SOC Analyst

DMI

Crownsville (MD)

On-site

USD 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

DMI, LLC is seeking a Security Operations Center (SOC) Analyst to monitor, detect, and analyze cybersecurity events across client environments. You will develop alarms, perform threat hunting, and support incident response activities on a 24/7 schedule.

Responsibilities include monitoring logs, enriching data, coordinating with security engineering, and preparing threat reports for clients. This onsite role requires strong communication and teamwork in a fast-moving environment.

Qualifications

  • Bachelor’s degree in a computer science, information systems, engineering or related field.
  •  
  • The candidate should have hands-on experience with intrusion events and threat analysis.

Responsibilities

  • Monitor, detect, and analyze security events and incidents.
  •  
  • Triage incidents, perform initial containment where feasible, and escalate as needed.
  •  
  • Develop SIEM correlation rules and support incident response activities.
  •  
  • Prepare management threat reports and briefings for clients.

Skills

Threat hunting
Threat detection
Incident analysis
Python scripting
PowerShell
Communication skills
Documentation
Team collaboration

Education

Bachelor's degree in computer science or related
Master's degree preferred

Tools

Wireshark
VirusTotal
Splunk
SIEM tools

Job description

DMI is a leading provider of digital services and technology solutions, headquartered in Tysons Corner, VA. With a focus on end-to-end managed IT services, including managed mobility, cloud, cybersecurity, network operations, and application development, DMI supports public sector agencies and commercial enterprises around the globe. Recognized as a Top Workplace, DMI is committed to delivering secure, efficient, and cost-effective solutions that drive measurable results. Learn more at www.dminc.com.

About The Opportunity

DMI, LLC is looking for a Security Operations Center (SOC) Analyst with hands-on experience monitoring, detecting, and analyzing threats and cybersecurity events to identify and defend against validated intrusion events. Daily work includes monitoring network and system security events, conducting threat hunting through event data and activity logs, developing alarms for suspicious or malicious activity, escalating alerts to clients, and preparing reports to summarize detected activities.

The SOC Analyst executes and helps to create operational processes for consistent monitoring of client environments and should be familiar with a variety of security tools and technologies. The SOC Analyst additionally works to support the Incident Response Team by conducting monitoring and analysis during incident management engagements.

Duties And Responsibilities
  • The shift is day, evening, or night shift.
  • Monitor, protect, and defend the enterprise perimeter against malicious network traffic.
  • Monitor, protect, and defend internal networks and hosts against ongoing and emerging threats.
  • Enrich monitoring logs with contextual operation data from functional areas, correlate events and identify security issues, threats, and vulnerabilities.
  • Conduct security event analysis and validation, triage validated incidents, perform initial containment where feasible, research incident, enrich incident case documentation, and escalate the incident for further analysis, containment, and eradication.
  • Review and analyze threat intelligence information and proactively search application, system, network logs to hunt for and thwart relevant threats identified threats.
  • Prepare and perform shift handover briefing to communicate completed and pending activities, and relay situational awareness information.
  • Contribute to the development and maintenance of SOC Standard Operating Procedures (SOPs) and Concept of Operations (CONOPS) to establish and continuously improve organization’s operating knowledge base.
  • Participate in post-incident activities and contribute to lessons learned to improve security operations.
  • Provide support in preparation of management threat reports and briefings, and recommendations.
  • Provide sound technical recommendations that enable remediation of security issues.
  • Partner with security engineering to develop and refine SIEM correlation rules.
  • Utilize advanced threat models, SIEM use cases, and incident response playbooks.
Qualifications
  • Bachelor’s degree from an accredited college or university with a major in computer science, information systems, engineering, business, or related scientific or technical disciplines. Master’s Degree is preferred.
  • CompTIA CySA+ certification/ or CompTIA Security+ (or other relevant IAT Level II/III Certification) along with one of the following:
    • CEH
    • CFR
    • CCNA Cyber Ops
    • CCNA-Security
    • GCIA
    • GCIH
    • GICSP
    • Cloud+
    • SCYBER
    • PenTest+
  • Experience analyzing intrusion events such as phishing emails, malware, privilege misuse, traffic indicating potential malicious activities such as DoS/DDoS, brute force, data loss through exfiltration/inadvertent disclosure.
  • Applied experience of threat analysis model/frameworks such as Cyber Kill Chain, MITRE ATT&CK, Diamond Model, Pyramid of Pain, etc.
  • Working knowledge of advanced threat Tactics, Techniques and Procedures (TTPs).
  • Applied experience with network traffic analysis with tools like Wireshark.
  • Applied experience with a variety of open‑source threat research tools/platforms such as Virus Total.
  • Working knowledge of network and security architecture principles such as defense‑in‑depth.
  • Experience with proprietary security protection/detections tools such as Firewall, Host and Network IDS/IPS, Anti‑Virus, EDR, URL Filtering Gateways, Email Filtering Gateways, DLP tools, and SIEM tools such as Splunk.
  • Capable of working independently, establishing priorities and managing task completion within set SLAs.
  • Able to communicate effectively through writing, speaking, and presenting to client technical representatives.
  • Team player capable of productively contributing to the client mission by supporting fellow teammates in a dynamic growing and changing environment.
Desired Skills And Qualifications
  • Experience with mid‑to‑advanced level malware analysis.
  • Experience creating detailed queries and scripts, such as regular expressions, for log, event and correlation analysis.
  • Experience scripting in Python, PowerShell, VBScript.
Background Requirements

Successful completion of a Fingerprint background investigation.

Citizenship Status Required

Must be a U.S. Citizen.

Physical Requirements

None required for this position.

Location

Crownsville, MD (100% onsite).

Day Shift/Night Shift

Day Shift/Night Shift.

Applicants selected may be subject to a government security investigation and must meet eligibility requirements for access to classified information. US citizenship may be required for some positions.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Analyst, Security Operations Center (SOC) Analyst
Cybersecurity Analyst, Security Operations Center (SOC) Analyst

Digital Global Connectors • McLean (VA)

Hybrid
USD 70,000 - 110,000
Cybersecurity Analyst, Security Operations Center (SOC) Analyst
Cybersecurity Analyst, Security Operations Center (SOC) Analyst

Digital-Global-Connectors • McLean (VA)

Hybrid
USD 90,000 - 130,000
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

10xTalents • Washington

On-site
USD 80,000 - 110,000
SOC Analyst 2
SOC Analyst 2

Mbi Llc • Harrisburg

On-site
USD 60,000 - 90,000
SOC Analyst
SOC Analyst

NTG • Alexandria (VA)

On-site
USD 85,000 - 125,000
Cyber Network Defense Analyst
Cyber Network Defense Analyst

Base One Technologies • Washington

Hybrid
USD 65,000 - 85,000
Mid Level SOC Operations Analyst with Security Clearance
Mid Level SOC Operations Analyst with Security Clearance

Cintel, Inc. • Huntsville (AL)

On-site
USD 75,000 - 95,000
Mid-Level SOC Analyst - Hybrid
Mid-Level SOC Analyst - Hybrid

International Executive Service Corps • Alexandria (VA)

Hybrid
USD 68,000 - 92,000
Competitive benefits
Information Security Advisor
Information Security Advisor

NTT DATA, Inc. • Merrifield (VA)

On-site
USD 100,000 - 130,000
Security Operations Center Analyst — Threat Hunter
Security Operations Center Analyst — Threat Hunter

DMI • Crownsville (MD)

On-site
USD 90,000 - 130,000