Enter a job title or keyword

Security Operations Center Analyst Low


Job Location:

Washington, DC - USA

Monthly Salary: Not provided by the employer
Posted: 17 July 2026 (30+ days ago)
Application Deadline: 14 October 2026
Vacancies: 1 Vacancy

Job Summary

Koniag Data Solutions LLC a Koniag Government Services company is seeking a Security Operations Center Analyst - Low to support KDS and our government customer in Washington DC. This position requires the candidate to be able to obtain a Public offer competitive compensation and an extraordinary benefits package including health dental and vision insurance 401K with company matching flexible spending accounts paid holidays three weeks paid time off and Data Solutions a Koniag Government Services company is seeking a motivated and detail-oriented Junior Security Operations Center (SOC) Analyst to support the U.S. Small Business Administration (SBA). The ideal candidate is an early-career cybersecurity professional with a foundational understanding of security operations network security monitoring and incident response concepts. This individual will work under the guidance and mentorship of senior SOC analysts and the Cybersecurity Operations Technical Lead supporting the continuous monitoring and defense of SBAs enterprise IT environment and gaining valuable hands-on experience in federal cybersecurity operations. The Junior SOC Analyst will support the continuous monitoring threat detection and incident response activities of SBAs Security Operations Center performing first-line security event monitoring alert triage and incident documentation under the direction of senior SOC staff. Principal responsibilities will include but are not limited to:Perform first-line monitoring and triage of security alerts and events generated by SBAs SIEM platform IDS/IPS systems endpoint detection and response (EDR) tools and other security monitoring technologies escalating potential security incidents to senior SOC analysts in accordance with established SOC procedures and escalation in the initial triage and analysis of security events and alerts applying foundational knowledge of common threat indicators attack patterns and malicious activity signatures to differentiate true positive security incidents from false positive alerts under the guidance of senior SOC incident response activities for identified security incidents assisting senior analysts in documenting incident details collecting relevant evidence and maintaining accurate and timely incident records in SBAs incident management and ticketing SBAs networks systems and endpoints for indicators of compromise (IOCs) anomalous activity and policy violations escalating observations and findings to senior SOC analysts for further investigation and in the collection review and analysis of security-relevant log data from diverse sources including Windows Event Logs Syslog firewall logs web proxy logs and application logs supporting senior analysts in identifying patterns of potentially malicious the documentation and tracking of security incidents tickets and cases within SBAs incident management platform ensuring accurate complete and timely recording of incident details response actions and resolution in the preparation of SOC shift handoff reports daily activity summaries and security event trend reports supporting senior SOC staff in maintaining situational awareness and communicating SOC activity status to vulnerability management activities by assisting in the review and documentation of vulnerability scan results tracking remediation ticket status and maintaining accurate vulnerability management records under the guidance of senior SOC in maintaining and updating SOC documentation including Standard Operating Procedures (SOPs) incident response playbooks runbooks and knowledge base articles ensuring documentation remains current and accurately reflects SOC operational procedures and lessons actively in SOC team meetings briefings training sessions and knowledge-sharing activities applying lessons learned and new knowledge to continuously improve personal performance and contribute to the overall capability of the SOC the review and analysis of threat intelligence reports and advisories from US-CERT CISA and other government and commercial sources assisting senior analysts in identifying relevant threats and IOCs applicable to SBAs in the monitoring and enforcement of SBAs security policies and acceptable use standards documenting potential policy violations and escalating findings to senior SOC staff for review and purple team and tabletop exercise activities by assisting in the documentation of exercise scenarios findings and lessons learned contributing to the continuous improvement of SBAs detection and response in continuous self-directed learning and professional development activities to build expertise in cybersecurity operations threat detection and incident response working toward recognized industry certifications and expanded SOC responsibilities over and Experience:Required:Bachelors degree in Cybersecurity Information Technology Computer Science or a related field from an accredited college or university.0-2 years of experience in cybersecurity IT operations or a related field with demonstrated foundational knowledge of security operations network monitoring or incident response familiarity with security operations concepts including security event monitoring alert triage incident response and common cybersecurity threat or more of the following certifications:CompTIA SecurityCompTIA CySACompTIA NetworkSystems Security Certified Practitioner (SSCP)Microsoft Security Operations Analyst Associate (SC-200)Desired:1-2 years of experience in a SOC IT operations help desk or cybersecurity-related role with hands-on exposure to security event monitoring alert triage or incident response internship academic project or work experience supporting cybersecurity operations or security monitoring activities in a federal government or enterprise SOC Analyst (CSA) certification or active pursuit of Skills and Competencies:Strong communication skills in English both written and oral with the ability to clearly document security events incidents and observations and effectively communicate findings and escalations to senior SOC staff and other understanding of security operations center (SOC) concepts and workflows including security event monitoring alert triage incident classification escalation procedures and incident knowledge of common cybersecurity threat types attack techniques and indicators of compromise (IOCs) including malware phishing unauthorized access attempts denial of service and insider with SIEM platforms and the ability to navigate SIEM dashboards query security event data and review alerts under the guidance of senior SOC analysts with experience in platforms such as Splunk Microsoft Sentinel or understanding of network security concepts including TCP/IP networking fundamentals common network protocols firewall concepts and IDS/IPS functionality sufficient to support first-line review and interpretation of network security events and with endpoint security concepts and basic EDR tool functionality including the ability to review endpoint alerts and telemetry data under senior staff guidance to support initial triage log analysis skills including the ability to review and interpret log entries from common sources such as Windows Event Logs Syslog and firewall logs with an understanding of key log fields and their security with incident response concepts and the phases of the incident response lifecycle including preparation detection and analysis containment eradication recovery and post-incident attention to detail and accuracy in documenting security events incidents and response activities within incident management and ticketing ability and willingness to work collaboratively under the direction of senior staff in a team-oriented mission-driven environment actively seeking guidance and feedback to improve personal performance and contribution to the SOC familiarity with the MITRE ATT&CK framework and its application to understanding adversary tactics techniques and procedures (TTPs) relevant to security event monitoring and alert triage work ethic intellectual curiosity and genuine commitment to continuous learning and professional development in the field of cybersecurity to obtain and maintain a Public Trust Skills and Competencies:Prior experience or academic coursework related to security operations network security monitoring or incident response demonstrating foundational knowledge of SOC workflows and cybersecurity operations with cloud security monitoring concepts and basic awareness of cloud-native security logging and monitoring capabilities in AWS Azure or GCP familiarity with threat intelligence concepts including an understanding of IOCs threat feeds and the role of threat intelligence in supporting SOC monitoring and alert triage with vulnerability management concepts and basic experience reviewing vulnerability scan results with an understanding of common vulnerability scoring systems such as scripting familiarity such as an introductory understanding of Python or PowerShell with an interest in developing automation skills to support SOC workflow efficiency over of federal cybersecurity frameworks and compliance requirements including basic familiarity with NIST SP 800-53 NIST SP 800-61 and FISMA and their relevance to SOC operations within a federal government with the CDM (Continuous Diagnostics and Mitigation) program and its role in supporting continuous monitoring activities within federal civilian using ticketing and case management platforms such as ServiceNow Jira or equivalent for tracking and documenting security incidents and SOC in cybersecurity competitions such as CTF (Capture the Flag) events academic cybersecurity research or other extracurricular activities demonstrating a genuine passion for cybersecurity and a commitment to professional interest in pursuing advanced cybersecurity certifications such as the GIAC Security Operations Certified (GSOC) Certified SOC Analyst (CSA) or GIAC Certified Incident Handler (GCIH) as part of a long-term professional development plan in cybersecurity Equal Employment Opportunity PolicyThe company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race color religion creed ethnicity sex sexual orientation gender or gender identity (except where gender is a bona fide occupational qualification) national origin or ancestry age disability citizenship military/veteran status marital status genetic information or any other characteristic protected by applicable federal state or local law. We are committed to equal employment opportunity in all decisions related to employment promotion wages benefits and all other privileges terms and conditions of company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website please get in touch with Heaven Wood via e-mail by calling to request Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical professional and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers employees and native communities. For more information please Opportunity Employer/Veterans/ Preference in accordance with Public Law 88-352

Required Experience:

IC


About Company

Company Logo

What We Do Koniag Government Services (KGS) is an Alaska Native Corporation comprised of multiple wholly owned subsidiary companies that deliver Enterprise Solutions, Professional Services, and Operations Management to Federal Government agencies. With an agile employee and corporate ... View more

View Profile View Profile