SOC Analyst: Advanced Threat Hunting & Incident Response

EverWatch

Maryland

On-site

USD 79,000 - 92,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

EverWatch invites applications for a Security Operations Center Analyst in the Annapolis Junction area to strengthen U.S. Cyber Command defenses.

You will analyze logs, threat intelligence, and forensic data to identify advanced threats and respond to incidents with a deep understanding of customer networks. The role requires experience in SIEM, vulnerability scans, Linux environments, and network fundamentals, plus TS/SCI clearance with polygraph.

Qualifications

  • Experience with SIEM fundamentals, including Splunk.
  • Knowledge of basic networking fundamentals.
  • Knowledge of Bro (Zeek) configurations.
  • Knowledge of Suricata or Snort.
  • Ability to review Nessus scans and Firewall configurations.
  • Ability to review Linux hosts for indicators of compromise and hardening of Linux systems.
  • Ability to navigate *nix based systems via CLI.
  • Ability to find, read, and analyze various logs.
  • TS/SCI clearance with a polygraph.
  • HS diploma or GED and 6+ years of incident response experience or Bachelor's +2 years.

Responsibilities

  • Analyze logs, forensic data, and threat intelligence to identify advanced threats.
  • Perform threat identification and complex incident response.
  • Advise on gaps to close and harden networks in collaboration with customers.

Skills

SIEM Fundamentals
Splunk
Networking basics
Linux CLI
Log analysis

Education

HS diploma or GED
Bachelor's degree

Tools

Bro (Zeek)
Suricata
Nessus

Job description

EverWatch invites applications for a Security Operations Center Analyst in the Annapolis Junction area to strengthen U.S. Cyber Command defenses.

You will analyze logs, threat intelligence, and forensic data to identify advanced threats and respond to incidents with a deep understanding of customer networks. The role requires experience in SIEM, vulnerability scans, Linux environments, and network fundamentals, plus TS/SCI clearance with polygraph.

Get your free, confidential resume review.

or drag and drop your file here.