... Operations Center (SOC) Analyst to support the U.S. Small Business Administration (SBA ... The ideal candidate is an experienced cybersecurity professional with a solid foundation in ...
... Operations Center (SOC) Analyst to support the U.S. Small Business Administration (SBA ... The ideal candidate is an experienced cybersecurity professional with a solid foundation in ...
They are seeking a Junior Third-Party Incident Response Analyst & Digital Forensics Analyst to support their Cyber Security Operations Center by handling cybersecurity incident escalations and ...
They are seeking a Junior Third-Party Incident Response Analyst & Digital Forensics Analyst to support their Cyber Security Operations Center by handling cybersecurity incident escalations and ...
... Operations Center (SOC) Analyst to support the U.S. Small Business Administration (SBA ... The ideal candidate is an early-career cybersecurity professional with a foundational understanding ...
... Operations Center (SOC) Analyst to support the U.S. Small Business Administration (SBA ... The ideal candidate is an early-career cybersecurity professional with a foundational understanding ...
Security Operations Center Analyst - Low
Washington, DC · On-site
$108K - $131K/yr
... Operations Center (SOC) Analyst to support the U.S. Small Business Administration (SBA ... The ideal candidate is an early-career cybersecurity professional with a foundational understanding ...
Security Operations Center Analyst - Low
Washington, DC · On-site
$108K - $131K/yr
... Operations Center (SOC) Analyst to support the U.S. Small Business Administration (SBA ... The ideal candidate is an early-career cybersecurity professional with a foundational understanding ...
... Operations Center (SOC) Analyst to support the U.S. Small Business Administration (SBA ... The ideal candidate is an early-career cybersecurity professional with a foundational understanding ...
... Operations Center (SOC) Analyst to support the U.S. Small Business Administration (SBA ... The ideal candidate is an early-career cybersecurity professional with a foundational understanding ...
Security Operations Center Analyst II
Orlando, FL · On-site
$80 - $100/hr
Overview Security Operations Center Analyst II - Orlando, Florida Company Overview Statement ... Responsible for cybersecurity operations, incident response, and defensive cyber measures across ...
Security Operations Center Analyst II
Orlando, FL · On-site
$80 - $100/hr
Overview Security Operations Center Analyst II - Orlando, Florida Company Overview Statement ... Responsible for cybersecurity operations, incident response, and defensive cyber measures across ...
Cybersecurity Operation Analyst 25-E-03
Springfield, IL · On-site
$80K - $112K/yr
The Cybersecurity Operations Analyst will be a key point of contact within Information Security, responsible for responding to escalations, and will assist with audit responses, compliance, and ...
Cybersecurity Operation Analyst 25-E-03
Springfield, IL · On-site
$80K - $112K/yr
The Cybersecurity Operations Analyst will be a key point of contact within Information Security, responsible for responding to escalations, and will assist with audit responses, compliance, and ...
Security Operations Center Analyst
Spartanburg, SC · On-site +1
BUILD YOUR CYBERSECURITY CAREER WITH SECURITY FINANCE Are you ready to take the next step in your cybersecurity career? Security Finance is looking for a Security Operations Center (SOC) Analyst who ...
New
Quick apply
Security Operations Center Analyst
Spartanburg, SC · On-site +1
BUILD YOUR CYBERSECURITY CAREER WITH SECURITY FINANCE Are you ready to take the next step in your cybersecurity career? Security Finance is looking for a Security Operations Center (SOC) Analyst who ...
New
ZeroEyes Operations Center Analyst
Honolulu, HI · On-site
$60 - $80/hr
As a ZeroEyes Operations Center (ZOC) Analyst working in our 24/7/365 Operations Center, you will ... Cybersecurity, Artificial Intelligence (AI), Machine Learning, Computer Vision, and more.* Able to ...
ZeroEyes Operations Center Analyst
Honolulu, HI · On-site
$60 - $80/hr
As a ZeroEyes Operations Center (ZOC) Analyst working in our 24/7/365 Operations Center, you will ... Cybersecurity, Artificial Intelligence (AI), Machine Learning, Computer Vision, and more.* Able to ...
Security Operations Center Analyst Mandatory Skills Requirements: * Thirst for knowledge, inquisitive nature, keen interest in actively participating in SOC expansion * Experience working in an ...
Security Operations Center Analyst Mandatory Skills Requirements: * Thirst for knowledge, inquisitive nature, keen interest in actively participating in SOC expansion * Experience working in an ...
Overview Security Operations Center Analyst II - Orlando, Florida Company Overview Statement ... Responsible for cybersecurity operations, incident response, and defensive cyber measures across ...
Overview Security Operations Center Analyst II - Orlando, Florida Company Overview Statement ... Responsible for cybersecurity operations, incident response, and defensive cyber measures across ...
Overview Security Operations Center Analyst II - Orlando, Florida Company Overview Statement ... Responsible for cybersecurity operations, incident response, and defensive cyber measures across ...
Overview Security Operations Center Analyst II - Orlando, Florida Company Overview Statement ... Responsible for cybersecurity operations, incident response, and defensive cyber measures across ...
Security Operations Center Analyst
Austin, TX · On-site
$100 - $125/hr
Our services include strategic cybersecurity consulting, incident response, proactive security ... Security Operations Center (SOC) Analyst** to join our growing U.S. Managed Detection and Response ...
Security Operations Center Analyst
Austin, TX · On-site
$100 - $125/hr
Our services include strategic cybersecurity consulting, incident response, proactive security ... Security Operations Center (SOC) Analyst** to join our growing U.S. Managed Detection and Response ...
... Operations Center (SOC) Analyst to support the U.S. Small Business Administration (SBA ... The ideal candidate is an early-career cybersecurity professional with a foundational understanding ...
... Operations Center (SOC) Analyst to support the U.S. Small Business Administration (SBA ... The ideal candidate is an early-career cybersecurity professional with a foundational understanding ...
Cybersecurity Operation Analyst 25-E-03
Springfield, IL · On-site
$80K - $112K/yr
The Cybersecurity Operations Analyst will be a key point of contact within Information Security, responsible for responding to escalations, and will assist with audit responses, compliance, and ...
Cybersecurity Operation Analyst 25-E-03
Springfield, IL · On-site
$80K - $112K/yr
The Cybersecurity Operations Analyst will be a key point of contact within Information Security, responsible for responding to escalations, and will assist with audit responses, compliance, and ...
The Illinois Attorney General's Office is seeking a Cybersecurity Operations Analyst to support their Information Security Bureau. The role involves monitoring security events, maintaining ...
The Illinois Attorney General's Office is seeking a Cybersecurity Operations Analyst to support their Information Security Bureau. The role involves monitoring security events, maintaining ...
Coalfire has been a cybersecurity thought leader for over 20 years and has offices throughout the ... We're currently seeking a skilled SOC Analyst with an active Secret or Top Secret clearance to ...
Coalfire has been a cybersecurity thought leader for over 20 years and has offices throughout the ... We're currently seeking a skilled SOC Analyst with an active Secret or Top Secret clearance to ...
AI Cybersecurity Analyst
Washington, DC · On-site
Seeking a Senior Cybersecurity Analyst with hands-on experience applying Artificial Intelligence (AI) to Security Operations Center (SOC) and computer network defense . The role combines advanced ...
AI Cybersecurity Analyst
Washington, DC · On-site
Seeking a Senior Cybersecurity Analyst with hands-on experience applying Artificial Intelligence (AI) to Security Operations Center (SOC) and computer network defense . The role combines advanced ...
Security Operations Center Analyst
Denver, CO · On-site
Coalfire has been a cybersecurity thought leader for over 20 years and has offices throughout the ... We're currently seeking a skilled SOC Analyst with an active Secret or Top Secret clearance to ...
Security Operations Center Analyst
Denver, CO · On-site
Coalfire has been a cybersecurity thought leader for over 20 years and has offices throughout the ... We're currently seeking a skilled SOC Analyst with an active Secret or Top Secret clearance to ...
Senior Cyber Security Analyst
Springfield, VA · On-site
$104K - $134K/yr
Providing leadership and advanced Cyber Security Operations Center (CSOC) support, managing cyber ... Performing cyber engineering trend analysis, producing detailed reports, and supporting 24x7 ...
Senior Cyber Security Analyst
Springfield, VA · On-site
$104K - $134K/yr
Providing leadership and advanced Cyber Security Operations Center (CSOC) support, managing cyber ... Performing cyber engineering trend analysis, producing detailed reports, and supporting 24x7 ...
Cyber Security Operation Center Analyst information
See salary details
$43K - $52.7K
1% of jobs
$52.7K - $62.5K
6% of jobs
$62.5K - $72.2K
10% of jobs
$78.8K is the 25th percentile. Wages below this are outliers.
$72.2K - $81.9K
12% of jobs
$81.9K - $91.6K
15% of jobs
The median wage is $95.8K / yr.
$91.6K - $101.4K
15% of jobs
$101.4K - $111.1K
10% of jobs
$115.3K is the 75th percentile. Wages above this are outliers.
$111.1K - $120.8K
16% of jobs
$120.8K - $130.5K
7% of jobs
$130.5K - $140.3K
5% of jobs
$140.3K - $150K
3% of jobs
$43K
$99.4K
$150K
How much do cyber security operation center analyst jobs pay per year?
What does a Cyber Security Operation Center analyst do?
What are some common challenges faced by Cyber Security Operation Center analysts during incident response?
What are the key skills and qualifications needed to thrive as a Cyber Security Operation Center analyst, and why are they important?
What is the difference between Cyber Security Operation Center Analyst vs Security Analyst?
| Aspect | Cyber Security Operation Center Analyst | Security Analyst |
|---|---|---|
| Certifications | CompTIA Security+, CEH, CISSP (preferred) | CompTIA Security+, CISSP, GIAC certifications |
| Work Environment | Monitoring security systems in a SOC, 24/7 shifts | Analyzing security data, conducting risk assessments |
| Employer & Industry Usage | Primarily in security operations centers across various industries | In IT security teams within organizations or consulting firms |
While both roles focus on cybersecurity, a Cyber Security Operation Center Analyst primarily monitors and responds to security incidents in a SOC environment, often working in shifts. A Security Analyst conducts broader security assessments, analyzes threats, and develops security strategies. Both roles require similar certifications and are integral to organizational security, but their daily tasks and work settings differ.
What cities are hiring for Cyber Security Operation Center Analyst jobs?
Cities with the most Cyber Security Operation Center Analyst job openings:
What states have the most Cyber Security Operation Center Analyst jobs?
States with the most job openings for Cyber Security Operation Center Analyst jobs include:
What are popular job titles related to Cyber Security Operation Center Analyst jobs?
For Cyber Security Operation Center Analyst jobs, the most frequently searched job titles are:
Security Operations Center Analyst - Mid
Washington, DC • On-site
Full-time
Medical, Dental, Vision, Retirement, PTO
Re-posted 26 days ago
Job description
Koniag Data Solutions, LLC, a Koniag Government Services company, is seeking a Security Operations Center Analyst - Mid to support KDS and our government customer in Washington, DC. This position requires the candidate to be able to obtain a Public Trust.
We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.
Koniag Data Solutions, a Koniag Government Services company, is seeking a skilled Mid-Level Security Operations Center (SOC) Analyst to support the U.S. Small Business Administration (SBA). The ideal candidate is an experienced cybersecurity professional with a solid foundation in security event monitoring, threat detection, and incident response within a SOC environment. This individual will play an important role in protecting SBA's systems, networks, and data by actively monitoring for threats, analyzing security events, and supporting incident response activities in alignment with federal cybersecurity policies and SBA security requirements.
The Mid-Level SOC Analyst will serve as an experienced cybersecurity operations professional responsible for monitoring, detecting, analyzing, and supporting the response to cybersecurity threats targeting SBA's enterprise IT environment. Working under the guidance of the Cybersecurity Operations Technical Lead and Senior Cyber Defense Analysts, this individual will contribute meaningfully to all aspects of SOC operations while continuing to develop and refine their technical skills and expertise.
Principal responsibilities will include but are not limited to:
- Perform continuous monitoring of SBA networks, systems, endpoints, and cloud environments using SIEM platforms, IDS/IPS tools, EDR solutions, and other security technologies to detect and identify potential threats, anomalies, and indicators of compromise.
- Conduct analysis and triage of security events and alerts generated by SOC monitoring tools, determining the validity, scope, and severity of potential security incidents and escalating confirmed or suspected incidents to senior analysts and the Technical Lead in accordance with established procedures.
- Support incident response activities, including initial containment actions, evidence preservation, and coordination with senior analysts and the Technical Lead during active security incidents, following SBA's incident response policies and NIST SP 800-61 guidelines.
- Investigate security events and incidents by analyzing network traffic, system logs, endpoint telemetry, and other relevant data sources to identify the root cause, scope, and impact of potential security issues.
- Â Document security events, incidents, and investigative findings accurately and thoroughly in SBA's ticketing and case management systems, maintaining detailed records of all SOC activities in accordance with established documentation standards.
- Â Assist in the development and refinement of SIEM detection rules, correlation logic, and alerting thresholds under the guidance of senior analysts and the Technical Lead, contributing recommendations based on observed alert patterns and false positive analysis.
- Support threat hunting activities by executing predefined hunt playbooks and assisting senior threat hunters in the identification of indicators of compromise and malicious activity within SBA's environment.
- Monitor and analyze threat intelligence from government and commercial sources, including US-CERT, CISA, and relevant ISACs, to stay current on emerging threats and incorporate relevant intelligence into daily SOC monitoring and analysis activities.
- Â Assist in the development and maintenance of SOC Standard Operating Procedures (SOPs), incident response playbooks, and runbooks, contributing updates and improvements based on operational experience and lessons learned.
- Collaborate effectively with SBA IT teams, system owners, and other stakeholders to communicate security findings, support remediation coordination, and contribute to the improvement of SBA's overall security posture.
- Support vulnerability management activities by reviewing and analyzing vulnerability scan results, assisting with the identification of high-priority vulnerabilities, and coordinating with system owners on remediation tracking and follow-up.
- Participate in after-action reviews (AARs) and lessons learned sessions following significant security incidents, contributing observations and recommendations to improve SOC processes, procedures, and capabilities.
- Prepare and contribute to the development of security incident reports, shift handover reports, and other SOC documentation, ensuring accuracy, completeness, and adherence to established reporting standards.
- Participate in SOC team training activities, tabletop exercises, and professional development opportunities to continuously expand technical knowledge and skills in cybersecurity operations and threat analysis.
- Ensure all SOC activities comply with applicable federal cybersecurity frameworks, policies, and regulations, including NIST, FISMA, and DHS/CISA directives and guidance.
Education and Experience:
Required:
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field from an accredited college or university.
- Â Relevant work experience may be considered in lieu of a degree.
- 3+ years of experience in cybersecurity operations, security event monitoring, or a related field, with demonstrated experience working within a SOC or cyber defense environment.
- Demonstrated experience working with SIEM platforms and security monitoring tools in an operational environment.
- One or more of the following certifications:
- CompTIA Security+
- CompTIA Cybersecurity Analyst (CySA+)
- Certified SOC Analyst (CSA)
- Â GIAC Security Essentials (GSEC)
- GIAC Certified Incident Handler (GCIH)
- Systems Security Certified Practitioner (SSCP)
Desired:
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field.
- 5+ years of cybersecurity operations experience, with a focus on SOC operations within a federal government or defense contracting environment.
Required Skills and Competencies:
-  Strong communication skills in English – both written and oral – with the ability to clearly document and communicate security findings, incident details, and analytical results to both technical and non-technical audiences.
- Solid understanding of security event monitoring, alert triage, and incident response processes and procedures within a SOC environment.
- Â Working knowledge of SIEM platforms (e.g., Splunk, Microsoft Sentinel, ArcSight, or similar), including the ability to perform log searches, build basic queries, and analyze security event data to identify potential threats and anomalies.
- Foundational knowledge of network security concepts, including TCP/IP, DNS, HTTP/S, firewalls, IDS/IPS, and the ability to analyze basic network traffic patterns to identify potentially malicious activity
- Experience working with endpoint detection and response (EDR) tools and the ability to investigate host-based security alerts and identify indicators of compromise on endpoints
- Familiarity with the MITRE ATT&CK framework and the ability to apply ATT&CK tactics and techniques to the analysis and classification of security events and incidents.
- Ability to conduct log analysis across common data sources, including Windows Event Logs, Syslog, and application logs, to support security event investigation and incident response activities.
- Familiarity with threat intelligence concepts and the ability to leverage threat intelligence feeds and indicators of compromise (IOCs) to support security monitoring and analysis activities
- Â Knowledge of federal cybersecurity frameworks and compliance requirements, including NIST SP 800-53, NIST SP 800-61, and FISMA, and their application to SOC operations within a federal environment
- Â Ability to accurately document security events, incidents, and investigative findings in ticketing and case management systems in a clear, concise, and thorough manner.
- Strong analytical and problem-solving skills with the ability to assess security alerts and events, identify patterns of potentially malicious activity, and escalate findings appropriately.
- Ability to work effectively both independently and as part of a collaborative team in a fast-paced, mission-driven SOC environment, including the ability to manage multiple concurrent tasks and priorities
- Â Ability to obtain and maintain a Public Trust Clearance.
Desired Skills and Competencies:
- Â Prior experience supporting SBA or other federal civilian agency SOC operations or cybersecurity programs.
- Â Experience with cloud security monitoring in AWS, Azure, or GCP environments, including familiarity with cloud-native logging and monitoring services such as AWS CloudTrail, Azure Monitor, or Google Cloud Logging.
- Familiarity with Security Orchestration, Automation, and Response (SOAR) platforms and basic scripting capabilities in Python or PowerShell to support the automation of routine SOC tasks and workflows.
- Experience supporting vulnerability management activities, including working with vulnerability scanning tools such as Tenable Nessus, Qualys, or similar platforms.
- Â Knowledge of Zero Trust Architecture (ZTA) principles and their implications for security monitoring and SOC operations within a federal IT environment.
- Familiarity with the CDM (Continuous Diagnostics and Mitigation) program tools, data requirements, and their role in supporting federal civilian agency SOC operations.
- Â Experience participating in incident response activities and contributing to after-action reviews and lessons learned processes.
- Familiarity with digital forensics concepts and basic forensic investigation techniques to support the collection and preservation of digital evidence during incident response activities.
- GIAC Security Operations Certified (GSOC) or GIAC Certified Enterprise Defender (GCED) certification.
- Experience working within a FedRAMP authorized cloud environment and familiarity with FedRAMP security requirements as they relate to SOC monitoring and incident response activities.
Our Equal Employment Opportunity Policy
The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.
The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.
Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.
Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352