Government Careers
  • Security Operation Center (SOC) Analyst II

  • System High
  • Colorado Springs, Colorado 80918 United States View Map

Position Overview Job Title: SOC Analyst (Security Operations Center) Location: Colorado Springs, CO Position Type: Full Time Shift: Day. The role requires a Top Secret (TS) with SCI eligibility and experience in Special Access Programs (SAP).Role Description The SOC Analyst provides comprehensive Computer Network Defense and Response support through 24×7×365 monitoring and analysis of potential threat activity targeting the enterprise. The position conducts security event monitoring, advanced analytics, and response activities to support the government's mission, supporting Special Access Programs and Sensitive Compartmented Information.Key Responsibilities Perform computer network defense operations, incident handling (detection, analysis, triage), hunting, and malware analysis.Analyze security events to discern legitimate incidents from non‑incidents, performing triage, investigation, countermeasure implementation, and incident response.Operate SIEM platforms and log management systems for collection, analysis, correlation, and alerting.Apply logical and critical thinking to analyze security events such as Windows event logs, network traffic, IDS alerts, and associated malicious intent.Track activities within Security Operations workflows with excellent organization and attention to detail.Understand operating systems (Windows, OSX, Linux), Windows Active Directory concepts, network communications, routing protocols (TCP, UDP, ICMP, BGP, MPLS etc.), and common internet applications and standards (SMTP, DNS, DHCP, SQL, HTTP, HTTPS).Identify and implement countermeasures or mitigating controls within an enterprise network environment.Use technologies such as Network Threat Hunting, Big Data Analytics, Endpoint Threat Detection and Response, SIEM, workflow and ticketing, and Intrusion Detection Systems.Qualifications 5–7 years related cybersecurity experience.Prior roles as ISSO or ISSM.Bachelor's degree in a related field, or equivalent experience (minimum 4 years).Certifications and Clearance Must meet DoD Directive 8570.01‑M requirements for Information Assurance Technician Level2, Information Assurance Manager Level2, CND Auditor, or Incident Responder certification within six months of hire.Current Top‑Secret clearance with SCI eligibility.Eligibility to access Special Access Program information.Willingness to submit to a counterintelligence polygraph.Other Requirements Develop rules, filters, views, signatures, countermeasures, and scripts to support analysis and detection.Research emerging threats and recommend monitoring content within security tools.Analyze NetFlow data and packet capture (PCAP).Robust knowledge of common attack methodologies, tactics, and protocols.Knowledge of TCP/IP suite, security architecture, DNS, and remote access security techniques and products.Technical experience with IDS/IPS, firewalls, log analysis, SIEM, network behavior analysis tools, antivirus, network packet analyzers, digital forensics tools, and cyber incident response in an enterprise environment.Equal Employment Opportunity System High Corporation is committed to equal employment opportunity and a diverse workplace. We do not discriminate based on race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender, gender identity or expression, veteran status, or any other characteristic protected by law.#J-18808-Ljbffr

Position Overview Job Title: SOC Analyst (Security Operations Center) Location: Colorado Springs, CO Position Type: Full Time Shift: Day. The role requires a Top Secret (TS) with SCI eligibility and experience in Special Access Programs (SAP).Role Description The SOC Analyst provides comprehensive Computer Network Defense and Response support through 24×7×365 monitoring and analysis of potential threat activity targeting the enterprise. The position conducts security event monitoring, advanced analytics, and response activities to support the government's mission, supporting Special Access Programs and Sensitive Compartmented Information.Key Responsibilities Perform computer network defense operations, incident handling (detection, analysis, triage), hunting, and malware analysis.Analyze security events to discern legitimate incidents from non‑incidents, performing triage, investigation, countermeasure implementation, and incident response.Operate SIEM platforms and log management systems for collection, analysis, correlation, and alerting.Apply logical and critical thinking to analyze security events such as Windows event logs, network traffic, IDS alerts, and associated malicious intent.Track activities within Security Operations workflows with excellent organization and attention to detail.Understand operating systems (Windows, OSX, Linux), Windows Active Directory concepts, network communications, routing protocols (TCP, UDP, ICMP, BGP, MPLS etc.), and common internet applications and standards (SMTP, DNS, DHCP, SQL, HTTP, HTTPS).Identify and implement countermeasures or mitigating controls within an enterprise network environment.Use technologies such as Network Threat Hunting, Big Data Analytics, Endpoint Threat Detection and Response, SIEM, workflow and ticketing, and Intrusion Detection Systems.Qualifications 5–7 years related cybersecurity experience.Prior roles as ISSO or ISSM.Bachelor's degree in a related field, or equivalent experience (minimum 4 years).Certifications and Clearance Must meet DoD Directive 8570.01‑M requirements for Information Assurance Technician Level2, Information Assurance Manager Level2, CND Auditor, or Incident Responder certification within six months of hire.Current Top‑Secret clearance with SCI eligibility.Eligibility to access Special Access Program information.Willingness to submit to a counterintelligence polygraph.Other Requirements Develop rules, filters, views, signatures, countermeasures, and scripts to support analysis and detection.Research emerging threats and recommend monitoring content within security tools.Analyze NetFlow data and packet capture (PCAP).Robust knowledge of common attack methodologies, tactics, and protocols.Knowledge of TCP/IP suite, security architecture, DNS, and remote access security techniques and products.Technical experience with IDS/IPS, firewalls, log analysis, SIEM, network behavior analysis tools, antivirus, network packet analyzers, digital forensics tools, and cyber incident response in an enterprise environment.Equal Employment Opportunity System High Corporation is committed to equal employment opportunity and a diverse workplace. We do not discriminate based on race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender, gender identity or expression, veteran status, or any other characteristic protected by law.#J-18808-Ljbffr

Government Careers

Government Careers

Government jobs offer stability, competitive benefits, and the chance to make a meaningful impact on your community and country.

Whether you’re starting your career or seeking new opportunities, these roles provide pathways for growth, security, and service.

Explore positions across a wide range of fields and take the first step toward a rewarding future in public service.

Show more

MORE JOBS