CSOC Analyst T1

Nightwing Intelligence SolutionsFalls Church, VA
Remote

About The Position

Nightwing provides technically advanced full-spectrum cyber, data operations, systems integration and intelligence mission support services to meet our customers’ most demanding challenges. Our capabilities include cyber space operations, cyber defense and resiliency, vulnerability research, ubiquitous technical surveillance, data intelligence, lifecycle mission enablement, and software modernization. Nightwing brings disruptive technologies, agility, and competitive offerings to customers in the intelligence community, defense, civil, and commercial markets. This position is CONTINGENT upon funding, an open position, customer approval, completion of a favorable background investigation, and the ability to obtain and maintain our customer's sensitive clearance. Job Requisition: JR101963 CSOC Analyst T1 – Falls Church, VA or Remote Tier 1 CSOC Analyst Job Description This position is CONTINGENT upon funding, an open position, customer approval, completion of a favorable background investigation, and the ability to obtain and maintain our customer's sensitive clearance. Nightwing is seeking to hire a Tier 1 CSOC Analyst. Candidates should have some work experience in Security Operations Centers (SOC), Cyber Security Operations Centers (CSOC), and Cyber Incident Response Team (CIRT). The Tier 1 Analysts receive all alerts from various sources, including SIEM, CSOC mailboxes, and phone calls directly from the central SIEM and handle as defined in Playbooks and SOPs. Tier 1 Analyst will escalate the events to Tier 2 after initial triage, along with providing input and analysis on how to leverage Artificial Intelligence, Machine Learning, and SOAR capabilities to improve CSOC efficiency and accuracy.

Requirements

  • Must be eligible to obtain a sensitive clearance – Position of Public Trust – and may be required to obtain a higher security clearance
  • Must have 1+ years’ experience in IT Operations
  • Must have 1+ year experience in IT Security
  • Working knowledge of: Platform Security Basics, Threat Lifecycle Management, TCP / IP, Incident Management
  • Knowledge of Control Frameworks and Risk Management techniques
  • Excellent oral and written communication skills
  • Excellent interpersonal and organizational skills
  • Strong understanding of IDS/IPS technologies, trends, vendors, processes and methodologies
  • Familiarity with the application of AI/ML techniques in cybersecurity, including but not limited to automated threat detection, incident response automation, and predictive analytics.
  • Understanding of ethical AI principles and their implications in cybersecurity.
  • Familiarity with cloud security (AWS, Azure, GCP)
  • Understanding and experience identifying and implementing automation use cases.
  • U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance.

Nice To Haves

  • Experience in evaluating the effectiveness of AI/ML solutions in a SOC environment is a plus.
  • Splunk experience, developing queries, data models, and dashboards
  • Cloud monitoring experience is a plus
  • One or more relevant certifications such as CEH, CISSP, CompTIA Security+, or GCIH are advantageous.

Responsibilities

  • Identification of Cybersecurity problems which may require mitigating controls
  • Interpret output from the SIEM, CSOC mailboxes, and phone calls to identify potential security incidents
  • Collect basic information to support analysis such as IP address, location, affected asset(s), etc.
  • Escalate items which require further investigation to other members of the Threat Management team
  • Execute operational processes in support of response efforts to identify security incidents
  • Utilize AI/ML-based tools and techniques to detect anomalies, automate incident triage, and improve threat intelligence
  • Performing and analyzing threat intelligence to assess risk and adapt defenses using ML enhance tools
  • Stay current on the latest cybersecurity trends, threat actors, and AI/ML research relevant to the field
  • Identify and support automation use cases, including the use of AI/ML to enhance SOC capabilities.
  • Collaborate across Operations to provide SOC enhancement capabilities with automation and AI.

Benefits

  • medical, vision and dental insurance coverage
  • 401k plan
  • PTO
  • Holidays
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service