USAF Security Operations Analyst
Job Location:
Anne Arundel County, MD - USA
Monthly Salary:
Not provided by the employer
Posted:
11 October 2026 (9 hours ago)
Application Deadline:
8 January 2027
Vacancies:
1 Vacancy
Job Summary
cFocus Software seeks a Security Operations Analyst to join our program supporting the United States Air Force (USAF). This position is on-site in Linthicum Heights MD. This position requires an Active TS/SCI clearance.
Qualifications:
Qualifications:
- Active TS/SCI clearance
- B.S. Computer Science Information Technology or a related field
- Experience monitoring security events investigating alerts and supporting enterprise incident response.
- Ability to correlate telemetry assess anomalies and document investigation findings.
- Knowledge of network protocols endpoints access controls and cyberattack techniques.
- Experience with security monitoring log analysis endpoint detection and vulnerability tools.
- Ability to hunt threats and apply intelligence to investigations and detection improvements.
- Understanding of incident response evidence handling and approved escalation procedures.
- Ability to analyze vulnerabilities and coordinate remediation with technical teams.
- Strong analytical judgment collaboration and writing skills for timely investigations
- Monitor and triage security alerts logs and events; correlate available telemetry to identify suspicious activity and potential threats.
- Analyze network endpoint application and cloud security data within assigned environments to determine event validity severity scope and mission impact.
- Conduct data and intelligence-driven threat hunting to identify hidden or advanced threats in DC3 IT and OT environments.
- Investigate anomalous behavior distinguish false positives from potential incidents and document evidence findings and recommended responses.
- Detect analyze and respond to suspected security incidents; escalate confirmed incidents through established Government-approved procedures.
- Perform assigned containment eradication and recovery activities upon incident confirmation within authorized procedures and access permissions.
- Maintain incident records timelines investigation notes and supporting evidence in accordance with approved handling and documentation procedures.
- Coordinate incident response and recovery with infrastructure network application cloud and cybersecurity teams; verify assigned corrective actions.
- Analyze vulnerability assessment findings support risk prioritization and remediation tracking and coordinate validation with certified assessment specialists.
- Provide continuous analysis of security events and trends; recommend detection improvements and mitigation actions for Government consideration.
- Support operation and maintenance of assigned SOC tools and sensors; identify telemetry gaps and coordinate corrective action with responsible teams.
- Support SOC coordination with Cybersecurity Service Providers (CSSPs) the AFCYBER Operations Center and applicable higher headquarters authorities.
- Track assigned cyber orders and taskers; coordinate status required actions and supporting evidence through approved command and control channels.
- Contribute incident response procedures lessons learned security monitoring documentation and evidence supporting compliance activities.
- Research emerging threats cybersecurity practices and technologies; document benefits risks and implementation recommendations.
Required Experience:
Senior IC
About Company
Our exclusive ATO as a Serviceâ„¢ software & expert services automate FISMA RMF & FedRAMP compliance.