect networks.
  • Collaborate with customer networks to stop adversaries.

Skills

SIEM fundamentals
Networking fundamentals
Linux CLI
Log analysis
Incident response
Threat intelligence

Education

HS diploma or GED + 6+ yrs IR
Bachelor's degree + 2+ yrs IR

Tools

Splunk
Bro/Zeek
Suricata
Snort
Nessus
Firewall configurations

Job description

Job Title

Security Operations Center Analyst

Overview

EverWatch is a government solutions company providing advanced defense, intelligence, and deployed support to our country’s most critical missions. We are a full-service government solutions company. Harnessing the most advanced technology and solutions, we strengthen defenses and control environments to preserve continuity and ensure mission success.

EverWatch employees are focused on tackling the most difficult challenges of the US Government. We offer the best salaries and benefits packages in our industry - to identify and retain the top talent in support of our critical mission objectives.

Commitment to Non-Discrimination:

All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.

Responsibilities

Are you ready to take a strategic role in cyber defense for U.S Cyber Command? Do you want to use your experience-based knowledge to protect critical warfighter infrastructure from the constant onslaught of cyber threats? If you want a position that uses your extensive threat analysis skills to perform advanced threat identification and complex incident response, you want to be a SOC analyst. As an analyst on our SOC team, you’ll analyze logs, forensic data, and threat intelligence to find the advanced threats that are escaping detection. Using your deep understanding of your customer’s networks, combined with your cybersecurity experience, you’ll analyze patterns to understand attackers’ goals and stop them from succeeding. Once you find the adversary in the SEIM’s blind spot, you’ll advise on ways to close the gaps and harden their network. Let’s outsmart malicious actors and protect U.S. Cyber Command.

Join us. The world can’t wait.

Qualifications

You Have:

  • Experience with SIEM Fundamentals, including Splunk

  • Knowledge of basic networking fundamentals

  • Knowledge of the basic functions and configurations of Bro (Zeek)

  • Knowledge of Suricata or Snort

  • Ability to review Nessus scans and Firewall configurations

  • Ability to review Linux hosts for indicators of compromise and hardening of Linux systems

  • Ability to navigate *nix based systems via CLI

  • Ability to find, read, and analyze various logs

  • TS/SCI clearance with a polygraph

  • HS diploma or GED and 6+ years of experience with incident response procedures and analysis, or Bachelor's degree and 2+ years of experience with incident response procedures and analysis

Nice If You Have:

  • Experience with correlating threat intelligence (INTEL) to determine the threat actor, the attack's scope, and the affected systems

  • Experience with AI Fundamentals

  • Knowledge of Splunk Phantom or SOAR

Clearance:Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; TS/SCI clearance with polygraph is required.

Compensation at EverWatch is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $57.69 to $67.30 per hour. The estimate displayed represents the typical compensation range for this position and is just one component of EverWatch’s total compensation package for employees.

Job Locations

US-MD-Annapolis Junction

Skills

cyber threat, SIEM, Networking, suricata, snort, Linux, *nix

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Center Analyst
Security Operations Center Analyst

EverWatch • Maryland

On-site
USD 79,000 - 92,000
Job Posting Title Digital Network Exploitation Analyst
Job Posting Title Digital Network Exploitation Analyst

EverWatch Corporation • Annapolis (MD)

On-site
Systems Analyst
Systems Analyst

Everwatch • Aurora (CO)

On-site
USD 104,352,000 - 151,580,000
Network Exploitation Analyst
Network Exploitation Analyst

EverWatch • Maryland

On-site
Job Posting Title Network Engineer, Senior
Job Posting Title Network Engineer, Senior

EverWatch Corporation • Annapolis (MD)

On-site
Job Posting Title Systems Engineer, Senior
Job Posting Title Systems Engineer, Senior

EverWatch Corporation • Annapolis (MD)

On-site
USD 113,000 - 132,000
SIGINT Development Analyst
SIGINT Development Analyst

EverWatch • Maryland

On-site
Job Posting Title SIGINT Development Analyst
Job Posting Title SIGINT Development Analyst

EverWatch Corporation • Annapolis (MD)

On-site
Job Posting Title Network Engineer
Job Posting Title Network Engineer

EverWatch Corporation • Annapolis (MD)

On-site
Information Systems Security Officer, Senior
Information Systems Security Officer, Senior

EverWatch • Maryland

On-site