Cyber Defense & Incident Responder (SOC Analyst)
Gormat · Arlington, VA
Apply directly on Gormat’s careers site — no account needed.
About the role
Quick Overview
Job Posted by ApplicantPro
- 100% work on site - no remote work
- Secret clearance with the ability to acquire a TS
- Locations near the Pentagon or Mayfield VA
- Customer DEA
- Intermediate SOC Analyst
-
6 years with Bachelor
- Monitor enterprise security systems and analyze alerts to identify potential cybersecurity incidents
- Review SIEM, IDS/IPS, EDR, and related security tool alerts for anomalous activity, indicators of compromise (IOCs), and indicators of attack (IOAs).
- Validate alerts, reduce false positives, and prioritize incidents based on severity and impact
- Perform triage and analysis of security events to determine scope, severity, and urgency
- Examine log data, network telemetry, and endpoint information to identify malicious activity
- Correlate event details with internal and external threat intelligence
- Execute incident response actions in accordance with established procedures
- Contain affected systems, remove malicious artifacts, and assist with system recovery
- Escalate complex or critical incidents to senior analysts or SOC leadership as needed
- Document investigative findings, incident timelines, and remediation actions
- Create and manage incident tickets and upload supporting evidence and artifacts
- Contribute to after action reviews and post incident reporting
- Communicate findings clearly and concisely to technical and nontechnical stakeholders
- Maintain SOC processes, tools, and playbooks to support effective incident handling
- Recommend improvements to SOPs, escalation procedures, and detection capabilities
- Participate in training exercises and knowledge sharing activities
- Support red, blue, or purple team exercises as directed
-
Stay informed on current and emerging cyber threats, threat actor TTPs, and industry trends
- Bachelor's degree in Information Technology, Cybersecurity, Information Systems, Computer Science, Data Science, or related field from an ABET accredited or CAE designated institution preferred. Equivalent experience may be considered in accordance with SOW education substitution requirements
- Minimum of 6 years of experience in Information Technology and/or Information Security
- Experience with incident response, threat analysis, SIEM platforms, endpoint security tools, and log analysis
- Strong analytical and investigative skills with the ability to derive accurate conclusions during incident investigations
- Active Secret clearance or higher required
- Must be eligible to obtain a Top Secret clearance if requested
- Ability to successfully complete a DEA background investigation
-
Must possess at least one applicable DoD 8140 certification or obtain certification within 6 months of onboarding
- Preferred DCWF Role 511 Cyber Defense Analyst certifications include:
- CBROPS
- CFR
- CompTIA Cloud+, CySA+, PenTest+, or Security+ CE
- FITSP O
- SANS GCED, GCFA, GCIA, GDSA, GFACT, GICSP, GISF, or GSEC
-
Additional Information
Job Posted by ApplicantPro
Description sourced from the public LinkedIn listing — this role isn't indexed from the company's career page yet.
Skills
- SIEM
Never be applicant #200 again
Every job here is indexed straight from company career pages — often hours after it opens, before it reaches the big boards. Create a free account and get your best matches in a twice-daily digest.
- Your best matches, twice a day
- No duplicates, no ghost jobs, no recruiter spam
- Every job free to browse — pay only when you apply
Get my matched jobs
Free account — no card required
93 117 live jobs · 17 641 companies tracked · 167 added today