Cybersecurity Operations Center Analyst, Senior

Booz Allen Hamilton•Honolulu, HI
•$99,000 - $225,000•Onsite

About The Position

The Cybersecurity Operations Center Analyst, Senior role focuses on cyber defense and protecting critical infrastructure from cyber-attacks. The analyst will improve tier monitoring strategies, analyze threats using advanced tools, and work with the team to mitigate and respond to threats, restore operations, and limit impact. Responsibilities include managing system impact assessments, recovery efforts, and combining threat intelligence with event data to identify attacker goals. This role offers hands-on experience in threat assessment and incident response, protecting clients from malicious actors. The senior analyst will lead a team in evaluating potential weaknesses and the effectiveness of cyber security mitigations using cyberspace capabilities. They will also leverage cyberspace operations systems to aggregate threat feeds for briefings to senior leadership, particularly for an Army client. This position is for individuals who want to be actively involved in critical global cyber missions.

Requirements

  • 6+ years of experience working in a Security Operations Center (SOC) at a classified level within the DoW
  • Experience leading every phase of the incident lifecycle, including conducting rapid triage to determine severity, performing deep-dive investigations into root causes, and assessing appropriate containment, eradication, and remediation strategies to halt active threats
  • Experience working with cybersecurity staff to evolve continuous monitoring toolsets by generating new detection rules and refining existing alerts to maximize high-fidelity alerts and minimize false positives
  • Experience refining, developing, and maturing standard operating procedures (SOPs) and SOC responsibilities throughout each stage of the incident response lifecycle
  • Ability to manage post-compromise activities, focusing on the eradication of malicious artifacts, guiding the secure recovery of mission services, and generating comprehensive After-Action Reports (AARs) to document lessons learned
  • Ability to serve as a primary focal point for active incident response operations, taking responsibility for technical coordination and clear communication with key stakeholders
  • TS/SCI clearance
  • HS diploma or GED
  • Ability to obtain an 8570 DoW approved CSSP baseline certification, including CEH, CFR, CCNA Cyber Ops, CCNA-Security, CySA+, GCIA, GCIH, GICSP, Cloud+, SCYBER, or PenTest+, before start date

Nice To Haves

  • Experience using Elastic for monitoring, analysis, and case management
  • Experience using endpoint tools to successfully hunt for adversarial behavior
  • Experience with GCFA, GNFA, or equivalent relevant digital forensics
  • Ability to conduct threat hunting using network and host-based information
  • TS/SCI clearance with a polygraph
  • 8570 CSSP Analyst or Incident Responder Certification

Responsibilities

  • Improve tier monitoring strategies and analyze threats using state-of-the-art tools and platforms.
  • Work with the team to comprehend, mitigate, and respond to threats quickly, restoring operations and limiting the impact.
  • Manage efforts to determine the number of affected systems and assist recovery efforts.
  • Combine threat intelligence, event data, and assessments of events to identify patterns and understand attackers’ goals.
  • Lead a team of professionals using cyberspace capabilities to evaluate potential weaknesses and the effectiveness of mitigations for cyber security solutions.
  • Leverage cyberspace operations systems to aggregate threat feeds that inform briefings for senior leadership.
  • Conduct rapid triage to determine severity during incident lifecycle.
  • Perform deep-dive investigations into root causes during incident lifecycle.
  • Assess appropriate containment, eradication, and remediation strategies to halt active threats.
  • Evolve continuous monitoring toolsets by generating new detection rules and refining existing alerts.
  • Refine, develop, and mature standard operating procedures (SOPs) and SOC responsibilities.
  • Manage post-compromise activities, focusing on eradication of malicious artifacts.
  • Guide the secure recovery of mission services.
  • Generate comprehensive After-Action Reports (AARs) to document lessons learned.
  • Serve as a primary focal point for active incident response operations.
  • Take responsibility for technical coordination and clear communication with key stakeholders.

Benefits

  • health, life, disability, financial, and retirement benefits
  • paid leave
  • professional development
  • tuition assistance
  • work-life programs
  • dependent care
  • recognition awards program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service