SOC Analyst
Job description
SOC AnalystLocation: Remote | Night and Weekend Shifts RequiredActive Secret Clearance Required
ASRC Federal is seeking a SOC Analyst to support the Department of Defense Education Activity (DoWEA) Enterprise Cyber Program. This role supports enterprise cybersecurity operations, including Risk Management Framework (RMF) compliance, vulnerability management, security monitoring, and incident response, in collaboration with other cybersecurity personnel.
This is a remote position requiring scheduled night and weekend shifts in support of SOC operations.
Key Responsibilities
Monitor and analyze network traffic, system logs, and other security data for signs of malicious activity.
Use Security Information and Event Management (SIEM) tools to investigate security alerts and notable events.
Manage incidents throughout their lifecycle, including analysis, triage, containment, and remediation.
Recommend improvements to prevent future incidents and expedite response based on lessons learned.
Communicate effectively and promptly with technical and nontechnical stakeholders.
Prepare situational awareness reports for the customer and management.
Develop and maintain manual and automated incident response playbooks.
Support the development of SIEM detection and data ingestion strategies to improve SOC visibility.
Conduct host and log forensic analysis and malware analysis as needed.
Perform threat hunting based on emerging adversary tactics, techniques, and procedures.
Develop and implement security procedures to prevent future incidents.
Provide technical support to other members of the security team.
Stay current on cybersecurity threats and trends.
Required Skills, Certifications, and
Qualifications
Minimum of five years of relevant cybersecurity experience, including SOC operations, security monitoring, and incident response.
Must hold and maintain required cybersecurity certifications, including one certification from each of the following groups:
CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, or CCSP.
CEH, CFR, CCNA Cyber Ops, CCNA-Security, CySA+, GCIA, GCIH, GICSP, Cloud+, SCYBER, or PenTest+.
Experience with SIEM tools, such as Microsoft Sentinel.
Experience leading and managing SOC operations.
Expertise in analyzing network packets, SIEM alerts, and server and application logs to investigate anomalous or malicious activity.
Experience tracking incidents using frameworks such as MITRE ATT&CK or the Cyber Kill Chain.
Ability to analyze advanced persistent threats and map the threat lifecycle.
Ability to work scheduled night and weekend shifts remotely.
Active Secret security clearance.
Desired
Skills
Experience with Microsoft Sentinel.
Forensic investigation and malware analysis experience.
Strong curiosity and problem-solving skills.
Proactive approach and a strong sense of ownership.
Skills mentioned

ASRC Federal is the government services subsidiary of Arctic Slope Regional Corporation, an Alaska Native Corporation owned by over 14,000 Iñupiat shareholders. The company provides a broad range of mission-critical services to federal government agencies dedicated to defense, civil, and intelligence support. Its areas of expertise encompass IT modernization, engineering solutions, software applications, analytics, professional services, and supply chain management. ASRC Federal employees are dedicated to fulfilling essential missions across various sectors, including space exploration, cybersecurity, public health, and providing operational support to U.S. military bases. By leveraging innovative technology, ASRC Federal plays a crucial role in facilitating seamless air travel and is known for supporting the Federal Aviation Administration's (FAA) objectives. As a certified Great Place to Work, ASRC Federal emphasizes employee growth and development, resulting in a motivated workforce that strives for excellence in serving federal clients.
Apply for this job
Use the application link supplied with this listing to apply to ASRC Federal. Check the destination before entering personal information.
