Advanced SOC Analyst (Fort Bragg, NC)

Akira TechnologiesFort Bragg, NC
Onsite

About The Position

Akira Technologies is seeking an Advanced SOC Analyst to support the U.S. Army Reserve Command (USARC) in cyberspace operations supporting Army and joint requirements. The Advanced SOC Analyst will perform Tier 2 and Tier 3 Blue Team functions, including multi-source correlation, advanced incident investigation, root-cause analysis, threat-hunting support, and detection-content development. This position serves as a senior analyst on the watch floor, providing technical guidance to junior analysts and ensuring the quality, accuracy, and timely resolution of cybersecurity incident records. This is an onsite position at Fort Bragg, NC supporting a mission-focused U.S. Army Reserve Command cyberspace operations environment. This role requires an active Secret clearance or higher.

Requirements

  • DoD Manual 8140.03 qualification for DCWF Work Role 511, Cyber Defense Analyst, Intermediate, and Work Role 531, Cyber Defense Incident Responder, Intermediate.
  • Active Secret security clearance at a minimum; TS/SCI eligibility/access where required by the assigned work role or supported network.
  • Demonstrated experience working with enterprise SIEM platforms, EDR/ENS solutions, packet capture and network-analysis tools, and IDS/IPS technologies.
  • Proven ability to perform root-cause analysis of complex cybersecurity incidents and develop appropriate detection content.
  • Demonstrated experience conducting advanced incident investigation, threat hunting, event correlation, or related Tier 2/Tier 3 SOC activities.
  • Experience analyzing network, host, endpoint, authentication, and security-event telemetry.
  • Experience developing or validating detection rules, signatures, or other defensive cyber capabilities.
  • Working knowledge of CJCSM 6510.01B incident categories and applicable incident-reporting requirements.
  • Familiarity with ARCYBER operational constructs and DoD defensive cyberspace operations.
  • Ability to work effectively in a fast-paced, mission-focused, classified operational environment.
  • Strong analytical, technical documentation, communication, and problem-solving skills.
  • Ability to work onsite at Fort Bragg, NC and support operational requirements, including watch-floor or shift coverage as required.

Nice To Haves

  • Experience supporting Army, Army Reserve, ARCYBER, or joint cyberspace operations.
  • Experience supporting a 24/7 Security Operations Center or enterprise defensive cyber operations environment.
  • Experience investigating APT activity, complex intrusions, malware, lateral movement, persistence, privilege escalation, or other advanced attack techniques.
  • Experience with Elastic, Splunk, Microsoft Defender, CrowdStrike, or comparable SIEM/EDR platforms.
  • Experience with Wireshark, Zeek, tcpdump, or other packet-capture and network-analysis tools.
  • Experience developing YARA, Snort, Suricata, Sigma, SIEM correlation, or host-based detection content.
  • Familiarity with MITRE ATT&CK and adversary TTP mapping.
  • Experience with digital forensics, volatile-memory analysis, malware analysis, or forensic artifact analysis.
  • Relevant cybersecurity certifications such as CySA+, GCIH, GCIA, GCED, CISSP, or equivalent are a plus.

Responsibilities

  • Perform multi-source correlation across SIEM, EDR/ENS, NetFlow, PCAP, proxy, authentication, and other security telemetry to characterize the scope, nature, and impact of cybersecurity events.
  • Conduct advanced analysis of security alerts, network activity, endpoint activity, authentication events, and other telemetry to identify malicious or anomalous behavior.
  • Recommend containment, mitigation, and eradication actions in coordination with the affected mission owner, Information System Security Officer (ISSO), and appropriate operational stakeholders.
  • Own assigned incident records through closure, ensuring documentation is complete, accurate, timely, and current within applicable ARCYBER operational portals.
  • Conduct quality-control reviews of Tier 1 incident tickets prior to closure to ensure appropriate analysis, documentation, categorization, and disposition.
  • Lead analysis of suspected Advanced Persistent Threat (APT) activity and complex cyber intrusions.
  • Plan and execute hypothesis-driven threat-hunting missions based on identified indicators, adversary behaviors, threat intelligence, and operational findings.
  • Develop, test, and validate detection content, including SIEM correlation rules, YARA rules, Snort/Suricata signatures, and host-based detection policies.
  • Coordinate detection and signature submissions with the CTI cell for review, refinement, and promotion to the production sensor grid.
  • Provide on-the-job training, technical guidance, and mentorship to Tier 1 and Tier 2 SOC personnel.
  • Execute critical defensive blocks within two hours of notification or detection, as required to mitigate ongoing threat activity.
  • Capture and perform initial analysis of volatile data, system/log data, and captured network traffic in support of incident investigations.
  • Maintain appropriate incident evidence and chain of custody in accordance with applicable ARCYBER forensic and malware analysis (F&MA) procedures.
  • Coordinate with the appropriate Technical Support Center (TSC), DoDIN-A staff, and supported Regional Cyber Center (RCC) personnel regarding network configuration changes and defensive measures.
  • Submit internal recommendations for defensive measures based on incident findings, threat intelligence, and technical analysis.
  • Support CDAP integrated assessment missions, including NAV and NDA activities, as directed.
  • Provide onsite technical support and forensic artifact analysis during cybersecurity assessment and DCO missions.
  • Contribute to the development, review, and refinement of Blue Team SOPs, incident-response playbooks, analytical procedures, and analytic scripts.
  • Identify opportunities to improve detection, investigation, incident-response, and operational processes.
  • Perform other SOC, Blue Team, and DCO support duties as required by the mission.

Benefits

  • Medical plans (some with Health Savings Account)
  • Dental plans
  • Vision coverage
  • 401(k) plan with employer match
  • Paid time off, including vacation and sick time
  • Holidays
  • Paid parental leave
  • Military leave
  • Bereavement leave
  • Jury duty leave
  • Short and long-term disability benefits
  • Life insurance
  • Accidental death and dismemberment insurance
  • Critical illness insurance
  • Tuition, training, and certification reimbursement
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service