Haystack
← Back to Jobs
Technology
KF

SOC Analyst (Night Shift) with Security Clearance

Kforce Federal SolutionsArlington, VA🇺🇸United StatesPosted 30 Aug 2026

Why This Role Stands Out

This on-site SOC Analyst role offers excellent hourly compensation and the chance to contribute to critical Department of Defense cybersecurity missions, utilizing industry-leading tools like Splunk and Trellix. You'll thrive here if you're a mid-senior level analyst with a security clearance, eager to develop your skills in threat detection and incident response within a stable, long-term program. Apply today to join a dedicated team protecting vital enterprise networks.

Quick Overview

Salary
$59 - $81/hr
Seniority
Mid Senior
Work mode
On Site
Location
Arlington, VA, United States
Posted
3 days ago
SplunkTCP/IP

Job Description

Cyber Security Analyst (SOC)
.

Pay Rate: $59-81/hr W2 depending on experience Location: Rosslyn, VA (Onsite)
Schedule: 24x7 Security Operations Center (SOC) Environment
Available Shifts:

  • Night Shift: 10:00 PM – 6:00 AM Overview
Join a long-term cybersecurity program supporting a critical Department of Defense mission in a fast-paced 24/7 Security Operations Center (SOC) environment. This role focuses on Cyber Network Defense (CND), threat detection, incident analysis, vulnerability management, and continuous monitoring across enterprise networks. Analysts will leverage industry-leading platforms including Splunk, Trellix, and ACAS to identify, investigate, and respond to cyber threats while helping maintain the security and integrity of mission-critical systems.
This opportunity offers long-term stability on a five-year contract supporting a high-visibility federal customer.

Key Responsibilities

  • Monitor and analyze security events from SIEM, EDR, IDS/IPS, and vulnerability management platforms.
  • Perform real-time cyber threat detection, triage, investigation, and escalation activities within a 24/7 SOC.
  • Conduct Cyber Network Defense (CND) operations to identify malicious activity, anomalous behavior, and indicators of compromise.
  • Investigate network traffic using packet capture (PCAP) data to identify intrusion attempts, malware activity, and unauthorized communications.
  • Analyze alerts and logs generated from Splunk, Trellix, ACAS, and other cybersecurity tools.
  • Utilize IDS/IPS technologies to identify threats, validate alerts, and support incident response efforts.
  • Perform threat hunting activities using log analysis, endpoint telemetry, network traffic analysis, and threat intelligence.
  • Conduct vulnerability assessments and track remediation activities using ACAS and related vulnerability management tools.
  • Correlate events from multiple data sources to determine root cause, scope, and impact of security incidents.
  • Develop and maintain incident documentation, shift reports, and operational metrics.
  • Coordinate with engineering, network, and system administration teams to support containment and remediation efforts.
  • Support continuous monitoring initiatives and compliance with DoD cybersecurity requirements.
  • Participate in daily shift handoffs to ensure seamless 24/7 operational coverage. Required Qualifications
  • Experience supporting a Security Operations Center (SOC), Cyber Defense Team, or Incident Response function.
  • Hands-on experience with Splunk for log analysis, correlation, alert investigation, and reporting.
  • Experience with Trellix security products and endpoint security monitoring.
  • Experience utilizing ACAS for vulnerability scanning, analysis, and remediation tracking.
  • Strong understanding of Cyber Network Defense (CND) principles and security monitoring methodologies.
  • Experience performing packet analysis using PCAP data.
  • Knowledge of IDS/IPS technologies and network-based threat detection.
  • Understanding of TCP/IP, network protocols, and common attack methodologies.
  • Experience analyzing security alerts, events, and indicators of compromise.
  • Strong troubleshooting, documentation, and communication skills.
  • Ability to work rotating shifts in a 24x7 operational environment.

Preferred Qualifications

  • Experience supporting DoD or Federal cybersecurity programs.
  • Familiarity with MITRE ATT&CK, Cyber Kill Chain, and threat hunting methodologies.
  • Experience with incident response, malware analysis, or digital forensics.
  • Knowledge of STIGs, vulnerability management processes, and security compliance frameworks.
  • Experience with threat intelligence integration and IOC analysis.
  • Understanding of Windows, Linux, and enterprise networking environments. Certifications (One or More Preferred)
  • Security+
  • CySA+
  • CASP+
  • GCIH
  • GCIA
  • CEH
  • CISSP Why Apply?
  • Long-term five-year program supporting a critical defense mission
  • High-visibility cybersecurity operations environment
  • Opportunity to work with leading security technologies including Splunk, Trellix, and ACAS
  • Multiple shift options available
  • Exposure to advanced cyber threat detection, network defense, and incident response operations
  • Strong career growth potential within enterprise cybersecurity and SOC operations

Similar jobs