Cybersecurity Analyst
Cybersecurity Operations
Cybersecurity Tools
Endpoint Security
Incident Response
Information Security
InfoSec
Intrusion Detection Systems
Mitre Att&ck
Security Automation
Security Detection Engineering
Security Information And Event Management
Security Monitoring
Security Operations
Siem
Sigma Rules
Splunk
Splunk Siem
Job Description
SAIC is seeking a Cybersecurity Analyst to strengthen SOC and detection capabilities for the Special Operations Command Information Technology Enterprise Contract (SITEC) – 3 EOM at Fort Bragg, NC.
Responsibilities
- Identify and analyze sophisticated threats using SIEM, intrusion detection systems (IDS), and other advanced tooling
- Correlate data from multiple sources to uncover APTs and complex attack patterns
- Refine detection rules and alerts to improve threat identification accuracy
- Lead high-priority security incidents, coordinating containment, eradication, and recovery
- Perform root cause analysis and provide actionable recommendations to reduce future risk
- Create detailed post-incident reports to support organizational strategy and resilience
- Lead audits and assessments, providing recommendations to enhance compliance and streamline processes
- Secure NetOps and systems/network infrastructure against evolving threats
- Mentor junior analysts and support development of technical expertise
- Coordinate with SOC, IT staff, and stakeholders to execute coordinated threat response activities
- Collaborate in cross-functional discussions to drive improvements in SOC operations
- Stay current on emerging threats, technologies, and best practices to enhance SOC performance
- Research and recommend tools, techniques, and strategies to improve detection and operations
- Deliver training sessions to increase team knowledge and preparedness
- Operate in a 24/7 SOC environment, which may require shift work including nights, weekends, and holidays
- Handle sensitive and classified information in line with DoD and USSOCOM requirements
- Perform cyber log correlation and reporting, coordinating with cyber analysts to contain users/systems and initiate formal CSSP documentation
- Analyze network traffic logs and encrypted patterns to detect ongoing threats, anomalous behavior, C2 activity, active exploitation, and potential data exfiltration
- Monitor NSA Pulse investigations related to USASOC assets and brief branch chiefs to coordinate mitigation while avoiding duplication with cyber analysts
- Coordinate with cyber operators for threat intelligence sharing, escalation criteria, and remediation plans
- Develop threat hunt playbooks based on industry findings, historical trends, or G639 requirements to search for indicators of compromise
- Aggregate and contextualize logs between Splunk, MDE environments, and other SIE native tools to generate actionable data
- Develop and refine advanced detection logic such as Sigma, YARA, and Splunk SPL signatures aligned to emerging TTPs
- Map hunt findings and defensive gaps to the MITRE ATT&CK Framework to prioritize mission focus areas
- Participate in Purple Team operations alongside adversary emulation cells to validate control effectiveness
Requirements
- DoD 8570 IAT II certifications AND CSSP Analyst OR CSSP Incident Responder
- Strong understanding of cybersecurity concepts including threat detection, malware analysis, and network security
- Proficiency with one or more tools such as SIEM platforms, IDS/IPS, endpoint protection solutions, and forensic analysis tools
- Advanced analytical and problem-solving skills for complex incidents and scenarios
- Effective communication skills, including the ability to produce detailed reports and brief stakeholders
- Ability to work independently and lead initiatives in a fast-paced, team-oriented environment
- Must be DoW 8140 compliant under the Work Role Code 531 – Cyber Defense Incident Responder - Intermediate level
Technologies
- SIEM
- Intrusion detection systems (IDS)
- Splunk
- MDE
- Sigma
- YARA
- Splunk SPL
- MITRE ATT&CK
- NSA Pulse
- Python
- PowerShell
- C2
- CSSP
- G639
Highly Desired Qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field (or equivalent experience)
- Advanced certifications such as CISSP, GIAC (e.g., GCIA, GCIH), or OSCP
- Experience with scripting/automation (e.g., Python, PowerShell) and threat hunting techniques
- Knowledge of advanced threat intelligence platforms and methodologies
Education and Years of Experience
- Minimum 12 years with HS Diploma
- Minimum 10 years with AS/AA degree
- Minimum 8 years with BS/BA
Clearance
- TS/SCI level DoD security clearance required
- Clearance level must be able to obtain: None
Location: Fayetteville, NC, US (onsite at Fort Bragg, NC)
Schedule: Full-Time
Shift: Day Job
Travel: 10%
Potential for Remote Work: ORA_ON_SITE
Job ID: 2617267
Date Posted: 2026-09-25
Similar Jobs
S