Cybersecurity Analyst

Posted 2 Days Ago
Be an Early Applicant
2 Locations
In-Office
Senior level
Security
The Role
Conduct advanced threat detection, hunting, incident response, log correlation, malware and network analysis, and SOC capability improvements. Develop detection logic, playbooks, and post-incident reports; map findings to MITRE ATT&CK; support purple-team operations; coordinate remediation with cyber and IT teams; mentor analysts; brief stakeholders; and work rotating shifts in a classified 24/7 SOC environment.
Summary Generated by Built In

SAIC is seeking a Cybersecurity Analysts to support the Special Operation Command Information Technology Enterprise Contract (SITEC) – 3 EOM.  This position is located at Fort Bragg, NC.

The purpose of the Special Operations Forces Information Technology Enterprise Contract (SITEC) 3 Enterprise Operations and Maintenance (EOM) Task Order (TO) is to provide USSOCOM, its Component Commands, its Theater Special Operations Commands (TSOCs), and its deployed forces with Operations and Maintenance (O&M) services to maintain Network Operations (NetOps); maintain systems and network infrastructure; provide end user and common device support; provide configuration, change, license, and asset management; conduct training, and perform Install, Move, Add, Change (IMACs) services. The responsibilities and tasks associated with each requirement play a pivotal role to USSOCOM, the CIO/J6 organization, and ultimately the end-user who operate around the globe 24x7x365. 

This position offers an opportunity for experienced cybersecurity professionals to take on advanced responsibilities in defending USSOCOM’s global operations. The Cybersecurity Analyst will play a pivotal role in enhancing SOC capabilities, mentoring junior team members, and ensuring the security and resilience of systems critical to USSOCOM’s mission success. The Cybersecurity Analyst will be responsible for but not limited to the following duties:

  • Expertise in identifying and analyzing sophisticated threats using SIEM platforms, intrusion detection systems (IDS), and other advanced tools.
  • Strategic ability to correlate data from multiple sources to uncover advanced persistent threats (APTs) and complex attack patterns.
  • Proficiency in refining detection rules and alerts to enhance threat identification capabilities. Leadership in managing high-priority security incidents, including coordinating containment, eradication, and recovery strategies.
  • Advanced skills in root cause analysis and delivering actionable recommendations for future mitigation.
  • Ability to create detailed post-incident reports to inform organizational strategy and resilience.
  • Ability to lead audits and assessments, providing recommendations to enhance compliance and streamline processes.
  • Advanced skills in securing NetOps and systems/network infrastructure against evolving threats.
  • Leadership in mentoring junior analysts, fostering their growth and technical expertise.
  • Strategic collaboration with SOC team members, IT staff, and stakeholders to develop coordinated threat responses.
  • Ability to contribute to cross-functional discussions and drive improvements in SOC operations.
  • Continuous Improvement and Research.
  • Commitment to staying informed on emerging threats, technologies, and best practices to enhance SOC capabilities.
  • Strategic mindset to research and recommend tools, techniques, and strategies for improved operations.
  • Ability to deliver training sessions to elevate team knowledge and preparedness.
  • Operate within a 24/7 SOC environment, which may require shift work, including nights, weekends, and holidays.
  • Handle sensitive and classified information in compliance with DoD and USSOCOM requirements.
  • Actively perform Cyber, correlate logs, report findings, and coordinate with cyber analysts to contain users/systems and initiate formal CSSP documentation.
  • Analyze network traffic logs and encrypted patterns to identify ongoing threats, anomalous behavior, command-and-control (C2) channels, active exploitation, or data exfiltration attempts.
  • Monitor NSA Pulse investigations related to USASOC assets and brief branch chiefs to coordinate mitigation while preventing duplication of effort with Cyber Analysts.
  • Coordinate with Cyber Operators for threat intelligence sharing, escalation criteria, and remediation plans.
  • Develop threat hunt playbooks based on industry findings, historical trends, or G639 requirements to systematically search for indicators of compromise.
  • Contextualize and aggregate logs between Splunk, MDE environments, and other SIE native tools for data generation.
  • Develop and refine advanced detection logic (e.g., Sigma, YARA, or Splunk SPL signatures) based on emerging TTPs to automate the identification of malicious activity.
  • Map all hunt findings and defensive gaps to the MITRE ATT&CK Framework to prioritize mission focus areas based on adversary trends.
  • Engage in "Purple Team" operations alongside adversary emulation cells to verify that security controls are effectively detecting and blocking known exploit techniques."
Qualifications

Required Education:

  • Bachelor's degree and five (5) years’ experience; additional four (4) years’ experience can be considered in lieu of degree.

Required Clearance: 

  • Must possess an active TS/SCI security clearance with the ability to maintain; US Citizenship required.

Required Skills: 

  • Strong understanding of cybersecurity concepts, including threat detection, malware analysis, and network security.
  • Proficiency with one or more tools such as SIEM platforms, IDS/IPS, endpoint protection solutions, and forensic analysis tools.
  • Advanced analytical and problem-solving skills with the ability to handle complex incidents and scenarios.
  • Effective communication skills, including the ability to create detailed reports and brief stakeholders.
  • Ability to work independently and lead initiatives in a fast-paced, team-oriented environment.

Required Certifications:

  • Must be DoW 8140 compliant under the Work Role Code 531 – Cyber Defense Incident Responder - Intermediate level.

Desired Skills: 

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent experience).
  • Advanced certifications such as CISSP, GIAC (e.g., GCIA, GCIH), or OSCP.
  • Experience with scripting or automation tools (e.g., Python, PowerShell) and threat hunting techniques.
  • Knowledge of advanced threat intelligence platforms and methodologies.
About UsSAIC® is a premier mission integrator focused on advancing the power of technology and innovation to serve and protect our world. Our robust portfolio of offerings across the defense, space, intelligence, and civilian markets includes secure high-end solutions in mission IT, enterprise IT, engineering services, and professional services. We integrate emerging technology, rapidly and securely, into mission critical operations that modernize and enable critical national imperatives.

We are approximately 23,000 strong; driven by mission, united by purpose, and inspired by opportunities. SAIC is an Equal Opportunity Employer. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.3 billion. For more information, visit saic.com. For ongoing news, please visit our newsroom.

Skills Required

  • Bachelor's degree and five years of experience, or an additional four years of experience in lieu of the degree.
  • Active TS/SCI security clearance with ability to maintain it.
  • U.S. citizenship.
  • Strong understanding of cybersecurity, threat detection, malware analysis, and network security.
  • Proficiency with SIEM platforms, IDS/IPS, endpoint protection solutions, and forensic analysis tools.
  • Advanced analytical and problem-solving skills for complex incidents and scenarios.
  • Effective communication skills, including detailed reporting and stakeholder briefings.
  • Ability to work independently and lead initiatives in a fast-paced, team-oriented environment.
  • DoD 8140 compliance under Work Role Code 531, Cyber Defense Incident Responder, Intermediate level.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field.
  • Advanced certification such as CISSP, GIAC, GCIA, GCIH, or OSCP.
  • Experience with Python, PowerShell, scripting, automation, and threat hunting techniques.
  • Knowledge of advanced threat intelligence platforms and methodologies.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Stamford, CT
34,000 Employees

What We Do

Spectrum San Diego is a high tech security innovator, specializing in ultra-low-dose X-ray screening systems.

Similar Jobs

City of High Point Logo City of High Point

Cybersecurity Analyst

Professional Services • Utilities
In-Office
High Point, NC, USA
76K-103K Annually
In-Office
Raleigh, NC, USA
108 Employees
In-Office
Raleigh, NC, USA
340 Employees

Agero Logo Agero

Cybersecurity Governance Analyst

Automotive • Big Data • Insurance • Software • Transportation
Easy Apply
Remote or Hybrid
14 Locations
1600 Employees
75K-95K Annually

Similar Companies Hiring

Closinglock Thumbnail
Fintech • Real Estate • Security • Software • Financial Services • Cybersecurity • PropTech
Austin, TX
110 Employees
Credal.ai Thumbnail
Software • Security • Productivity • Machine Learning • Artificial Intelligence
Brooklyn, NY
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account