Senior SOC Cyber Analyst; Norfolk, VA
Job Description
Akira Technologies is seeking a Senior SOC Cyber Defense Analyst to support a government client in Norfolk, VA. This senior-level role is responsible for leading cybersecurity monitoring, forensic analysis, and threat detection across Operational Technology (OT), Industrial Control Systems (ICS), and enterprise network environments—both on-premises and in the cloud.
The ideal candidate is a proactive self-starter with a deep understanding of Windows and Linux operating systems, network security, and advanced threat analysis. This position plays a key role in improving SOC visibility, mentoring junior analysts, and supporting the client’s mission to maintain a secure and resilient cyber environment.
Key Responsibilities- Lead cyber defense and forensic analysis across host and network systems, including malware triage, timeline reconstruction, and log correlation.
- Oversee SOC operations, providing technical guidance and mentorship to junior and journeyman analysts.
- Manage and tune SIEM platforms (e.g., Splunk, Elastic SIEM, Cribl) to enhance detection capabilities and threat visibility.
- Conduct forensic investigations and attack reconstruction using the Cyber Kill Chain and MITRE ATT&CK frameworks.
- Evaluate network and system configurations for vulnerabilities, providing recommendations aligned with DoD security standards.
- Assess and ensure compliance with Security Technical Implementation Guides (STIGs) and handle Information Assurance Vulnerability Management (IVAM) notifications.
- Utilize asset mapping tools to verify connected inventory and detect unauthorized devices.
- Produce detailed technical and executive-level reports summarizing findings, impacts, and recommended mitigations.
- Collaborate with client leadership to optimize SOC processes, incident response workflows, and threat-hunting strategies.
- Active Secret Clearance (or higher).
- Minimum of 5 years of experience in cybersecurity operations, incident response, or SOC analysis.
- Strong understanding of DoD cybersecurity frameworks, MITRE ATT&CK, and Cyber Kill Chain.
- Demonstrated expertise in network traffic analysis, vulnerability management, and SIEM engineering.
- Hands‑on experience with tools such as Splunk, Palo Alto, Elastic SIEM, VMware, Nessus, Crowd Strike, or Security Center.
- Proven ability to lead investigations, mentor team members, and communicate effectively with both technical and non‑technical audiences.
- Relevant certifications such as CISSP, GCIH, CEH, OSCP, or GRID are highly desired.
- Experience with Nessus, Endgame, Crowd Strike, SCADA systems, and more.
- Proficiency in Splunk Enterprise Security, using tstats and data models for continuous monitoring.
- Knowledge of handling security incidents and evidence according to best practices.
- Experience securing Operational Technology (OT) or Industrial Control Systems (ICS) environments.
- Advanced skill in Splunk Enterprise Security content development (tstats, data models, correlation rules).
- Familiarity with tools and protocols such as Gray Noise, Shodan, MODBus, SCADA systems, or PCAP analysis.
- Strong analytical, troubleshooting, and forensic investigation capabilities.
- Understanding of evidence handling and cybersecurity best practices for government environments.
$120,000 to $145,000
Akira’s pay range for this position considers various factors including skills, years of experience, training, licenses, certifications, alignment with market data, and internal equity in the organization. This pay range estimate is a general guideline only and not a guarantee of compensation or salary, which Akira believes to be done in good faith in compliance with local laws. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled.
It is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case.
Akira offers its employees multiple options for medical plans (some with Health Savings Account), dental…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).