Security Operations Center Analyst Everforth ECS is seeking a Security Operations Center Analyst to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax. Please Note:
New
Security Operations Center Analyst Everforth ECS is seeking a Security Operations Center Analyst to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax. Please Note:
New
Security Operations Center Analyst Everforth ECS is seeking a Security Operations Center Analyst to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax. Please Note:
New
Everforth ECS is seeking a Security Operations Center Analyst to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax . Please Note: This position is contingent upon ...
New
Everforth ECS is seeking a Security Operations Center Analyst to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax . Please Note: This position is contingent upon ...
New
Everforth ECS is seeking a Security Operations Center Analyst to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax . Please Note: This position is contingent upon ...
New
Everforth ECS is seeking a Security Operations Center Analyst to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax . Please Note: This position is contingent upon ...
New
$55.20K - $126K/yr
Security Operations Center Analyst The Opportunity: As a security operations center (SOC) analyst, you're in the middle of the action, responding to and mitigating threats in real time. You're the ...
$55.20K - $126K/yr
Security Operations Center Analyst The Opportunity: As a security operations center (SOC) analyst, you're in the middle of the action, responding to and mitigating threats in real time. You're the ...
Washington, DC · On-site
$55.20K - $126K/yr
Share Security Operations Center Analyst The Opportunity: As a security operations center (SOC) analyst, you're in the middle of the action, responding to and mitigating threats in real time. You're ...
Washington, DC · On-site
$55.20K - $126K/yr
Share Security Operations Center Analyst The Opportunity: As a security operations center (SOC) analyst, you're in the middle of the action, responding to and mitigating threats in real time. You're ...
Washington, DC · On-site
$55.20K - $126K/yr
Security Operations Center Analyst The Opportunity: As a security operations center (SOC) analyst, you're in the middle of the action, responding to and mitigating threats in real time. You're the ...
Washington, DC · On-site
$55.20K - $126K/yr
Security Operations Center Analyst The Opportunity: As a security operations center (SOC) analyst, you're in the middle of the action, responding to and mitigating threats in real time. You're the ...
The Global Security Operations Center (GSOC) Supervisor maintains full accountability for the GSOC and its personnel, systems, and procedures to ensure effective and timely response to alarms, calls ...
The Global Security Operations Center (GSOC) Supervisor maintains full accountability for the GSOC and its personnel, systems, and procedures to ensure effective and timely response to alarms, calls ...
The Global Security Operations Center (GSOC) Supervisor maintains full accountability for the GSOC and its personnel, systems, and procedures to ensure effective and timely response to alarms, calls ...
The Global Security Operations Center (GSOC) Supervisor maintains full accountability for the GSOC and its personnel, systems, and procedures to ensure effective and timely response to alarms, calls ...
The Global Security Operations Center (GSOC) Supervisor maintains full accountability for the GSOC and its personnel, systems, and procedures to ensure effective and timely response to alarms, calls ...
The Global Security Operations Center (GSOC) Supervisor maintains full accountability for the GSOC and its personnel, systems, and procedures to ensure effective and timely response to alarms, calls ...
RESPONSIBILITIES In the role of Access Security Operations Center (ASOC) Supervisor, you will be a crucial member of a team of security professionals dedicated to detecting and preventing acts of ...
RESPONSIBILITIES In the role of Access Security Operations Center (ASOC) Supervisor, you will be a crucial member of a team of security professionals dedicated to detecting and preventing acts of ...
RESPONSIBILITIES In the role of Access Security Operations Center (ASOC) Supervisor, you will be a crucial member of a team of security professionals dedicated to detecting and preventing acts of ...
RESPONSIBILITIES In the role of Access Security Operations Center (ASOC) Supervisor, you will be a crucial member of a team of security professionals dedicated to detecting and preventing acts of ...
The Global Security Operations Center (GSOC) Supervisor maintains full accountability for the GSOC and its personnel, systems, and procedures to ensure effective and timely response to alarms, calls ...
Quick apply
The Global Security Operations Center (GSOC) Supervisor maintains full accountability for the GSOC and its personnel, systems, and procedures to ensure effective and timely response to alarms, calls ...
The Security Operations Center Analyst supports the War Data Platform's continuous monitoring mission by performing threat detection, incident investigation, and response operations across various ...
New
The Security Operations Center Analyst supports the War Data Platform's continuous monitoring mission by performing threat detection, incident investigation, and response operations across various ...
New
The security operations center lead sme is the senior cybersecurity operations authority within the wdp core integration program, responsible for directing continuous monitoring, threat detection ...
The security operations center lead sme is the senior cybersecurity operations authority within the wdp core integration program, responsible for directing continuous monitoring, threat detection ...
... Security Operations Center Lead SME is the senior cybersecurity operations authority within the WDP Core Integration program, responsible for directing continuous monitoring, threat detection, and ...
... Security Operations Center Lead SME is the senior cybersecurity operations authority within the WDP Core Integration program, responsible for directing continuous monitoring, threat detection, and ...
... Security Operations Center Lead SME is the senior cybersecurity operations authority within the WDP Core Integration program, responsible for directing continuous monitoring, threat detection, and ...
... Security Operations Center Lead SME is the senior cybersecurity operations authority within the WDP Core Integration program, responsible for directing continuous monitoring, threat detection, and ...
Security Operations Center (SOC) Manager Location: Washington, DC (On-Site) Clearance: Active Public Trust, Secret, or higher required Position Overview The SOC Manager provides strategic and ...
Security Operations Center (SOC) Manager Location: Washington, DC (On-Site) Clearance: Active Public Trust, Secret, or higher required Position Overview The SOC Manager provides strategic and ...
About the job Security Operations Center (SOC) Analyst We are seeking a skilled and detail-oriented Security Operations Center (SOC) Analyst to join our team. As a SOC Analyst, you will be ...
About the job Security Operations Center (SOC) Analyst We are seeking a skilled and detail-oriented Security Operations Center (SOC) Analyst to join our team. As a SOC Analyst, you will be ...
Security Operations Center (SOC) Manager Location: Washington, DC (On-Site) Clearance: Active Public Trust, Secret, or higher required Position Overview The SOC Manager provides strategic and ...
Security Operations Center (SOC) Manager Location: Washington, DC (On-Site) Clearance: Active Public Trust, Secret, or higher required Position Overview The SOC Manager provides strategic and ...
Security Operations Center (SOC) Manager Location: Washington, DC (On-Site) Clearance: Active Public Trust, Secret, or higher required Position Overview The SOC Manager provides strategic and ...
Quick apply
Security Operations Center (SOC) Manager Location: Washington, DC (On-Site) Clearance: Active Public Trust, Secret, or higher required Position Overview The SOC Manager provides strategic and ...
$8.38 - $10.37
3% of jobs
$10.37 - $12.36
0% of jobs
$12.36 - $14.34
0% of jobs
$14.34 - $16.33
2% of jobs
$18.29 is the 25th percentile. Wages below this are outliers.
$16.33 - $18.31
20% of jobs
$18.31 - $20.30
24% of jobs
The median wage is $20.35 / hr.
$20.30 - $22.29
22% of jobs
$22.65 is the 75th percentile. Wages above this are outliers.
$22.29 - $24.27
19% of jobs
$24.27 - $26.26
7% of jobs
$26.26 - $28.25
1% of jobs
$28.25 - $30.23
1% of jobs
$8
$20
$30
Everforth ECS is seeking a Security Operations Center Analyst to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax. Please Note: This position is contingent upon contract award.
The War Data Platform (WDP) is a key initiative within the U.S. Department of War's (DoW) AI-First strategy introduced in early 2026. The WDP separates business and financial data from operational warfighting data, aiming to accelerate the deployment of artificial intelligence (AI) on the battlefield. The WDP extends to Unclassified, Secret, and Top Secret environments, and supports collaboration between Combatant Commands, Joint Staff directorates, Senior Executive Service leaders, and operational analysts.
The Security Operations Center Analyst supports WDP's 24/7 continuous monitoring mission by performing structured threat detection, incident investigation, and response operations across NIPRNet, SIPRNet, and JWICS. This role operates within an integrated SOC environment leveraging Splunk SIEM, SOAR-driven automation, and AI-assisted triage capabilities to identify adversary behavior, contain incidents, and sustain cyber defense resilience across WDP's classified and unclassified mission enclaves.
• Executes continuous security monitoring operations across classified and unclassified DoW networks, supporting mission systems operating on NIPRNet, SIPRNet, and JWICS.
• Analyzes security events generated by enterprise Security Information and Event Management platforms including Splunk and Elastic, correlating host, network, and application telemetry to identify anomalous activity and potential adversary behavior.
• Conducts structured incident investigations using established incident response playbooks aligned to DoW Cyber Incident Handling Program guidance, documenting findings within ServiceNow and SharePoint tracking repositories.
• Performs proactive threat hunting activities leveraging MITRE ATT&CK mappings, endpoint telemetry, network flow data, and log analytics to detect previously unidentified threats.
• Coordinates containment and remediation actions with system administrators, ISSOs, and vulnerability management teams, supporting rapid mitigation of malware, unauthorized access, and policy violations.
• Maintains detailed incident records, forensic timelines, and evidentiary artifacts supporting after-action reporting and continuous monitoring requirements under the Risk Management Framework.
• Tunes detection logic, refines correlation rules, and contributes to improvement of SOC use cases to reduce false positives and increase detection fidelity.
• Provides technical mentorship to junior analysts through peer review of investigations and collaborative shift handovers.
• Delivers operational reporting products including incident summaries, alert trend analysis, and threat activity assessments supporting operational readiness, cyber defense resilience, and mission assurance across combat support and intelligence environments.
• Performs other duties as assigned.
• Current Secret security clearance with the ability to obtain and maintain a Top Secret (TS) security clearance.
• A minimum of 3 years of experience in security operations, cyber threat analysis, or incident response within a federal, defense, or intelligence community environment, with demonstrated hands-on proficiency performing continuous monitoring and structured incident investigations using enterprise SIEM platforms such as Splunk or Elastic across multi-enclave network environments.
• Active IAM Level I certification, satisfied by one of the following: CompTIA Security+ CE, ISC² CAP, ISC² SSCP, or GIAC GSLC.
• Strong problem-solving and decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution.
• Highly developed interpersonal and oral/written communication skills, with the ability to effectively and professionally interact with a diverse set of stakeholders (from peers to end-users to executive management).