$125,228 monthly
Sandy Mac Evolution LLC is seeking a highly skilled Security Operations Center (SOC) Analyst II to provide comprehensive Computer Network Defense, cybersecurity monitoring, threat analysis, and incident response support at Schriever AFB, Colorado.
The selected candidate will support continuous 24Ã7Ã365 security monitoring and analysis of potential cyber threats targeting enterprise systems and networks. The SOC Analyst will conduct security event triage, advanced analytics, threat hunting, incident investigation, malware analysis, and response activities supporting the government’s mission.
This position supports Department of Defense Special Access Programs and organizations such as Headquarters Air Force, the Office of the Secretary of Defense, and Military Department compartmented programs. The SOC Analyst will provide day -to -day cybersecurity support for Collateral, Sensitive Compartmented Information, and Special Access Program environments.
Monitor enterprise systems, networks, applications, and security platforms for suspicious or malicious activity.
Analyze cybersecurity alerts and information technology security events to distinguish legitimate security incidents from false positives and non -incidents.
Lead or support incident handling activities, including detection, analysis, triage, containment, eradication, recovery, and documentation.
Conduct proactive threat hunting to identify anomalous behaviors, malicious patterns, compromised systems, and emerging threats.
Perform malware analysis and evaluate malicious files, behaviors, indicators, and attack techniques.
Investigate Windows event logs, network traffic, intrusion detection alerts, endpoint telemetry, NetFlow data, and packet capture data for evidence of malicious activity.
Use Security Information and Event Management platforms and log management systems to collect, correlate, analyze, and alert on security events.
Develop and maintain security monitoring rules, filters, dashboards, views, signatures, scripts, countermeasures, and detection content.
Research emerging cyber threats, attack methodologies, threat actors, campaigns, tactics, techniques, procedures, and observables.
Recommend and implement new monitoring content, mitigating controls, and countermeasures within enterprise security tools and network environments.
Support the development and execution of incident response procedures and cybersecurity operational workflows.
Maintain accurate documentation and track activities through security operations workflow and ticket management systems.
Coordinate with cybersecurity personnel, network administrators, system administrators, Information System Security Officers, and Information System Security Managers.
Analyze network communications, routing activity, protocols, enterprise operating systems, and common internet services for indicators of compromise.
Support cybersecurity operations involving Collateral, SCI, and SAP systems and information.
Prepare reports, incident documentation, technical findings, and recommendations for government and program leadership.
Ensure cybersecurity activities comply with applicable Department of Defense security policies, directives, and program requirements.
Five to seven years of related cybersecurity, information assurance, security operations, incident response, or computer network defense experience.
Prior experience performing in an Information System Security Officer or Information System Security Manager role.
Strong analytical and technical skills in computer network defense and security operations.
Demonstrated experience with cybersecurity incident detection, event analysis, triage, investigation, response, and remediation.
Hands -on experience using Security Information and Event Management platforms or enterprise log management systems.
Experience developing or modifying detection rules, filters, signatures, dashboards, scripts, and operational security content.
Experience analyzing Windows event logs, network traffic, intrusion detection events, NetFlow data, and packet captures.
Experience identifying and implementing countermeasures or mitigating controls within enterprise network environments.
Experience with one or more of the following technologies:
Security Information and Event Management
Endpoint Detection and Response
Network Threat Hunting
Big Data Analytics
Intrusion Detection and Prevention Systems
Security workflow and ticketing platforms
Firewalls and log analysis tools
Network behavior analysis tools
Antivirus and endpoint security platforms
Network packet analyzers
Digital forensics tools
Working knowledge of Windows, Linux, macOS, and other operating systems commonly deployed within enterprise networks.
Conceptual understanding of Microsoft Windows Active Directory.
Working knowledge of network communications and routing protocols, including TCP, UDP, ICMP, BGP, and MPLS.
Working knowledge of common internet applications, protocols, and standards, including SMTP, DNS, DHCP, SQL, HTTP, and HTTPS.
Strong understanding of common attack methodologies, tactics, techniques, procedures, and protocols.
Excellent critical -thinking, organizational, documentation, and attention -to -detail skills.
Ability to work effectively within structured SOC workflows and fast -paced operational environments.
Ability to support rotating shifts or continuous 24Ã7Ã365 security operations, as required by the mission.
Bachelor’s degree in cybersecurity, information technology, computer science, information assurance, or a related discipline.
Four additional years of relevant professional experience may be accepted in place of the degree requirement.
Candidates must possess qualifying training as a:
Cybersecurity Service Provider Auditor; or
Cybersecurity Service Provider Incident Responder.
Candidates must also meet the applicable position and certification requirements outlined in DoD Directive 8570.01 -M within six months of hire for one of the following categories:
Information Assurance Technician Level II;
Information Assurance Manager Level II;
Computer Network Defense Auditor; or
Computer Network Defense Incident Responder.
Must possess an active Top Secret clearance with Sensitive Compartmented Information eligibility.
Must maintain active TS/SCI eligibility throughout employment.
Must be eligible for access to Special Access Program information.
Must be willing to submit to a Counterintelligence polygraph.
Must meet all security requirements established by the applicable Task Order.
Must maintain all required security access, program approvals, and classified system eligibility throughout employment.
Experience supporting Department of Defense classified systems or cybersecurity operations.
Experience working within Special Access Program or Sensitive Compartmented Information environments.
Experience supporting enterprise -level cyber incident response and digital forensics activities.
Familiarity with cyber threat intelligence, threat actor attribution, campaign analysis, and indicator development.
Experience automating cybersecurity analysis or detection activities through scripts and operational applications.
This position operates within a highly secure, mission -focused environment supporting sensitive Department of Defense programs. The successful candidate must be comfortable working with classified systems, following strict security procedures, responding to time -sensitive cyber incidents, and supporting continuous SOC operations.
Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.