Job Summary:
ECS is seeking a SOC CTIC Technician - Senior to support the Army National Guard's Cybersecurity Operations. The role involves assisting threat intelligence operations, updating detection content, and producing reports to enhance SOC situational awareness and continuous monitoring compliance.
Responsibilities:
• Collect, organize, and maintain cyber threat indicators, observables, and related analytic data to support SOC threat intelligence operations.
• Assist senior analysts with enrichment of indicators and events to improve threat context, prioritization, and operational awareness.
• Update and refine detection content under senior guidance to support continuous monitoring and threat-informed defense across ARNG network environments.
• Produce summary reports, analytic notes, and supporting documentation that enhance SOC situational awareness and support continuous monitoring compliance.
• Support MITRE ATT&CK-aligned analysis activities by helping map indicators and observed behaviors to adversary tactics, techniques, and procedures.
• Contribute to USIEM analytic support by organizing relevant data inputs and assisting with correlation activities that improve detection quality.
• Help maintain awareness of data feeds used in the ARNG cyber environment, including sources such as Zeek metadata and Sysmon-based monitoring, to support more effective detections.
• Coordinate analytic support activities with SOC personnel and related cybersecurity teams operating in conjunction with NETCOM Global Cyber Center and DISA DCDC.
• Assist with documentation and reporting that support 24x7x365 cybersecurity operations defending ARNG classified and unclassified enclaves across the DoDIN-Army-NG area of responsibility.
Qualifications:
Required:
• U.S. Citizenship is required
• Security Clearance: Secret Eligible
• Required Certifications: DCWF Work Role 511-Cyber Defense Analyst — Basic proficiency; must hold ONE OR MORE of the following: CC, CEH, GFACT, GISF
• 1+ years of experience in cybersecurity
• Experience collecting, organizing, and tracking threat indicators and related analytic artifacts in support of cyber defense operations.
• Ability to assist with indicator enrichment and prepare concise summary reporting for SOC or cybersecurity operations teams.
• Familiarity with continuous monitoring concepts and documentation practices used to support cybersecurity compliance activities.
• Exposure to SIEM-driven analysis workflows and security event correlation in an enterprise environment.
• Ability to follow senior guidance to update detection content and maintain supporting analytic documentation.
• Working knowledge of MITRE ATT&CK-based analytic methods for organizing and interpreting threat activity.
Preferred:
• Security Clearance: Active Secret (preferred)
• Experience supporting SOC, CTI, or cyber defense activities in a DoD or Army enterprise environment.
• Familiarity with USIEM operations or integrated SIEM/C2C/DLP analytic environments.
• Exposure to data sources used for advanced detection engineering, such as Zeek metadata or Sysmon monitoring.
• Experience supporting cyber operations across both classified and unclassified enclaves.
• Familiarity with ARNG, NETCOM, or DISA-coordinated cybersecurity operations and reporting processes.
Company:
Everforth ECS is the federal segment of Everforth, a $4B global organization with over 10,000 employees. Founded in 2001, the company is headquartered in Fairfax, USA, with a team of 1001-5000 employees. The company is currently Late Stage.