cFocus Software seeks a Security Operations Analyst to join our program supporting the United States Air Force (USAF). This position is on-site in Linthicum Heights, MD. This position requires an Active TS/SCI clearance. Qualifications:
Active TS/SCI clearance
B.S. Computer Science, Information Technology, or a related field
Ability to correlate telemetry, assess anomalies, and document investigation findings.
Knowledge of network protocols, endpoints, access controls, and cyberattack techniques.
Experience with security monitoring, log analysis, endpoint detection, and vulnerability tools.
Ability to hunt threats and apply intelligence to investigations and detection improvements.
Understanding of incident response, evidence handling, and approved escalation procedures.
Ability to analyze vulnerabilities and coordinate remediation with technical teams.
Strong analytical judgment, collaboration, and writing skills for timely investigations
Duties:
Monitor and triage security alerts, logs, and events; correlate available telemetry to identify suspicious activity and potential threats.
Analyze network, endpoint, application, and cloud security data within assigned environments to determine event validity, severity, scope, and mission impact.
Conduct data and intelligence-driven threat hunting to identify hidden or advanced threats in DC3 IT and OT environments.
Investigate anomalous behavior, distinguish false positives from potential incidents, and document evidence, findings, and recommended responses.
Detect, analyze, and respond to suspected security incidents; escalate confirmed incidents through established Government-approved procedures.
Perform assigned containment, eradication, and recovery activities upon incident confirmation, within authorized procedures and access permissions.
Maintain incident records, timelines, investigation notes, and supporting evidence in accordance with approved handling and documentation procedures.
Coordinate incident response and recovery with infrastructure, network, application, cloud, and cybersecurity teams; verify assigned corrective actions.
Analyze vulnerability assessment findings, support risk prioritization and remediation tracking, and coordinate validation with certified assessment specialists.
Provide continuous analysis of security events and trends; recommend detection improvements and mitigation actions for Government consideration.
Support operation and maintenance of assigned SOC tools and sensors; identify telemetry gaps and coordinate corrective action with responsible teams.
Support SOC coordination with Cybersecurity Service Providers (CSSPs), the AFCYBER Operations Center, and applicable higher headquarters authorities.
Track assigned cyber orders and taskers; coordinate status, required actions, and supporting evidence through approved command and control channels.