Security Operations Center Cyber Analyst

Arcfield

Newport (RI)

On-site

USD 64,000 - 112,000

Full time

8 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health Insurance
Life Insurance
Paid Time Off
Holiday Pay
Disability Insurance (Short/Long Term)
Retirement and Savings

Job summary

Arcfield is seeking a Security Operations Center professional in the United States to monitor and analyze security events with Splunk and Airlock Digital, investigate alerts, and coordinate incident response. The role emphasizes threat detection, analytics development, and cross-domain logs interpretation.

Candidates should have strong SIEM/XDR experience, AD and Windows Server knowledge, and a DoD clearance.

Qualifications

  • BS 2-4 Years, MS 0-2 6+ Years experience in Security Operations Center processes and using SIEM and XDR tools
  • Security Operations Center Analyst: Understand and respond to security detections in a SIEM adhering to Incident Response Processes. Ability to collect relevant information from network and host logs, correlate events together to develop incident timelines and deduce root cause. Collaborate with ISSOs and engineers/developers/admins to resolve security incidents
  • Strong background in Security Compliance & Vulnerability Management. Familiarity with adhering to Cybersecurity Standard Operating Procedures, ability to review and update SOP documents for clarity and accuracy.
  • Prior experience with deploying enterprise tools on Domain Computers, including Antivirus, endpoint protection, and vulnerability scanning
  • Proficient in Active Directory (AD) & Domain Controller (DC) Administration
  • Knowledge of Windows Server Administration, including Windows Server 2019/2022/2025 internals, registry, event logs, and system services
  • Experience with Windows security baselines (CIS, DISA STIG)
  • CompTIA Security+ CE
  • Active Secret DoD Security Clearance required for this role

Responsibilities

  • Monitor and analyze security events in Splunk and Airlock Digital. Analyst on Duty: Investigate alerts that are triggered in the Splunk Console to determine if a threat or normal activity is allowed in the environment.
  • Provide threat detection and incident response to mitigate risks to the Network
  • Security Detection Engineering: troubleshoot, improve and develop security detection analytics. able to determine detection gaps and draft analytics to correct them
  • Experience in interpreting activity to determine what is malicious vs expected from a variety of sources such as Windows and Linux workstations and servers, Firewall, Switch, Router, Endpoint Security, Wireless Intrusion Detection, and other security and application logs Proficiency in scripting languages (PowerShell, Python, Bash, etc.)

Skills

Scripting languages
PowerShell
Python
Bash
Threat detection
Incident response

Education

Bachelor's degree
Master's degree

Tools

Splunk
Airlock Digital
SIEM
XDR

Job description

  • Monitor and analyze security events in Splunk and Airlock Digital. Analyst on Duty: Investigate alerts that are triggered in the Splunk Console to determine if a threat or normal activity is allowed in the environment.
  • Provide threat detection and incident response to mitigate risks to the Network
  • Security Detection Engineering: troubleshoot, improve and develop security detection analytics. able to determine detection gaps and draft analytics to correct them
  • Experience in interpreting activity to determine what is malicious vs expected from a variety of sources such as Windows and Linux workstations and servers, Firewall, Switch, Router, Endpoint Security, Wireless Intrusion Detection, and other security and application logs Proficiency in scripting languages (PowerShell, Python, Bash, etc.)
Responsibilities
  • Monitor and analyze security events in Splunk and Airlock Digital. Analyst on Duty: Investigate alerts that are triggered in the Splunk Console to determine if a threat or normal activity is allowed in the environment.
  • Provide threat detection and incident response to mitigate risks to the Network
  • Security Detection Engineering: troubleshoot, improve and develop security detection analytics. able to determine detection gaps and draft analytics to correct them
  • Experience in interpreting activity to determine what is malicious vs expected from a variety of sources such as Windows and Linux workstations and servers, Firewall, Switch, Router, Endpoint Security, Wireless Intrusion Detection, and other security and application logs Proficiency in scripting languages (PowerShell, Python, Bash, etc.)
Qualifications
  • BS 2-4 Years, MS 0-2 6+ Years experience in Security Operations Center processes and using SIEM and XDR tools
  • Security Operations Center Analyst: Understand and respond to security detections in a SIEM adhering to Incident Response Processes. Ability to collect relevant information from network and host logs, correlate events together to develop incident timelines and deduce root cause. Collaborate with ISSOs and engineers/developers/admins to resolve security incidents
  • Strong background in Security Compliance & Vulnerability Management. Familiarity with adhering to Cybersecurity Standard Operating Procedures, ability to review and update SOP documents for clarity and accuracy.
  • Prior experience with deploying enterprise tools on Domain Computers, including Antivirus, endpoint protection, and vulnerability scanning
  • Proficient in Active Directory (AD) & Domain Controller (DC) Administration
  • Knowledge of Windows Server Administration, including Windows Server 2019/2022/2025 internals, registry, event logs, and system services
  • Experience with Windows security baselines (CIS, DISA STIG)
  • CompTIA Security+ CE
  • Active Secret DoD Security Clearance required for this role
Equal Pay Act

This is the projected compensation range for this position. There are differentiating factors that can impact a final salary/hourly rate, including, but not limited to, Contract Wage Determination, relevant work experience, skills and competencies that align to the specified role, geographic location (For Remote Opportunities), education and certifications as well as Federal Government Contract Labor categories. In addition, Arcfield invests in its employees beyond just compensation. Arcfield ’s benefits offerings include, dependent upon position, Health Insurance, Life Insurance, Paid Time Off, Holiday Pay, Short Term and Long-Term Disability, Retirement and Savings, Learning and Development opportunities, wellness programs as well as other optional benefit elections. Min: $64,252.03 Max: $111,721.81

EEO Statement

We are an equal opportunity employer and federal government contractor. We do not discriminate against any employee or applicant for employment as protected by law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

On-site
USD 97,600 - 109,800
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
External Job Posting Title Cyber Monitoring Signature Analyst
External Job Posting Title Cyber Monitoring Signature Analyst

Peraton • Beltsville (MD)

On-site
USD 80,000 - 128,000
Cyber Monitoring Signature Analyst
Cyber Monitoring Signature Analyst

Peraton • Beltsville (MD)

On-site
USD 80,000 - 128,000
Senior Security Analyst
Senior Security Analyst

Yardi • Santa Barbara (CA)

On-site
USD 97,600 - 109,800
Remote SOC Cyber Analyst: Threat Detection & Incident Response
Remote SOC Cyber Analyst: Threat Detection & Incident Response

Arcfield • Newport (RI)

On-site
USD 64,000 - 112,000
Health Insurance
Life Insurance
Paid Time Off
+3
Network Security Analyst 2
Network Security Analyst 2

Ampcus, Inc • Austin (TX)

On-site
USD 90,000 - 130,000
Cyber Data Scientist
Cyber Data Scientist

Arcfield • Virginia (MN)

On-site
USD 137,000 - 238,000
Health Insurance
Life Insurance
Paid Time Off
+5
Cyber Threat Analyst (I&W) with Splunk and Analyst
Cyber Threat Analyst (I&W) with Splunk and Analyst

Peraton • Arlington (VA)

On-site
USD 104,000 - 166,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Defensive Cybersecurity Analyst
Defensive Cybersecurity Analyst

Leidos • Town of Whitehall (NY)

On-site
USD 70,000 - 126,000