cFocus Software Incorporated

USAF - Security Operations Analyst

Linthicum Heights, Maryland · Posted today

Opens cfocussoftware.applytojob.com

Get a version of your resume written for this job.

Salary
Not listed
Job type
Full-time
Work mode
Not specified
Source
Jazzhr (employer's hiring system)

Skills mentioned

Incident Response, Cybersecurity, Cloud Security

About the role

cFocus Software seeks a Security Operations Analyst to join our program supporting the United States Air Force (USAF). This position is on-site in Linthicum Heights, MD. This position requires an Active TS/SCI clearance.
Qualifications:
  • Active TS/SCI clearance
  • B.S. Computer Science, Information Technology, or a related field
  • Experience monitoring security events, investigating alerts, and supporting enterprise incident response.
  • Ability to correlate telemetry, assess anomalies, and document investigation findings.
  • Knowledge of network protocols, endpoints, access controls, and cyberattack techniques.
  • Experience with security monitoring, log analysis, endpoint detection, and vulnerability tools.
  • Ability to hunt threats and apply intelligence to investigations and detection improvements.
  • Understanding of incident response, evidence handling, and approved escalation procedures.
  • Ability to analyze vulnerabilities and coordinate remediation with technical teams.
  • Strong analytical judgment, collaboration, and writing skills for timely investigations
Duties:
  • Monitor and triage security alerts, logs, and events; correlate available telemetry to identify suspicious activity and potential threats.
  • Analyze network, endpoint, application, and cloud security data within assigned environments to determine event validity, severity, scope, and mission impact.
  • Conduct data and intelligence-driven threat hunting to identify hidden or advanced threats in DC3 IT and OT environments.
  • Investigate anomalous behavior, distinguish false positives from potential incidents, and document evidence, findings, and recommended responses.
  • Detect, analyze, and respond to suspected security incidents; escalate confirmed incidents through established Government-approved procedures.
  • Perform assigned containment, eradication, and recovery activities upon incident confirmation, within authorized procedures and access permissions.
  • Maintain incident records, timelines, investigation notes, and supporting evidence in accordance with approved handling and documentation procedures.
  • Coordinate incident response and recovery with infrastructure, network, application, cloud, and cybersecurity teams; verify assigned corrective actions.
  • Analyze vulnerability assessment findings, support risk prioritization and remediation tracking, and coordinate validation with certified assessment specialists.
  • Provide continuous analysis of security events and trends; recommend detection improvements and mitigation actions for Government consideration.
  • Support operation and maintenance of assigned SOC tools and sensors; identify telemetry gaps and coordinate corrective action with responsible teams.
  • Support SOC coordination with Cybersecurity Service Providers (CSSPs), the AFCYBER Operations Center, and applicable higher headquarters authorities.
  • Track assigned cyber orders and taskers; coordinate status, required actions, and supporting evidence through approved command and control channels.
  • Contribute incident response procedures, lessons learned, security monitoring documentation, and evidence supporting compliance activities.
  • Research emerging threats, cybersecurity practices, and technologies; document benefits, risks, and implementation recommendations.

Job ID jz-cfocussoftware-20261009151228_gv77yogwb7225lu8 · Original posting ↗