Tier I SOC Analyst

The Phoenix Group

Arlington (VA)

On-site

USD 75,000 - 110,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Shift premium
Certification costs covered
Published salary band
Three days off weekly (4‑day shift)
Impactful work with federal clients

Job summary

The Phoenix Group is seeking a Security Operations Center Analyst to join our client’s federal-grade cloud operations in Arlington, VA. You will monitor alerts, decide on containment or escalation, and work across performance, availability, and security issues in a single queue.

This role emphasizes shift flexibility, a four-day rotation, and a fixed schedule. Certifications like CompTIA Security+ are preferred or obtainable within 90 days, with on-site duties and opportunities to contribute to

Qualifications

  • CompTIA Security+ or an equivalent certification, or the ability to earn it within 90 days of starting.
  • Hands-on experience in IT Ops, a help desk, a network operations center, or something similar.
  • Good judgment about when to escape, and comfort working on your own if the shift you take is an overnight.

Responsibilities

  • Review alerts and decide what to do — escalate, contain, or close with your reasoning noted.
  • Handle performance and availability issues alongside security ones, out of the same queue.
  • Follow our runbooks for containment and call the senior analyst on duty when a runbook runs out.
  • Work customer requests and tickets once the higher priorities are clear.
  • Leave notes the next shift can pick up without having to call you.
  • Complete shift handovers with a written log.

Skills

IT Ops
Help Desk
NOC
Overnight shift
Alert review

Job description

Our client runs the largest Federal and DoW managed cloud, building and operating secure cloud and AI environments that support the U.S. government’s most critical missions — from national security and public safety to essential public services. Our customers rely on us to deploy production systems that meet the highest standards for security, reliability, and compliance.

Work is high-impact and purpose-driven. The problems we solve are high-stakes, the expectations are high, and the results are visible. Speed, rigor, and trust matter here - because the environments we secure cannot fail. Your contributions are visible, your expertise is relied upon, and the impact of your work is immediate and measurable. We operate at federal scale, securing some of the most sensitive government environments in the country - because the systems we build must perform without fail.

How We Work

Most companies run a security team and a network team separately. We don’t. For our client, one team watches everything — performance, availability and security — out of the same queue. You see the whole picture, and a problem never sits with the wrong team while the clock runs. It is a better way to work and a much faster way to learn.

How We Prioritize
  1. Active intrusion or suspected compromise
  2. Service-affecting outage
  3. Degradation and early warning signs
  4. Customer requests and tickets

Higher priorities always come first. You will not be asked to finish a routine ticket while a live alert is open.

What You'll Do
  • Work a full shift on a weekday or a four-day rotation schedule and hand over with a written log.
  • Review alerts and decide what to do — elevate, contain, or close with your reasoning noted.
  • Handle performance and availability issues alongside security ones, out of the same queue.
  • Follow our runbooks for containment and call the senior analyst on duty when a runbook runs out.
  • Work customer requests and tickets once the higher priorities are clear.
  • Leave notes the next shift can pick up without having to call you.
What You'll Need
  • CompTIA Security+ or an equivalent certification, or the ability to earn it within 90 days of starting.
  • Hands-on experience in IT Ops, a help desk, a network operations center, or something similar.
  • Good judgment about when to escape, and comfort working on your own if the shift you take is an overnight.
What We'll Teach You
  • Cloud security monitoring, SIEM tools, and how to tune detections.
  • How FedRAMP controls work in practice, and how we evidence them.
  • Incident containment, network troubleshooting, and our runbooks.
  • The path to Tier 2, usually around three years.
What We Don't Require
  • An active security clearance. If you hold one, or held one, that’s a plus — it is never a requirement.
What We Offer
  • Your schedule is fixed and published ahead of time. Shifts do not rotate.
  • Three consecutive days off every week on the four-day rotation schedules.
  • Certification costs and renewals covered, including the first attempt and a retake.
  • Shift premium paid on the hours you actually work in a premium window, at a published rate.
  • A published salary band, and a published band for the level above you.
  • We are a small team, so what you do is visible. You will make an impact.

Hiring Requirement: Due to the nature of our work with federal government clients and compliance with applicable regulations, this position requires U.S. citizenship. Dual citizenship is not permitted for this role.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Analyst
SOC Analyst

Tactibit • Suitland (MD)

On-site
USD 85,000 - 110,000
SOC Analyst
SOC Analyst

Tactibit Technologies LLC. • Suitland (MD), Northern (KY)

Hybrid
USD 95,000 - 125,000
Level 1 Cyber Security Analyst
Level 1 Cyber Security Analyst

Netrio • McKinney (TX)

On-site
USD 65,000 - 90,000
SOC Analyst - Tier 1
SOC Analyst - Tier 1

Evans & Chambers • Fort Meade (MD)

On-site
USD 88,000 - 118,000
SOC Analyst - Tier 1
SOC Analyst - Tier 1

Evans & Chambers • Maryland

On-site
USD 88,000 - 118,000
Level 2 Cyber Security Analyst
Level 2 Cyber Security Analyst

Netrio • McKinney (TX)

On-site
USD 80,000 - 110,000
Tier 1 Analyst
Tier 1 Analyst

Aretec, Inc. • Northern (KY)

Hybrid
USD 42,000 - 60,000
Health, Dental, and Vision Insurance
401(k) Plan with Employer Match
Certification Stipends
+3
SOC Analyst I
SOC Analyst I

SOClogix, Inc. • Catonsville (MD)

On-site
USD 55,000 - 75,000
Health insurance
Dental insurance
Vision insurance
+6
Security Operations Analyst - Tier 2
Security Operations Analyst - Tier 2

Knox Systems, Inc • Arlington (VA), Northern (KY)

Hybrid
USD 100,000 - 135,000
Shift premium
Published salary band
Three days off per week
+2
Security Operations Analyst - Tier 1
Security Operations Analyst - Tier 1

Knox Systems, Inc • Arlington (VA), Northern (KY)

Hybrid
USD 65,000 - 95,000
Shift premium
Certification costs covered
Published salary bands
+2