Intermediate SOC Analyst (Fort Bragg, NC)

Akira Technologies Inc. Fort Bragg, NC, US, NC
$80,000 - $90,000Onsite

About The Position

Akira Technologies is seeking an Intermediate SOC Analyst to support the U.S. Army Reserve Command (USARC) in cyberspace operations supporting Army and joint requirements. The Intermediate SOC Analyst will perform Tier 1 and Tier 2 Blue Team functions, including real-time security monitoring, event triage, incident documentation, initial investigation, and standardized response actions. The analyst will continuously review SIEM alerts, sensor events, and host-based detections during assigned watch shifts and escalate significant or complex events in accordance with established procedures. This is an onsite position at Fort Bragg, NC supporting a mission-focused U.S. Army Reserve Command cyberspace operations environment. An active Secret clearance or higher is required.

Requirements

  • DoD Manual 8140.03 qualification for DCWF Work Role 511, Cyber Defense Analyst, Intermediate.
  • Active Secret security clearance at a minimum; TS/SCI eligibility/access where required by the assigned work role or supported network.
  • Demonstrated experience working with SIEM platforms, host-based security solutions, and basic network traffic analysis.
  • Experience performing security-event monitoring, alert triage, incident documentation, or related SOC activities.
  • Familiarity with CJCSM 6510.01B incident categories and standard incident-response procedures.
  • Ability to analyze and correlate information from multiple security data sources.
  • Ability to follow established SOPs, playbooks, escalation procedures, and incident-response processes.
  • Strong analytical, technical documentation, and communication skills.
  • Ability to work effectively in a mission-focused, classified operational environment.
  • Ability to work onsite at Fort Bragg, NC.
  • Ability to work rotating shifts in a 24/7/365 operational environment.

Nice To Haves

  • Experience supporting Army, Army Reserve, ARCYBER, or joint cyberspace operations.
  • Experience working in a 24/7 Security Operations Center (SOC), Network Operations Center (NOC), or defensive cyberspace operations environment.
  • Experience with Elastic, Splunk, Microsoft Defender, CrowdStrike, or comparable SIEM/EDR platforms.
  • Familiarity with network monitoring and analysis tools such as Wireshark, Zeek, tcpdump, or similar technologies.
  • Familiarity with MITRE ATT&CK, common adversary TTPs, and indicators of compromise (IOCs).
  • Experience supporting cybersecurity incident response, threat hunting, or network defense activities.
  • Experience supporting DoD cybersecurity assessments, exercises, or Cybersecurity Readiness Inspections (CCRI).
  • Relevant cybersecurity certifications such as Security+, CySA+, or equivalent are a plus.

Responsibilities

  • Conduct continuous monitoring and review of SIEM alerts, network sensor events, host-based detections, and other security telemetry during assigned watch shifts.
  • Perform initial event triage, determine event relevance and severity, create incident tickets, and assign appropriate CJCSM 6510.01B incident categories.
  • Execute approved Tier 1 incident-response playbook actions in accordance with established SOPs.
  • Escalate events meeting documented thresholds to Tier 2 personnel within established SOP timelines.
  • Perform Tier 2 multi-source correlation across SIEM, EDR, NetFlow, PCAP, proxy, authentication, and other available telemetry to characterize event scope and potential impact.
  • Analyze network, host, endpoint, and security-event data to identify suspicious or malicious activity.
  • Recommend containment and eradication actions in coordination with the affected mission owner, Information System Security Officer (ISSO), and appropriate operational personnel.
  • Manage assigned incident records through closure, ensuring accurate and timely documentation and currency within applicable ARCYBER operational portals.
  • Conduct quality-control reviews of Tier 1 tickets prior to closure when performing Tier 2 responsibilities.
  • Support incident investigation and response activities in accordance with established cybersecurity procedures and playbooks.
  • Support development and refinement of event-triage processes, incident-response procedures, analytic scripts, and analyst playbooks.
  • Participate in monthly DCO-specific internal training sessions.
  • Contribute to the shared knowledge base of adversary tactics, techniques, and procedures (TTPs), troubleshooting guides, incident lessons learned, and analyst reference materials.
  • Support cyberspace exercises, training events, and other operational activities as directed.
  • Scale exercise and training support as required while maintaining steady-state operational coverage.
  • Maintain effective shift turnover and communicate significant events, open incidents, pending actions, and operational concerns to incoming personnel.
  • Identify and escalate significant cyber events through established notification and reporting procedures.
  • Perform other SOC, Blue Team, and DCO support duties as required by the mission.

Benefits

  • Multiple options for medical plans (some with Health Savings Account)
  • Dental plans
  • Vision coverage
  • 401(k) plan with employer match
  • Paid time off, including vacation and sick time
  • Holidays
  • Paid parental leave
  • Military leave
  • Bereavement leave
  • Jury duty leave
  • Short and long-term disability benefits
  • Life insurance
  • Accidental death and dismemberment insurance
  • Critical illness insurance
  • Tuition, training, and certification reimbursement for professional development and career advancement
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service