1

Soc Cyber Security Jobs in Virginia (NOW HIRING)

Information Security Advisor

Merrifield, VA ยท On-site

$100 - $130/hr

They work closely with the SOC manager and leads, mentor junior staff, assist to refine SOC processes, and ensure the organization maintains a strong cybersecurity posture. They collaborate with ...

SOC Lead

Alexandria, VA

$131K - $237K/yr

Our Cybersecurity team performs cyber defensive actions in support of J6 to prevent, detect, respond and recover from adversarial activities. The SOC consists of a variety of highly-skilled ...

New

Candidates should have some work experience in Security Operations Centers (SOC), Cyber Security Operations Centers (CSOC), and Cyber Incident Response Team (CIRT). The Tier 1 Analysts receive all ...

SOC Lead

Alexandria, VA ยท On-site

$131K - $237K/yr

Our Cybersecurity team performs cyber defensive actions in support of J6 to prevent, detect, respond and recover from adversarial activities. The SOC consists of a variety of highly-skilled ...

New

Ready to take your cybersecurity experience beyond routine alert monitoring? Leidos Enterprise ... You'll join a high-visibility Security Operations Center (SOC) providing 24x7x365 defensive cyber ...

New

Support Security Operations Center (SOC) activities, including threat monitoring, alert analysis ... Ensure compliance with cybersecurity standards, frameworks, and government regulations (e.g., NIST ...

Ready to take your cybersecurity experience beyond routine alert monitoring? Leidos Enterprise ... You'll join a high-visibility Security Operations Center (SOC) providing 24x7x365 defensive cyber ...

SOC Analyst

Alexandria, VA ยท On-site

$150K - $165K/yr

The SOC Analyst will be responsible for monitoring, analyzing, investigating, and responding to ... Identify, investigate, and respond to cybersecurity incidents and suspected system compromises ...

The SOC Analyst will be responsible for monitoring, analyzing, investigating, and responding to ... Identify, investigate, and respond to cybersecurity incidents and suspected system compromises ...

Cybersecurity Engineer

Richmond, VA ยท On-site

$120 - $180/hr

Knowledge of security frameworks such as MITRE ATT&ACK and compliance standards including NIST, HIPAA, or SOC 2 * Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a ...

next page

Showing results 1-20

Soc Cyber Security information

What is a SOC Cyber Security professional?

SOC Cyber Security professionals are specialists who work within a Security Operations Center (SOC), where they monitor, detect, analyze, and respond to cybersecurity incidents. Their primary role is to protect an organization's information systems from cyber threats by using various tools and processes to identify suspicious activities. These professionals often work in shifts to provide 24/7 security coverage, investigate security alerts, and help mitigate potential breaches. They also create reports, support incident response efforts, and continuously improve security measures based on emerging threats.

What are the key skills and qualifications needed to thrive as a SOC Cyber Security analyst?

To thrive as a SOC Cyber Security Analyst, you need a solid understanding of network security, threat analysis, and incident response, often supported by a degree in cybersecurity or information technology. Familiarity with Security Information and Event Management (SIEM) tools such as Splunk, intrusion detection systems, and certifications like CompTIA Security+ or CISSP are typically required. Strong analytical thinking, attention to detail, and clear communication are crucial soft skills for effectively identifying and mitigating threats. These skills and qualifications are essential to quickly detect, analyze, and respond to cyber threats, ensuring the organization's information assets remain secure.

What are some common challenges faced by SOC Cyber Security professionals during incident response, and how are they typically addressed?

SOC Cyber Security professionals often face challenges such as rapidly identifying genuine threats among false positives, coordinating response actions across teams, and managing high-pressure situations when incidents occur. Effective incident response requires strong analytical skills, communication, and well-established protocols to ensure swift remediation. Many SOCs use automation tools and regular training exercises to streamline processes and improve collaboration, enabling teams to respond efficiently and minimize potential damage.

What is the difference between Soc Cyber Security vs Security Analyst?

AspectSoc Cyber SecuritySecurity Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, CISSP, CEH
Work EnvironmentSecurity Operations Center (SOC), 24/7 monitoringOffice or remote, analyzing security data
Employer & IndustryIT security firms, large corporations, government agenciesVarious industries including finance, healthcare, tech

Both roles require similar certifications and often work in security-focused environments. However, Soc Cyber Security professionals typically operate within a SOC, focusing on real-time monitoring and incident response, while Security Analysts analyze security data to identify threats. The roles are complementary but differ mainly in daily responsibilities and work setting.

Is SOC Cyber Security analyst still in demand?

SOC Cyber Security analysts are in high demand due to increasing cyber threats and the need for organizations to monitor and respond to security incidents. The role requires skills in threat detection, incident response, and familiarity with security tools like SIEM systems, and job growth is expected to remain strong in the coming years.

Is SOC cyber security an entry level job?

A Security Operations Center (SOC) cybersecurity role can be entry level, especially for positions like SOC analyst or technician, which often require basic knowledge of security tools, networking, and monitoring. However, more advanced SOC roles may require prior experience, certifications such as CompTIA Security+ or Certified SOC Analyst, and a solid understanding of cybersecurity principles.

What does SOC do in cyber security?

A Security Operations Center (SOC) in cyber security is a team responsible for monitoring, detecting, and responding to security threats and incidents. SOC analysts use tools like SIEM systems to analyze security data, investigate alerts, and coordinate incident response to protect organizational assets. They often work in shifts to ensure 24/7 security coverage and may hold certifications such as CISSP or CEH.

What are popular job titles related to Soc Cyber Security jobs in Virginia?

For Soc Cyber Security jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Soc Cyber Security jobs in Virginia look for?

The top searched job categories for Soc Cyber Security jobs in Virginia are:

Infographic showing various Soc Cyber Security job openings in Virginia as of August 2026, with employment types broken down into 79% Full Time, 19% Part Time, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution.

Senior SOC Analyst at NTT DATA, Inc. Merrifield, VA

Merrifield, VA โ€ข On-site

$140 - $180/hr

Other

Posted 23 days ago


Job description

Senior SOC Analyst โ€“ NTT DATA, Merrifield, VA.

We are currently seeking a Senior SOC Analyst to join our team in Merrifield, Virginia. The Senior SOC Analyst is a key member of the 24/7/365 Security Operations Center, serving as the escalation point for advanced investigations, incident response, and proactive threat hunting.

Job Summary

The Senior SOC Analyst conducts higher-level analysis than other analysts on the team. This role performs deep forensic investigations, correlates multi-source threat intelligence information, and guides containment and remediation strategies. The analyst identifies and mitigates advanced threats across enterprise IT endpoints, cloud environments, and OT systems, leveraging frameworks such as the MITRE ATT&CK framework to detect, disrupt, and prevent malicious activity from occurring in the enterprise environment.

Duties and Responsibilities
  1. Lead advanced incident detection, investigation, and analysis efforts.

    1. Correlate SIEM, EDR, IDS/IPS, and firewall data to identify and analyze potential incidents.

    2. Perform deepโ€‘dive investigations to determine root cause, scope, and impact of incidents.

    3. Apply MITRE ATT&CK and other frameworks for adversary TTP identification.

    4. Conduct killโ€‘chain and supplyโ€‘chain analysis to understand and counter threats.

  2. Coordinate and direct complex incident response activities.

    1. Guide preparation, identification, containment, eradication, and recovery actions in collaboration with SOC, forensics, and engineering teams.

    2. Serve as the primary escalation point for highโ€‘impact or advanced incidents.

    3. Ensure incident handling aligns with established guidelines, response plans, and playbooks.

  3. Conduct proactive threat hunting to identify emerging risks.

    1. Analyze telemetry, logs, and behavioral patterns for indicators of compromise or attack.

    2. Hunt for advanced persistent threats and undiscovered vulnerabilities.

    3. Use advanced queries in SOC cybersecurity tools to detect anomalous or suspicious activity.

  4. Work with forensic teams to ensure proper forensic collection, preservation, and analysis of digital evidence.

    1. Coordinate with forensics teams to ensure chainโ€‘ofโ€‘custody and evidence integrity.

    2. Extract and analyze relevant artifacts to support investigations and postโ€‘incident reviews.

    3. Document and communicate forensic findings to stakeholders.

  5. Develop and enhance SOC processes, playbooks, and detection capabilities.

    1. Refine detection rules, alert thresholds, and automation workflows in SIEM/SOAR platforms and other cybersecurity tools.

    2. Create SOPs, knowledge base articles, and training materials for SOC staff.

    3. Recommend and guide implementation of new detection and analysis tools.

  6. Perform threat intelligence collection, analysis, and dissemination.

    1. Gather threat data from internal, classified, and openโ€‘source intelligence feeds.

    2. Analyze and contextualize intelligence to produce actionable recommendations.

    3. Share relevant threat information with SOC, leadership, and partner teams.

  7. Mentor and train SOC analysts to improve investigative capabilities and analytical thought process.

    1. Provide realโ€‘time guidance during active incidents.

    2. Conduct regular training sessions, tabletop exercises, and red/blue team drills.

    3. Validate analyst findings and provide feedback to provoke thought, improve accuracy, and investigative thoroughness.

  8. Collaborate with stakeholders to strengthen overall cybersecurity posture.

    1. Work with engineering, IT, and cloud teams to address identified vulnerabilities.

    2. Participate in tool evaluations, recommending solutions that enhance SOC capabilities and identify capability overlap.

    3. Support internal coordination with client sections, divisions, and external entities.

  9. Maintain documentation and reporting for SOC operations.

    1. Record investigative steps, evidence, and incident timelines in case management systems.

    2. Generate incident reports, trend analyses, and postโ€‘mortem summaries.

    3. Provide executiveโ€‘level briefings on security events and SOC performance.

Basic Qualifications
  • Masterโ€™s degree in Information Technology, Cybersecurity, Data Science, Information Systems, or Computer Science from an ABET accredited or CAE designated institution.
  • Oneโ€‘andโ€‘oneโ€‘half (1.5) years of additional experience can substitute for one (1) year of a typical degree program.
  • Minimum eight years of experience in Information Technology (IT) and/or Information Security (IS).
  • DoD 8140 certification for the respective area, or the ability to obtain certification within six (6) months of onboarding.
  • Active Secret Security Clearance.
  • Must be a US Citizen who lives within a commutable distance to the clientโ€™s sites in Arlington or Merrifield, VA.
Preferred Qualifications
  • Cyber Defense Analyst advanced certifications including:
  • CBROPS, CFR, CompTIA CySA+, Security+ CE, CASP+ CE, FITSPโ€‘O, SANS GCFA, GCIA, GDSA, GICSP, CCNAโ€‘Security, CCNP Security, CISSP (or associate), CCSP, CISA, SSCP, CND.
Equal Employment Opportunity Statement

NTT DATA is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. For Pay Transparency information, please click here.

#J-18808-Ljbffr