Cybersecurity Analyst, Security Operations Center (SOC) Analyst

Digital Global Connectors

McLean, UShybridPosted Jul 28, 2026
Posting intelligenceActively listed

Skills

jira

About the role

Cybersecurity Analyst – Tier 1 (Security Operations Center Analyst)

Location: Bethesda, MD (Hybrid; On-site as Required)

Clearance: Tier 2 Public Trust (Required)

Employment Type: Full-Time

Position Summary

Digital Global Connectors (DGC) is seeking a motivated Cybersecurity Analyst – Tier 1 (Security Operations Center Analyst) to support a Federal information security program. The Tier 1 SOC Analyst serves as the first line of defense in monitoring, detecting, analyzing, documenting, and escalating cybersecurity events affecting enterprise information systems and networks.

This position is responsible for continuous monitoring of security tools, initial incident triage, alert validation, event correlation, ticket management, and coordination with higher-tier cybersecurity personnel. The analyst helps identify potential threats, supports incident response activities, and contributes to maintaining a strong enterprise cybersecurity posture through proactive monitoring and timely reporting.

The successful candidate will possess strong analytical skills, experience working within a Security Operations Center (SOC), and a solid understanding of cybersecurity principles, network operations, and security monitoring technologies.

Essential Duties and Responsibilities:

Security Monitoring

Monitor enterprise security monitoring platforms for cybersecurity events and alerts.

Identify, review, and validate potential security incidents.

Analyze security events to determine severity, priority, and potential business impact.

Continuously monitor enterprise networks, systems, endpoints, cloud environments, and applications.

Escalate suspicious activity requiring advanced investigation.

Maintain situational awareness of the organization's security posture.

Event Analysis and Triage

Perform initial analysis of security alerts generated by SIEM, EDR, IDS/IPS, and other security technologies.

Correlate alerts from multiple security platforms.

Distinguish false positives from legitimate security events.

Categorize and prioritize security events based on established procedures.

Document findings and recommended actions.

Initiate incident response procedures when appropriate.

Incident Response Support

Support Tier 2 Incident Responders during security investigations.

Collect preliminary evidence supporting incident analysis.

Preserve relevant logs and security artifacts.

Assist with containment activities under senior analyst guidance.

Update incident records throughout the investigation lifecycle.

Participate in post-incident documentation and lessons learned.

Security Tool Operations

Operate and monitor technologies including:

Microsoft Sentinel

Splunk Enterprise Security

Microsoft Defender XDR

Microsoft Defender for Endpoint

Microsoft Defender for Identity

Microsoft Defender for Cloud

CrowdStrike Falcon

Palo Alto Cortex XDR

Trellix

Cisco Secure

Security Information and Event Management (SIEM)

Endpoint Detection and Response (EDR)

Extended Detection and Response (XDR)

Intrusion Detection and Prevention Systems (IDS/IPS)

Assist in identifying operational issues affecting monitoring platforms and coordinate with engineering teams as needed.

Threat Detection

Monitor indicators of compromise (IOCs) and indicators of attack (IOAs).

Identify suspicious user activity, anomalous network behavior, and unauthorized access attempts.

Recognize malware infections, phishing attempts, credential misuse, and policy violations.

Review threat intelligence provided by internal and external sources.

Support implementation of updated detection rules and monitoring use cases.

Ticket and Case Management

Create, update, and maintain incident tickets.

Document investigation activities, findings, and recommendations.

Track incidents through resolution.

Ensure complete and accurate case documentation.

Escalate unresolved issues according to established procedures.

Maintain audit-ready documentation supporting security operations.

Reporting and Documentation

Develop and maintain:

Incident Reports

Alert Summaries

Daily Operations Reports

Shift Handover Reports

Security Event Logs

Investigation Notes

Trend Reports

Metrics Dashboards

Lessons Learned Documentation

Standard Operating Procedures

Ensure documentation is complete, accurate, and supports operational continuity.

Collaboration

Coordinate with Tier 2 Incident Responders, Threat Hunters, Security Engineers, ISSOs, Vulnerability Management personnel, and technical support teams.

Participate in operational briefings and shift turnover meetings.

Communicate security findings clearly to technical and non-technical stakeholders.

Support cross-functional cybersecurity initiatives.

Maintain effective working relationships across cybersecurity disciplines.

Continuous Improvement

Stay current with emerging cyber threats, attack techniques, and defensive technologies.

Recommend improvements to monitoring procedures and operational workflows.

Participate in tabletop exercises, incident response drills, and training events.

Assist in refining detection logic and operational playbooks.

Pursue professional development and relevant cybersecurity certifications.

Minimum Qualifications

Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a related discipline.

Minimum two (2) years of experience supporting cybersecurity operations or a Security Operations Center (SOC).

Experience monitoring SIEM, EDR, or related cybersecurity technologies.

Understanding of networking concepts, operating systems, common attack techniques, and cybersecurity fundamentals.

Experience documenting security events and supporting incident investigations.

Strong analytical, organizational, and communication skills.

Ability to work rotating shifts, evenings, weekends, holidays, or on-call schedules as required.

U.S. Citizenship required.

Ability to obtain and maintain a Tier 2 Public Trust.

Preferred Qualifications

Experience supporting a Federal civilian agency.

Experience using Microsoft Sentinel, Splunk Enterprise Security, Microsoft Defender XDR, or comparable enterprise security platforms.

Experience supporting incident response or vulnerability management activities.

Familiarity with the MITRE ATT&CK Framework.

CompTIA Security+

CompTIA CySA+

GIAC Security Essentials (GSEC)

Microsoft Certified: Security Operations Analyst Associate (SC-200)

Splunk Core Certified User or Power User

Cisco CyberOps Associate (preferred)

Knowledge, Skills, and Abilities

Security Operations Center (SOC) Operations

Security Monitoring

Security Information and Event Management (SIEM)

Microsoft Sentinel

Splunk Enterprise Security

Endpoint Detection and Response (EDR)

Extended Detection and Response (XDR)

Microsoft Defender XDR

Microsoft Defender for Endpoint

Microsoft Defender for Cloud

Incident Triage

Event Correlation

Log Analysis

Threat Detection

Malware Identification

Phishing Analysis

Network Security

TCP/IP

Windows Security

Linux Security

MITRE ATT&CK Framework

NIST Cybersecurity Framework

NIST Risk Management Framework (RMF)

Ticket Management

Technical Documentation

Microsoft Office Suite

ServiceNow

Jira

Security Requirements

Ability to successfully obtain and maintain a Tier 2 Public Trust investigation.

Compliance with all applicable Federal security, privacy, ethics, and information assurance training requirements before receiving system access.

Ability to support 24x7 cybersecurity operations, emergency response activities, scheduled maintenance windows, continuity of operations (COOP), and surge support as required.

Must maintain strict confidentiality while handling sensitive security events, log data, investigation records, and Federal information systems.

Ability to work effectively in a fast-paced Security Operations Center environment while providing timely monitoring, accurate incident documentation, and responsive support to Government stakeholders and cybersecurity teams.

Questions about this role

Click "Apply with AI Applyd" above and you are done. Your resume is rewritten for this advert, the screening questions are answered, and it is submitted on Digital Global Connectors's own hiring system. No retyping your history, no fourteen tabs, no evening lost.

Compensation for Security Engineer roles in United States varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Security Engineer hub for United States medians across recent openings.

You never touch the form - the application is filled and submitted for you on Digital Global Connectors's own hiring system. It is not marked sent when we press submit. It is marked sent when a confirmation from their system arrives at the address we apply with, and your dashboard shows which stage each application is at until then.

Twelve applicant tracking systems have a real apply path: Workday, Greenhouse, Lever, Ashby, Workable, iCIMS, Personio, Recruitee, Teamtailor, Rippling, Breezy and SmartRecruiters. Your application goes in on the employer's own hiring system, never into an aggregator queue.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.