USAF - Security Operations Analyst
Linthicum Heights, MD
Full Time
USAF - DC3
Experienced
cFocus Software seeks a Security Operations Analyst to join our program supporting the United States Air Force (USAF). This position is on-site in Linthicum Heights, MD. This position requires an Active TS/SCI clearance.
Qualifications:
Qualifications:
- Active TS/SCI clearance
- B.S. Computer Science, Information Technology, or a related field
- Experience monitoring security events, investigating alerts, and supporting enterprise incident response.
- Ability to correlate telemetry, assess anomalies, and document investigation findings.
- Knowledge of network protocols, endpoints, access controls, and cyberattack techniques.
- Experience with security monitoring, log analysis, endpoint detection, and vulnerability tools.
- Ability to hunt threats and apply intelligence to investigations and detection improvements.
- Understanding of incident response, evidence handling, and approved escalation procedures.
- Ability to analyze vulnerabilities and coordinate remediation with technical teams.
- Strong analytical judgment, collaboration, and writing skills for timely investigations
- Monitor and triage security alerts, logs, and events; correlate available telemetry to identify suspicious activity and potential threats.
- Analyze network, endpoint, application, and cloud security data within assigned environments to determine event validity, severity, scope, and mission impact.
- Conduct data and intelligence-driven threat hunting to identify hidden or advanced threats in DC3 IT and OT environments.
- Investigate anomalous behavior, distinguish false positives from potential incidents, and document evidence, findings, and recommended responses.
- Detect, analyze, and respond to suspected security incidents; escalate confirmed incidents through established Government-approved procedures.
- Perform assigned containment, eradication, and recovery activities upon incident confirmation, within authorized procedures and access permissions.
- Maintain incident records, timelines, investigation notes, and supporting evidence in accordance with approved handling and documentation procedures.
- Coordinate incident response and recovery with infrastructure, network, application, cloud, and cybersecurity teams; verify assigned corrective actions.
- Analyze vulnerability assessment findings, support risk prioritization and remediation tracking, and coordinate validation with certified assessment specialists.
- Provide continuous analysis of security events and trends; recommend detection improvements and mitigation actions for Government consideration.
- Support operation and maintenance of assigned SOC tools and sensors; identify telemetry gaps and coordinate corrective action with responsible teams.
- Support SOC coordination with Cybersecurity Service Providers (CSSPs), the AFCYBER Operations Center, and applicable higher headquarters authorities.
- Track assigned cyber orders and taskers; coordinate status, required actions, and supporting evidence through approved command and control channels.
- Contribute incident response procedures, lessons learned, security monitoring documentation, and evidence supporting compliance activities.
- Research emerging threats, cybersecurity practices, and technologies; document benefits, risks, and implementation recommendations.
Apply for this position
Required*