SOC Analyst

Peraton•,
•$80,000 - $128,000•Remote

About The Position

Peraton is seeking a SOC Analyst to join their team on the Department of State (DOS) Bureau of Diplomatic Technology (DT) Consular Affairs Enterprise Infrastructure Operations (CAEIO) program. This program provides IT Operations and Maintenance to modernize legacy networks, applications, and databases supporting consular applications and services globally. The role involves monitoring and investigating security alerts, performing threat hunting, analyzing network traffic, and coordinating with internal and external teams to identify and mitigate threats. The SOC Analyst will also be responsible for developing and documenting security standards, advising on technology risks, and preparing reports on security activities. Additionally, they will identify attack tactics, recommend system enhancements, refine SOC processes, train junior team members, and manage SOC projects. Clear communication and flexibility are essential for this role.

Requirements

  • Bachelors degree and 2 years of experience or an Associates degree and 4 years of experience or a High School diploma/equivalent and 6 years of experience.
  • U.S. citizenship and an active SECRET security clearance
  • 2+ years of cybersecurity, SOC, or systems security experience in a federal government environment supporting business critical, high availability systems.
  • 2+ years of SOC or cybersecurity related experience.
  • Experience working with a SIEM platform, preferably Splunk.
  • Experience using Splunk dashboards and Microsoft Sentinel for security monitoring and analysis.
  • Experience querying and analyzing security data, including SPL, with a working understanding of data types, conditions, and regular expressions.
  • Working knowledge of system, network, and application security threats and vulnerabilities, with the ability to support the development and improvement of monitoring solutions.
  • Understanding of Boolean logic and event correlation.
  • Experience identifying logging and monitoring gaps and supporting efforts to improve security monitoring.
  • Working knowledge of cybersecurity incidents, anomaly analysis, log analysis, digital forensics, and common threat vectors.
  • Understanding of TCP/IP, UDP, network ports, protocols, and traffic flow.
  • Security+ CE or other DoD 8570 IAT Level II certification.
  • Familiarity with cybersecurity frameworks and specifications, including RMF and NIST standards, such as NIST SP 800-53.
  • Familiarity frameworks and specifications, including RMF and NIST standards (e.g., NIST SP 800-53)

Nice To Haves

  • Experience with Splunk data normalization (field aliases, calculated fields, field extractions)
  • Splunk Power User certification or higher
  • Experience tracking incidents using the MITRE ATT&CK framework
  • Knowledge of cloud security
  • Experience with system administration, networking, and operating system hardening techniques
  • Mixed OS experience (Linux, Windows)
  • Experience troubleshooting storage-related issues
  • Scripting or coding experience
  • Knowledge of Web Application Firewall (WAF) security features

Responsibilities

  • Monitor and investigate security alerts, perform threat hunting, and notify designated managers, cyber incident responders, and cybersecurity service provider personnel of suspected incidents.
  • Clearly articulate event history, status, and potential impact in accordance with the organization’s cyber incident response plan.
  • Analyze and characterize network traffic to identify anomalous activity and potential threats to network resources.
  • Create advanced ad hoc SPL queries.
  • Coordinate with internal and external teams to investigate threats, assess risks, and conduct forensic analysis.
  • Review and analyze log files from various sources (host logs, network traffic logs, firewall logs, IDS logs) to identify potential security threats.
  • Utilize SIEM and EDR tools to monitor the operational environment.
  • Develop and document configuration standards, policies, and procedures to operate, manage, and secure system infrastructure.
  • Advise management and team members on technology risks and recommend mitigation strategies.
  • Engage with multiple levels of management, providing technical expertise and thought leadership.
  • Prepare reports detailing investigations, incidents, and other security-related activities.
  • Identify and classify attack tactics and techniques.
  • Recommend and implement enhancements to improve system performance, security, and reliability.
  • Build and refine SOC processes and procedures, including documenting work in SOPs.
  • Train and mentor junior SOC team members.
  • Plan and execute SOC-related projects and initiatives.
  • Communicate clearly and professionally with managers and colleagues.
  • Demonstrate flexibility and an eagerness to take on additional responsibilities as needed.

Benefits

  • Overtime
  • Shift differential
  • Discretionary bonus
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service