SOC Analyst

Koniag Government Services

Durham (NC)

On-site

USD 70,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
401K with company matching
Flexible spending accounts
Paid holidays
Three weeks paid time off

Job summary

Tuknik Government Services, LLC, a Koniag Government Services company, seeks a SOC Analyst to support our government customer in Durham, NC. The role involves 24/7/365 monitoring and analysis of security event alerts across the enterprise network, with a Public Trust clearance.

You will review alerts, investigate incidents using the agency's ticketing platform, and generate reports for the federal customer.

Qualifications

  • Minimum 2–4 years of analyst experience in a SOC or similar environment.
  • Experience with SOC tools to detect intrusion attempts.
  • Experience creating custom intrusion signatures to detect network traffic anomalies.
  • Experience populating sensors with new signatures in response to events.

Responsibilities

  • Provide 24/7/365 monitoring and analysis of security event alerts across the enterprise network.
  • Monitor agency systems and logs to identify potential security threats.
  • Review alerts, investigate, and ticket identified threats using the incident response platform.
  • Prioritize alerts and respond promptly according to procedures.
  • Validate traffic as anomalous per agency standards.
  • Identify and escalate threats to senior resources when needed.
  • Produce contractual and ad hoc reports for the federal customer.
  • Provide data for inclusion in the agency's CISA report.

Skills

SOC monitoring
Threat analysis
Incident response
Ticket management
English communication

Education

High School Diploma with cybersecurity training
BS/BA preferred

Tools

ServiceNow
CAPRS
Microsoft 365 tools
Windows OS

Job description

Tuknik Government Services, LLC, a Koniag Government Services company, is seeking a SOC Analyst to support TGS and our government customer in Durham, NC. This position requires the candidate to be able to obtain a Public Trust.

We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.

The ideal candidate will be able to obtain a Public Trust Clearance. This position involves providing 24/7/365 monitoring and analysis of security event alerts across the enterprise network. The SOC Analyst will monitor agency systems and daily log events to identify potential security threats, utilizing various sources such as sensor alert logs, firewall logs, content filtering logs, and Security Information and Event Management logs. This role requires reviewing all incoming alerts, investigating, and ticketing all identified potential security threats using the agency's incident response-ticketing platform. The SOC Analyst will validate traffic and/or network activity as anomalous according to agency standards and procedures, and will identify, investigate, and elevate potential security threats to senior agency resources when necessary. The position also involves measuring and modeling traffic, identifying patterns and ports, and producing reports, both contractual and ad hoc, providing information on events, trends, issues, and activity as requested by the federal customer. Additionally, the SOC Analyst will provide data for inclusion in the agency's CISA Report and investigate Open-Source Threat Intelligence for the agency. The role may also require the creation of new intrusion detection signatures as needed.

Shift

1:30pm to 10pm EST Sat to Wed OR 2:30pm EST to 11pm EST Sun to Thur.

All employees are considered mission critical and are expected to report even during inclement weather conditions.

Essential Functions, Responsibilities & Duties
  • Providing 24/7/365 monitoring and analysis of security event alerts across the enterprise network.
  • Monitoring agency systems and daily log events to identify potential security threats. Sources include, but not limited to, sensor alert logs, firewall logs, content filtering logs, and Security Information and Event Management logs.
  • Reviewing incoming alerts, investigating, and ticketing all identified potential security threats using agency incident response ticketing platform.
  • Prioritizing all incoming alerts and responding accordingly in a timely manner.
  • Validating traffic and/or network activity (per alerts/logs) as anomalous in accordance with agency standards and procedures.
  • Identifying, investigating, and escalating potential security threats to senior agency resources when needed.
  • Measuring and modeling traffic, while identifying patterns and ports.
  • Producing reports, both contractual and ad hoc, providing information on events, trends, issues, and activity as requested by the federal customer.
  • Providing data for inclusion in the agency’s CISA report.
  • Utilizing OSINT tools to identify and mitigate potential cybersecurity threats to the customer’s network.
  • Identifying the necessity for, and implementing, the creation of new intrusion detection signatures.
Work Experience, Knowledge, Skills & Abilities
  • Candidate must have a minimum of 2-4 years of experience as an analyst in a SOC or similar environment.
  • Working knowledge of SOC tools and their usage for detecting intrusion attempts.
  • Demonstrated experience creating custom intrusion signatures to detect specific network traffic anomalies.
  • Demonstrated experience in populating sensors with newly available signatures when responding to events or management requests.
  • Knowledge of potential threat reporting and tracking by means of at least one large-scale ticketing system (ServiceNow, CAPRS, or other similar system).
  • Ability to utilize email, instant messaging, and other monitoring tools to effectively navigate through the incident response process.
  • Strong oral presentation skills and the ability to articulate English in a clear and concise manner.
  • Demonstrated experience with Windows Operating System and Microsoft 365 tools.
Requirements
  • High School Diploma accompanied with related advanced training and certifications in cybersecurity or a related field. BS/BA degree preferred.
  • Must have at least one of the following certifications: CompTIA Network+, CompTIA Security+, or CompTIA CySA+.
  • Documented proof of certifications is required prior to the start of employment.
  • Experience with Windows Operating System and Microsoft 365 tools.
  • Great written and oral communication skills, with the ability to convey complex information clearly and effectively.
  • Must live within a 2-hour commute of the designated Security Operations Center for which they are applying.
Nice To Have
  • Bachelor’s or master’s degree in computer science, or cybersecurity, or information technology.
  • Other advanced certifications such as Cybersecurity Analyst+ (CySA+), Certified Ethical Hacker (CEH), GIAC Security Operations Certified (GSOC), etc.
  • Home lab setup and participation in training platforms like TryHackMe or similar.
Security Requirement
  • Ability to obtain a Public Trust.
Our Equal Employment Opportunity Policy

The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms and conditions of employment.

The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.

Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long‑term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.

Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Analyst
SOC Analyst

Koniag Services, Inc. • Durham (NC)

On-site
USD 70,000 - 100,000
SOC Analyst
SOC Analyst

Koniag Services, Inc. • Baltimore (MD)

On-site
USD 70,000 - 100,000
Health, dental and vision insurance
401K with company matching
Paid holidays
+1
SOC Analyst
SOC Analyst

Koniag Government Services • Denver (CO)

On-site
USD 43,050 - 55,104
Health insurance
Dental insurance
Vision insurance
+3
SOC Analyst
SOC Analyst

Koniag Government Services • Baltimore (MD)

On-site
USD 80,000 - 110,000
Health insurance
Dental insurance
Vision insurance
+4
SOC Analyst
SOC Analyst

Koniag Services, Inc. • Denver (CO)

On-site
USD 70,000 - 110,000
Security Operations Center Analyst - Mid
Security Operations Center Analyst - Mid

Koniag Services, Inc. • Washington

On-site
USD 85,000 - 120,000
Security Operations Center Analyst - High
Security Operations Center Analyst - High

Koniag Services, Inc. • Washington

On-site
USD 120,000 - 150,000
Health insurance
401(k) with company matching
Paid holidays
+1
Cybersecurity Operations Technical Lead (SOC Engineer/SME)
Cybersecurity Operations Technical Lead (SOC Engineer/SME)

Koniag Services, Inc. • Washington

On-site
USD 140,000 - 200,000
Health insurance
Dental insurance
Vision insurance
+4
Cyber Defense Analysts – Senior
Cyber Defense Analysts – Senior

Koniag Services, Inc. • Washington

On-site
USD 120,000 - 170,000
Health insurance
Dental insurance
Vision insurance
+4
Senior Security Manager
Senior Security Manager

Socket.dev • Smyrna (GA)

On-site
USD 140,000 - 185,000
Health insurance
Dental insurance
Vision insurance
+4