Senior Cyber Defense Analyst

Posted Yesterday
Be an Early Applicant
Smith, AR, USA
In-Office
110K-149K Annually
Senior level
Aerospace • Information Technology • Professional Services • Defense
The Role
Lead shift-level SOC operations including triage, threat hunting, incident response, and escalation. Validate AI-assisted detections, mentor analysts, coordinate cross-functional response, document investigations, support red/blue exercises, and ensure compliance with RMF, DoD 8140, and CSSP accreditation in a 24/7 mission environment.
Summary Generated by Built In
Company Description

Founded in 1989, SOSi is among the largest private, founder-owned technology and services integrators in the defense and government services industry. We deliver tailored solutions, tested leadership, and trusted results to enable national security missions worldwide.

Job Description

Senior Cyber Defense Analyst – Shift Lead 

Step into a high-impact cyber defense leadership role at the forefront of mission operations. As a Shift Lead within SOSi’s INDOPACOM Network Security Operations Center, you’ll drive real-time threat defense across multi-enclave coalition environments powered by cutting-edge DaaS private cloud technology.

This role blends advanced cyber operations with modern AI-assisted detection—leading analysts through threat hunting, incident response, and rapid decision-making to protect critical warfighter networks. You’ll be the connective force between detection engineering, cyber innovation teams, and mission partners, ensuring precision, speed, and mission assurance in a dynamic, 24/7 operational environment.

Lead the shift. Validate the signal. Defend the mission.

Essential Job Duties

  • Serve as the senior analyst and shift lead for assigned operations, providing direction on monitoring priorities, triage, threat hunting, and incident investigation activities.
  • Coordinate shift-level cyber defense response activities during alerts, incidents, outages, and mission-impacting events, escalating to the Incident Response Lead, DCO Lead, or INSOC leadership as required.
  • Validate, adjudicate, and prioritize escalated detections from AI-assisted SOC tools, SIEM, EDR, SOAR, and enterprise monitoring platforms.
  • Lead initial incident triage and support containment, remediation, evidence preservation, reporting, and handoff activities across shift transitions.
  • Mentor junior and mid-level analysts in detection analysis, threat hunting, incident response procedures, documentation standards, and operational best practices.
  • Serve as the shift-level liaison between analysts, DCAI engineers, detection engineering, NetOps, SysOps, and mission partners to refine detections, SOAR playbooks, AI-assisted workflows, and response procedures.
  • Conduct threat hunting based on adversary tactics, techniques, and procedures (TTPs), threat intelligence, anomaly detection, and mission-specific risk indicators.
  • Ensure incidents, investigations, shift notes, case updates, and lessons learned are documented accurately in accordance with SOPs, CSSP reporting requirements, and escalation timelines.
  • Support red/blue team events, tabletop exercises, operational drills, and after-action reviews to validate analyst readiness and improve shift procedures.
  • Provide clear verbal and written shift updates, incident summaries, and operational reporting to leadership, Government stakeholders, and external mission partners as required.
  • Maintain awareness of enterprise cyber, network, system, and mission environments to support timely detection, correlation, and mission-impact assessment.
  • Support compliance with RMF, CSSP, DoD 8140, SOPs, and accreditation requirements for AI-augmented cyber defense and incident response processes.

Qualifications

Minimum Requirements

  • Active in-scope Top Secret/SCI clearance.
  • DoD 8140 / 8570 IAT Level II certification required within 180 days of hire, such as Security+ CE, CySA+, GSEC, CCNA Security, or equivalent.
  • Minimum 5+ years of SOC, CSSP, Defensive Cyberspace Operations, or cyber defense experience with demonstrated incident response and threat hunting expertise.
  • Experience serving as a senior analyst, shift lead, incident lead, or escalation point within a SOC or enterprise cyber defense environment.
  • Strong understanding of adversary TTPs, MITRE ATT&CK, malware analysis fundamentals, cyber kill chain concepts, and advanced detection and response techniques.
  • Hands-on experience with SIEM, EDR, SOAR, packet capture and analysis tools, and enterprise monitoring platforms, such as Splunk, Elastic, Defender, Wireshark, Zeek, ServiceNow, or similar tools.
  • Ability to coordinate cross-functional response efforts across analysts, engineers, operations teams, Government stakeholders, and mission partners during cyber incidents and operational events.
  • Strong written and verbal communication skills, including the ability to brief technical findings, incident status, operational risk, and recommended actions to technical and non-technical audiences.
  • Must be flexible to support 24/7/365 operations, including rotating shifts, nights, weekends, holidays, on-call support, and surge coverage during major incidents or exercises.

Preferred Qualifications

  • Advanced certifications such as GCIA, GCIH, GDAT, GCTI, CISSP, CASP+, or equivalent.
  • Experience supporting DISA, CSSP, TNCC, INDOPACOM, coalition, or military cyber defense environments.
  • Prior Tier 2/Tier 3 SOC analyst, shift lead, incident commander, battle captain, or major incident coordination experience.
  • Experience working with AI/ML-assisted SOC platforms, automation pipelines, SOAR workflows, and operational analytics platforms.
  • Experience building, maturing, or refining SOC workflows, CONOPS, SOPs, escalation procedures, dashboards, and reporting products.
  • Experience with Mavin, Power BI, JIRA, ServiceNow, Elastic, Splunk, Microsoft Defender, Zeek, Wireshark, or similar enterprise platforms.

Additional Information

Work Environment

  • Shift-based senior analyst role supporting 24/7/365 mission operations; flexibility is required for rotating shifts, weekends, holidays, after-hours escalations, exercises, and surge support.
  • Fast-paced, mission-critical cyber defense operations supporting classified mission activities and enterprise-level operational response.
  • May require participation in operational meetings, briefings, shift turnovers, tabletop exercises, and after-action reviews.
  • Target Salary Range: $110,290 to $148,891.

Working at SOSi

All interested individuals will receive consideration and will not be discriminated against for any reason.

Skills Required

  • Active in-scope Top Secret/SCI clearance.
  • DoD 8140 / 8570 IAT Level II certification (e.g., Security+ CE, CySA+, GSEC, CCNA Security) required within 180 days of hire.
  • Minimum 5+ years of SOC, CSSP, Defensive Cyberspace Operations, or cyber defense experience with incident response and threat hunting expertise.
  • Experience serving as a senior analyst, shift lead, incident lead, or escalation point within a SOC or enterprise cyber defense environment.
  • Strong understanding of adversary TTPs, MITRE ATT&CK, malware analysis fundamentals, cyber kill chain concepts, and advanced detection/response techniques.
  • Hands-on experience with SIEM, EDR, SOAR, packet capture and analysis tools, and enterprise monitoring platforms (e.g., Splunk, Elastic, Defender, Wireshark, Zeek, ServiceNow).
  • Ability to coordinate cross-functional response across analysts, engineers, operations teams, Government stakeholders, and mission partners.
  • Strong written and verbal communication skills, able to brief technical and non-technical audiences.
  • Flexibility to support 24/7/365 operations including rotating shifts, nights, weekends, holidays, on-call, and surge coverage.
  • Advanced certifications such as GCIA, GCIH, GDAT, GCTI, CISSP, CASP+ (preferred).
  • Experience supporting DISA, CSSP, TNCC, INDOPACOM, coalition, or military cyber defense environments (preferred).
  • Prior Tier 2/Tier 3 SOC analyst, shift lead, incident commander, battle captain, or major incident coordination experience (preferred).
  • Experience with AI/ML-assisted SOC platforms, automation pipelines, SOAR workflows, and operational analytics (preferred).
  • Experience building or maturing SOC workflows, CONOPS, SOPs, escalation procedures, dashboards, and reporting products (preferred).
  • Experience with Mavin, Power BI, JIRA, ServiceNow, Elastic, Splunk, Microsoft Defender, Zeek, Wireshark (preferred).

SOSi Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about SOSi and has not been reviewed or approved by SOSi.

  • Healthcare Strength Health coverage is considered a relative strength, with international plan options and substantial employer contribution that support OCONUS and travel-heavy work. Company materials also highlight a comprehensive medical offering alongside wellness support.
  • Retirement Support A 401(k) program is available, with indications of employer matching though specifics are not publicly detailed. This suggests foundational retirement support for eligible employees.
  • Career-Linked Recognition & Rewards Compensation is often characterized as competitive for cleared, hard‑to‑hire, and certain overseas or mission‑critical roles. Pay levels appear closely tied to contract demands, clearance, and location.

SOSi Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
2,460 Employees
Year Founded: 1989

What We Do

SOSi is a technology and services integrator focused on the aerospace, defense, and government services industry, described as one of the largest private, founder-owned companies in its sector.

Similar Jobs

Zeta Global Logo Zeta Global

Associate Vice President, Paid Search - EDU

AdTech • Artificial Intelligence • Marketing Tech • Software • Analytics
Easy Apply
Remote or Hybrid
United States
2429 Employees
140K-160K Annually

Wipfli Logo Wipfli

Audit Manager, Tribal Industry

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
3000 Employees
97K-145K Annually

Bringg Logo Bringg

Enterprise Account Executive

Cloud • Enterprise Web • Logistics • Software
Remote or Hybrid
United States
180 Employees
260K-320K Annually

ServiceNow Logo ServiceNow

Consultant

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Remote or Hybrid
United States
29000 Employees

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Outpost Space Thumbnail
Aerospace • Defense
US
24 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account