1

Soc Level 1 Analyst Jobs in Virginia (NOW HIRING)

Tier 1 SOC Analyst

Alexandria, VA · On-site

$78K - $105K/yr

Analyze endpoint, user-activity, and network-security alerts at the Tier 1 level and escalate ... SOC reporting. * Coordinate with Tier 2 analysts and other cybersecurity stakeholders to support ...

Tier 1 SOC Analyst

Alexandria, VA · On-site

$78K - $105K/yr

Analyze endpoint, user-activity, and network-security alerts at the Tier 1 level and escalate ... SOC reporting. * Coordinate with Tier 2 analysts and other cybersecurity stakeholders to support ...

Tier 1 SOC Analyst

Alexandria, VA · On-site

$78 - $105/hr

Analyze endpoint, user-activity, and network-security alerts at the Tier 1 level and elevate events ... SOC reporting. * Coordinate with Tier 2 analysts and other cybersecurity stakeholders to support ...

$80K/yr

Mid-Level SOC Analyst Location: HYBRID - Alexandria, VA Salary: $80k Clearance: Ability to obtain a ... Week 1: Wednesday through Saturday, 7:00 PM - 7:00 AM * Week 2: Sunday through Tuesday, 7:00 PM - 7 ...

... 1 CSOC Analyst. Candidates should have some work experience in Security Operations Centers (SOC ... Two years of related work experience may be substituted for each year of degree-level education.

Perform intermediate-level review of massive log files, pivot between data sets, and correlate ... In-depth knowledge of architecture, engineering, and operations of at least one enterprise SIEM ...

... 1 CSOC Analyst. Candidates should have some work experience in Security Operations Centers (SOC ... Two years of related work experience may be substituted for each year of degree-level education.

SOC Analyst

Alexandria, VA · On-site

$87K - $157K/yr

Perform intermediate-level review of massive log files, pivot between data sets, and correlate ... In-depth knowledge of architecture, engineering, and operations of at least one enterprise SIEM ...

SOC Analyst

Alexandria, VA · On-site

$150K - $165K/yr

The SOC Analyst will be responsible for monitoring, analyzing, investigating, and responding to ... DoD 8570 IAT Level II (or higher) certification prior to start date (CompTIA Security+, SSCP, etc.

The SOC Analyst will be responsible for monitoring, analyzing, investigating, and responding to ... DoD 8570 IAT Level II (or higher) certification prior to start date (CompTIA Security+, SSCP, etc.

next page

Showing results 1-20

Soc Level 1 Analyst information

See Virginia salary details

$32.7K

$75.6K

$122.9K

How much do soc level 1 analyst jobs pay per year?

As of Aug 29, 2026, the average yearly pay for soc level 1 analyst in Virginia is $75,619.00, according to ZipRecruiter salary data. Most workers in this role earn between $57,000.00 and $89,200.00 per year, depending on experience, location, and employer.

What is a SOC Level 1 analyst?

A SOC Level 1 Analyst is an entry-level cybersecurity professional who monitors and analyzes an organization's security systems for potential threats and incidents. Their main responsibilities include reviewing security alerts, triaging incidents, escalating issues to higher-tier analysts, and documenting findings. They play a critical role in the early detection of cyber threats and help maintain the overall security posture of the organization. SOC Level 1 Analysts usually work in Security Operations Centers (SOCs) and use various security tools, such as SIEM (Security Information and Event Management) platforms, to carry out their tasks. This position is ideal for individuals looking to start a career in cybersecurity.

What are the key skills and qualifications needed to thrive as a SOC Level 1 analyst?

To thrive as a SOC Level 1 Analyst, you need foundational knowledge of cybersecurity principles, incident response processes, and familiarity with network and system administration, often supported by a relevant degree or certifications like CompTIA Security+. Experience with security information and event management (SIEM) tools, ticketing systems, and basic scripting is typically required. Strong analytical thinking, attention to detail, and effective communication skills help analysts quickly identify and escalate potential threats. These skills and qualities are crucial to ensure timely detection of security incidents and accurate reporting, forming the first line of defense in an organization's cybersecurity posture.

What are some common challenges faced by SOC Level 1 analysts in their daily workflow?

SOC Level 1 Analysts often face the challenge of handling a high volume of security alerts, many of which may be false positives. Quickly triaging these alerts while maintaining accuracy is essential to ensure real threats are identified promptly. Additionally, analysts must communicate effectively with other team members and escalate incidents when necessary, all while continuing to develop their technical skills in a fast-paced, evolving threat landscape. Balancing these responsibilities can be demanding but offers valuable experience for career growth within cybersecurity.

What is the difference between Soc Level 1 Analyst vs Soc Level 2 Analyst?

AspectSoc Level 1 AnalystSoc Level 2 Analyst
CertificationsBasic security certifications (e.g., CompTIA Security+)Advanced certifications (e.g., GIAC Security Essentials)
Work EnvironmentMonitors security alerts, initial incident responsePerforms in-depth analysis, escalates complex issues
ResponsibilitiesInitial detection, alert triageIncident investigation, root cause analysis

The main difference between a Soc Level 1 Analyst and a Soc Level 2 Analyst lies in their responsibilities and expertise. Level 1 analysts handle initial alerts and basic troubleshooting, while Level 2 analysts perform more detailed investigations and escalate complex issues. Both roles require security knowledge, but Level 2 analysts typically have more experience and advanced certifications.

Infographic showing various Soc Level 1 Analyst job openings in Virginia as of August 2026, with employment types broken down into 93% Full Time, and 7% Contract. Highlights an 100% In-person job distribution, with an average salary of $75,619 per year, or $36.4 per hour.

Cybersecurity Officer (Entry to Senior Level) TS/SCI with Poly REQUIRED

Arlington, VA • On-site


CGI Inc.

7.1

Company rating: 7.1 out of 10

Based on 19 frontline employees who took The Breakroom Quiz

149th of 226 rated it services

Good employer

Paid breaks

Recommended by parents


Full-time

Retirement, PTO

Re-posted 7 days ago


Job description

Cybersecurity Officer (Entry to Senior Level) TS/SCI with Poly REQUIRED
Category: Cyber Security
Main location: United States, Virginia, Arlington
Position ID:J0726-1936
Employment Type: Full Time
Position Description:
CGI Federal has an exciting opportunity for a Cybersecurity Officers within our Intel sector advancing the national security mission through cutting edge technology. You must have a passion for keeping pace with rapidly evolving technology advancements and leveraging your knowledge on a highly collaborative team to deliver state-of-the-art capabilities.
The Cybersecurity Officer protects an organization's digital assets by monitoring systems for threats, investigating basic security alerts, and helping enforce company security rules. It is a foundational role focused on learning, triage, and assisting senior staff with day-to-day security operations.
CGI Federal is growing its high-performance team whose members share a passion for building high-quality, scalable, advanced IT solutions in a collaborative, fast-paced, outcome-driven mission.
This position is located in our Arlington office; however, a hybrid working model is acceptable.
Your future duties and responsibilities:
Key Responsibilities (Entry Level)
• System Monitoring: Watch security tools and dashboards for unusual network traffic or suspicious activity.
• Alert Triage: Review basic security alerts, determine if they are false alarms, and escalate real threats to senior team members.
• Access Management: Assist with granting or removing employee access to company software and sensitive files.
• Security Awareness: Help educate staff on security best practices, such as recognizing phishing emails.
• Incident Assistance: Follow established step-by-step procedures to respond to minor security incidents (e.g., locking a compromised account).
• Documentation: Write simple reports outlining diagnostic test results or security events.
Key Responsibilities (Junior Level)
Security Monitoring & Incident Response
• Monitor Alerts: Continuously review security logs and network traffic for suspicious activity, anomalies, or breaches.
• Triage Incidents: Serve as the first responder to basic security alerts, mitigating minor threats and collecting preliminary data.
• Escalation: Escalate complex or high-severity cyber attacks to Level 2 or Level 3 senior security teams.
Vulnerability Management
• Diagnostic Testing: Execute diagnostic tests and vulnerability scans to identify potential loopholes in systems and networks.
• Patch Management: Apply antivirus updates, firewall configurations, and security patches across enterprise systems.
• Report Generation: Document known vulnerabilities and draft regular system status reports for management.
Compliance & Governance
• Data Protection: Enforce organizational security policies and ensure adherence to statutory or regulatory requirements regarding information access and privacy.
• Access Control: Grant, review, and revoke user access credentials to maintain the principle of least privilege.
• Auditing: Conduct periodic security audits to measure compliance and identify inefficiencies.
Training & Awareness
• Phishing Prevention: Lead or assist in employee cybersecurity awareness training and phishing simulations.
• Resource Development: Provide technical consultation and security best-practice documentation to staff.
Key Responsibilities (Mid-Level)
• Incident Response & Triage: Lead the investigation of complex security alerts escalated from Level 1, determining root causes, scoping the blast radius, and executing rapid containment protocols.
• Threat Hunting & Vulnerability Management: Conduct proactive threat hunting using endpoint data, network telemetry, and actionable intelligence. Analyze system logs to identify abnormalities and suspicious network signals.
• Security Operations & Tooling: Configure, fine-tune, and deploy security solutions (e.g., SIEM, EDR, firewalls, and DLP). Author custom detection rules and detection playbooks.
• Risk Management & Compliance: Conduct enterprise-level risk assessments, enforce adherence to security legislation, and manage system security documentation (e.g., SSPs, ATO lifecycle, and security controls).
• Mentorship & Reporting: Guide junior SOC/Level 1 analysts, and communicate complex technical risks to executive leadership and IT teams through detailed post-mortem reports.
Key Responsibilities (Senior Level)
• Proactive Threat Hunting: Design, develop, and execute deep-dive threat hunting missions using hypothesis-driven methodologies to uncover deeply embedded, covert, and zero-day threats within the enterprise architecture.
• Malware Analysis & Reverse Engineering: Intercept, deconstruct, and analyze complex malware, ransomware, and malicious binaries to understand execution mechanisms, C2 infrastructure, and exfiltration pathways.
• Advanced Incident Management: Lead the technical command of catastrophic and nation-state-level security incidents. Conduct forensic analysis across endpoints, networks, and cloud infrastructures to establish root causes and execute surgical eradication and recovery protocols.
• Cryptographic & Security Architecture: Review highly complex system designs, microservices, and network topologies. Provide architectural oversight on encryption protocols, data-in-transit/at-rest safeguards, and secure hardware/software integrations.
• Vulnerability & Exploitation Research: Conduct authorized red-team-style exploitation testing to simulate real-world attacks. Bridge the gap between offensive and defensive operations by contributing directly to threat intelligence and secure coding hardening guides.
• Executive & Strategic Advising: Translate complex technical findings and threat landscapes into actionable, high-level strategic directives for executive leadership and stakeholders.
Required qualifications to be successful in this role:
All levels require an active TS/SCI with Poly
Entry Level:
• Education:
o High School Diploma/GED with 4 years of relevant experience,
o Associates Degree with 2 years of relevant experience,
o or Bachelor's Degree with 0 years of relevant experience
• Basic IT Knowledge: Understanding of computer networks (e.g., IP addresses, routers) and operating systems like Windows, macOS, or Linux.
• Problem-Solving: Strong critical thinking and the ability to research or "Google" answers when encountering unfamiliar issues.
• Communication: Ability to clearly explain technical issues to non-technical coworkers or management.
• Certifications: Foundational certifications such as CompTIA Security+, Network+, or ISC2 CC are highly recommended for beginners.
Junior Level/Moderate:
• Education:
o High School Diploma/GED with 6 years of relevant experience,
o Associates Degree with 4 years of relevant experience,
o Bachelor's Degree with 2 years of relevant experience,
o or Masters Degree with 0 years of relevant experience
• Certifications: Foundational certifications such as CompTIA Security+, [ISC]² CCSP, or [CodeHS] are highly valued.
• Technical Skills: Working knowledge of TCP/IP, firewalls, endpoint security, and intrusion detection systems.
Mid-Level/Complex:
• Education:
o High School Diploma/GED with 8 years of relevant experience,
o Associates Degree with 6 years of relevant experience,
o Bachelor's Degree with 4 years of relevant experience,
o or Masters Degree with 2 years of relevant experience,
o or PhD with 0 years of relevant experience
• Technical Proficiencies: Strong working knowledge of various operating systems (Linux, Windows, macOS), networking protocols (TCP/IP), and cloud architecture (AWS, Azure). Basic understanding of scripting languages (Python, PowerShell).
• Certifications: Industry-recognized certifications such as CompTIA Security+, GIAC Certified Incident Handler (GCIH), or Certified Information Systems Security Professional (CISSP).
Senior Level/Exceptionally Complex:
• Education:
o High School Diploma/GED with 10 years of relevant experience,
o Associates Degree with 8 years of relevant experience,
o Bachelor's Degree with 6 years of relevant experience,
o or Masters Degree with 4 years of relevant experience,
o or PhD with 2 years of relevant experience
• Certifications: Elite credentials such as CISSP, GIAC Security Expert (GSE), OSCP, or CCIE Security.
• Technical Proficiencies: Mastery of advanced SIEM, SOAR, and EDR platforms. Deep understanding of network protocols, cloud-native architecture security, and scripting/programming languages (Python, C, C++, or Assembly).
CGI is required by law in some jurisdictions to include a reasonable estimate of the compensation range for this role. The determination of this range includes various factors not limited to skill set, level, experience, relevant training, and licensure and certifications. To support the ability to reward for merit-based performance, CGI typically does not hire individuals at or near the top of the range for their role. Compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range for this role in the U.S. is $89,600.00 - $204,000.00.
CGI Federal's benefits are offered to eligible professionals on their first day of employment to include:
. Competitive compensation
. Comprehensive insurance options
. Matching contributions through the 401(k) plan and the share purchase plan
. Paid time off for vacation, holidays, and sick time
. Paid parental leave
. Learning opportunities and tuition assistance
. Wellness and Well-being programs
#CGIFederalJob
#LI-LB1
#ClearanceJobs
#CGIInternationalSecurity
What you can expect from us:
Together, as owners, let's turn meaningful insights into action.
Life at CGI is rooted in ownership, teamwork, respect and belonging. Here, you'll reach your full potential because...
You are invited to be an owner from day 1 as we work together to bring our Dream to life. That's why we call ourselves CGI Partners rather than employees. We benefit from our collective success and actively shape our company's strategy and direction.
Your work creates value. You'll develop innovative solutions and build relationships with teammates and clients while accessing global capabilities to scale your ideas, embrace new opportunities, and benefit from expansive industry and technology expertise.
You'll shape your career by joining a company built to grow and last. You'll be supported by leaders who care about your health and well-being and provide you with opportunities to deepen your skills and broaden your horizons.
Come join our team-one of the largest IT and business consulting services firms in the world.
Qualified applicants will receive consideration for employment without regard to their race, ethnicity, ancestry, color, sex, religion, creed, age, national origin, citizenship status, disability, pregnancy, medical condition, military and veteran status, marital status, sexual orientation or perceived sexual orientation, gender, gender identity, and gender expression, familial status or responsibilities, reproductive health decisions, political affiliation, genetic information, height, weight, or any other legally protected status or characteristics to the extent required by applicable federal, state, and/or local laws where we do business.
CGI provides reasonable accommodations to qualified individuals with disabilities. If you need an accommodation to apply for a job in the U.S., please email the CGI U.S. Employment Compliance mailbox at US_Employment_Compliance@cgi.com. You will need to reference the Position ID of the position in which you are interested. Your message will be routed to the appropriate recruiter who will assist you. Please note, this email address is only to be used for those individuals who need an accommodation to apply for a job. Emails for any other reason or those that do not include a Position ID will not be returned.
We make it easy to translate military experience and skills! Click here to be directed to our site that is dedicated to veterans and transitioning service members.
All CGI offers of employment in the U.S. are contingent upon the ability to successfully complete a background investigation. Background investigation components can vary dependent upon specific assignment and/or level of US government security clearance held. Dependent upon role and/or federal government security clearance requirements, and in accordance with applicable laws, some background investigations may include a credit check. CGI will consider for employment qualified applicants with arrests and conviction records in accordance with all local regulations and ordinances.
CGI will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with CGI's legal duty to furnish information.

What CGI employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom