USAF - Security Operations Analyst

cFocus Software Incorporated

Linthicum Heights, MD, United States Full-time yesterday
Workplace
On-site
Location
Linthicum Heights, MD, United States
Who can apply
Based in the United States: you usually need the right to work there

Check your CV against this job

Free · No signup · A 0–100 ATS match score and the keywords you're missing.

Check my CV free

$14.99/month, cancel anytime. Already have an account? Log in

About the role

cFocus Software seeks a Security Operations Analyst to join our program supporting the United States Air Force (USAF). This position is on-site in Linthicum Heights, MD. This position requires an Active TS/SCI clearance. Qualifications: * Active TS/SCI clearance * B.S. Computer Science, Information Technology, or a related field * Experience monitoring security events, investigating alerts, and supporting enterprise incident response. * Ability to correlate telemetry, assess anomalies, and document investigation findings. * Knowledge of network protocols, endpoints, access controls, and cyberattack techniques. * Experience with security monitoring, log analysis, endpoint detection, and vulnerability tools. * Ability to hunt threats and apply intelligence to investigations and detection improvements. * Understanding of incident response, evidence handling, and approved escalation procedures. * Ability to analyze vulnerabilities and coordinate remediation with technical teams. * Strong analytical judgment, collaboration, and writing skills for timely investigations

Duties: * Monitor and triage security alerts, logs, and events; correlate available telemetry to identify suspicious activity and potential threats. * Analyze network, endpoint, application, and cloud security data within assigned environments to determine event validity, severity, scope, and mission impact. * Conduct data and intelligence-driven threat hunting to identify hidden or advanced threats in DC3 IT and OT environments. * Investigate anomalous behavior, distinguish false positives from potential incidents, and document evidence, findings, and recommended responses. * Detect, analyze, and respond to suspected security incidents; escalate confirmed incidents through established Government-approved procedures. * Perform assigned containment, eradication, and recovery activities upon incident confirmation, within authorized procedures and access permissions. * Maintain incident records, timelines, investigation notes, and supporting evidence in accordance with approved handling and documentation procedures. * Coordinate incident response and recovery with infrastructure, network, application, cloud, and cybersecurity teams; verify assigned corrective actions. * Analyze vulnerability assessment findings, support risk prioritization and remediation tracking, and coordinate validation with certified assessment specialists. * Provide continuous analysis of security events and trends; recommend detection improvements and mitigation actions for Government consideration. * Support operation and maintenance of assigned SOC tools and sensors; identify telemetry gaps and coordinate corrective action with responsible teams. * Support SOC coordination with Cybersecurity Service Providers (CSSPs), the AFCYBER Operations Center, and applicable higher headquarters authorities. * Track assigned cyber orders and taskers; coordinate status, required actions, and supporting evidence through approved command and control channels. * Contribute incident response procedures, lessons learned, security monitoring documentation, and evidence supporting compliance activities. * Research emerging threats, cybersecurity practices, and technologies; document benefits, risks, and implementation recommendations.

Get matched & apply with FindAJobAI

Upload your resume once. We score every job against your profile, tailor your resume and cover letter, and autofill the application.