19 -076 – Security Operations Center (SOC) Analyst II

Sandy Mac EvolutionSchriever Air Force Base, CO
Onsite

About The Position

Sandy Mac Evolution LLC is seeking a highly skilled Security Operations Center (SOC) Analyst II to provide comprehensive Computer Network Defense, cybersecurity monitoring, threat analysis, and incident response support at Schriever AFB, Colorado. The selected candidate will support continuous 24x7x365 security monitoring and analysis of potential cyber threats targeting enterprise systems and networks. The SOC Analyst will conduct security event triage, advanced analytics, threat hunting, incident investigation, malware analysis, and response activities supporting the government’s mission. This position supports Department of Defense Special Access Programs and organizations such as Headquarters Air Force, the Office of the Secretary of Defense, and Military Department compartmented programs. The SOC Analyst will provide day-to-day cybersecurity support for Collateral, Sensitive Compartmented Information, and Special Access Program environments.

Requirements

  • Five to seven years of related cybersecurity, information assurance, security operations, incident response, or computer network defense experience.
  • Prior experience performing in an Information System Security Officer or Information System Security Manager role.
  • Strong analytical and technical skills in computer network defense and security operations.
  • Demonstrated experience with cybersecurity incident detection, event analysis, triage, investigation, response, and remediation.
  • Hands-on experience using Security Information and Event Management platforms or enterprise log management systems.
  • Experience developing or modifying detection rules, filters, signatures, dashboards, scripts, and operational security content.
  • Experience analyzing Windows event logs, network traffic, intrusion detection events, NetFlow data, and packet captures.
  • Experience identifying and implementing countermeasures or mitigating controls within enterprise network environments.
  • Experience with one or more of the following technologies: Security Information and Event Management, Endpoint Detection and Response, Network Threat Hunting, Big Data Analytics, Intrusion Detection and Prevention Systems, Security workflow and ticketing platforms, Firewalls and log analysis tools, Network behavior analysis tools, Antivirus and endpoint security platforms, Network packet analyzers, Digital forensics tools.
  • Working knowledge of Windows, Linux, macOS, and other operating systems commonly deployed within enterprise networks.
  • Conceptual understanding of Microsoft Windows Active Directory.
  • Working knowledge of network communications and routing protocols, including TCP, UDP, ICMP, BGP, and MPLS.
  • Working knowledge of common internet applications, protocols, and standards, including SMTP, DNS, DHCP, SQL, HTTP, and HTTPS.
  • Strong understanding of common attack methodologies, tactics, techniques, procedures, and protocols.
  • Excellent critical-thinking, organizational, documentation, and attention-to-detail skills.
  • Ability to work effectively within structured SOC workflows and fast-paced operational environments.
  • Ability to support rotating shifts or continuous 24x7x365 security operations, as required by the mission.

Nice To Haves

  • Experience supporting Department of Defense classified systems or cybersecurity operations.
  • Experience working within Special Access Program or Sensitive Compartmented Information environments.
  • Experience supporting enterprise-level cyber incident response and digital forensics activities.
  • Familiarity with cyber threat intelligence, threat actor attribution, campaign analysis, and indicator development.
  • Experience automating cybersecurity analysis or detection activities through scripts and operational applications.

Responsibilities

  • Monitor enterprise systems, networks, applications, and security platforms for suspicious or malicious activity.
  • Analyze cybersecurity alerts and information technology security events to distinguish legitimate security incidents from false positives and non-incidents.
  • Lead or support incident handling activities, including detection, analysis, triage, containment, eradication, recovery, and documentation.
  • Conduct proactive threat hunting to identify anomalous behaviors, malicious patterns, compromised systems, and emerging threats.
  • Perform malware analysis and evaluate malicious files, behaviors, indicators, and attack techniques.
  • Investigate Windows event logs, network traffic, intrusion detection alerts, endpoint telemetry, NetFlow data, and packet capture data for evidence of malicious activity.
  • Use Security Information and Event Management platforms and log management systems to collect, correlate, analyze, and alert on security events.
  • Develop and maintain security monitoring rules, filters, dashboards, views, signatures, scripts, countermeasures, and detection content.
  • Research emerging cyber threats, attack methodologies, threat actors, campaigns, tactics, techniques, procedures, and observables.
  • Recommend and implement new monitoring content, mitigating controls, and countermeasures within enterprise security tools and network environments.
  • Support the development and execution of incident response procedures and cybersecurity operational workflows.
  • Maintain accurate documentation and track activities through security operations workflow and ticket management systems.
  • Coordinate with cybersecurity personnel, network administrators, system administrators, Information System Security Officers, and Information System Security Managers.
  • Analyze network communications, routing activity, protocols, enterprise operating systems, and common internet services for indicators of compromise.
  • Support cybersecurity operations involving Collateral, SCI, and SAP systems and information.
  • Prepare reports, incident documentation, technical findings, and recommendations for government and program leadership.
  • Ensure cybersecurity activities comply with applicable Department of Defense security policies, directives, and program requirements.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service