About the company
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Associate Cyber Operations Analyst – SOC Threat Management based in the United States.
This is an opportunity to join a mission-focused Security Operations Center supporting a large federal environment and protecting critical systems and data.
Responsibilities
- Support 24x7 SOC operations by monitoring security events, identifying suspicious activity, and detecting advanced cyber threats across enterprise environments.
- Review SIEM alerts, incident reporting systems, mailboxes, and other sources to identify potential incidents and determine their scope, severity, and impact.
- Analyze and correlate information from multiple sources to assess threats affecting critical systems, applications, networks, and datasets.
- Execute established operational procedures for security incidents, identify potential mitigating controls, and escalate complex cases for deeper investigation.
- Analyze current threat intelligence, adversary activity, and emerging vulnerabilities to assess organizational risk and improve defensive measures.
- Apply knowledge of network attacks, intrusion methodologies, IDS/IPS technologies, and threat detection techniques to investigate suspicious activity.
- Use AI/ML capabilities to identify anomalies, automate alert triage, enhance threat intelligence, and improve the efficiency and effectiveness of SOC operations.
- Work closely with Threat Management colleagues and other security professionals to investigate incidents, communicate findings, and coordinate response activities.
- Stay current with cybersecurity trends, threat actors, attack techniques, cloud security developments, and emerging AI/ML applications relevant to security operations.
- Identify opportunities to improve detection processes, automation, analytical methods, and overall SOC effectiveness.
Requirements
- At least 1 year of direct experience in cybersecurity, IT security, SOC operations, or cyber incident analysis with a relevant bachelor’s degree, or 5+ years of cybersecurity, IT, and SOC analysis/operations experience.
- Practical understanding of security monitoring, incident management, threat detection, and cyber analysis within an operational security environment.
- Familiarity with artificial intelligence and machine learning concepts and their application to anomaly detection, behavioral analysis, threat intelligence, and SOC automation.
- Strong understanding of TCP/IP, Boolean logic, network-level exploits, network traffic analysis, IDS/IPS architectures, and security detection methodologies.
- Hands-on experience with SIEM/SOAR platforms and cybersecurity automation technologies.
- Familiarity with security principles, risk management, control frameworks, and cloud environments such as AWS, Azure, or GCP.
- Ability to interpret threat intelligence and apply knowledge of threat actors, attack techniques, and intrusion methodologies to security investigations.
- Ability to analyze security data and, ideally, apply feature engineering or ML techniques to security models and behavioral detection.
- Excellent written and verbal communication, organization, collaboration, and interpersonal skills, with the ability to clearly communicate findings and escalate incidents appropriately.
- Bachelor’s degree in Computer Science, Information Technology, cybersecurity, or a related field is preferred, or equivalent professional experience.
- Security certifications such as CompTIA Security+, CEH, GCED, GCIA, GCDA, GCIH, GDAT, GSOC, or CISSP are desirable.
- U.S. citizenship is required, along with the ability to obtain and maintain Public Trust security vetting.
- Ability to work remotely in a shift-based environment supporting 24x7 SOC operations.
Conditions
- Fully remote position with telework eligibility and no regular travel requirement.
- Medical, dental, and vision insurance.
- Life insurance plus short-term and long-term disability coverage.
- 401(k) retirement savings plan with company matching.
- Paid time off and paid holidays.
- Tuition assistance and support for ongoing professional development.
- Opportunity to work on cybersecurity operations supporting critical federal missions and complex security environments.
- Exposure to modern SIEM/SOAR, AI/ML, cloud security technologies.