{"id":1503070,"url":"https://alion.io/job/by-light-cnd-analyst-soc","title":"CND Analyst - SOC","company":{"id":1964053,"name":"By Light","domain":"bylight.com","url":"https://alion.io/company/bylight","size_band":"11-50","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"iCIMS","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Falls Church, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":106000,"max_usd":209000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":775},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"ITIL","optional":false},{"name":"ITSM","optional":false},{"name":"SIEM","optional":false}],"status":"live","first_seen_at":"2026-09-30T04:41:54Z","employer_posted_date":"2026-09-30","last_verified_at":"2026-09-30T14:00:37Z","board_verified":true,"closed_at":null,"days_open":1,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":1},"description":"Company Overview\nBy Light Professional IT Services LLC readies warfighters and federal agencies with technology and systems engineered to connect, protect, and prepare individuals and teams for whatever comes next. Headquartered in McLean, VA, By Light supports defense, civilian, and commercial IT customers worldwide.\nPosition Overview\nBy Light has an opening for a CND Analyst - SOC supporting the Army National Guard (ARNG) in Falls Church, VA. This is an IT Service Management contract in support of the operation, modernization, expansion, and further evolution of the ARNG’s global Information Technology (IT) services including networking, compute, storage, infrastructure, applications, hosting, and program management services. The Guard Enterprise Cyber Operations Support (GECOS) program supports the ARNG enterprise IT infrastructure, its Wide Area Network (WAN), authentication and directory services, cybersecurity, application hosting, and associated services. GECOS uses ITIL best practices framework as the basis for IT Service Management (ITSM) model.\nThis position is: T hursday through Saturday (12-hour shifts) and every other Wednesday (8-hour shift)\nResponsibilities\nThe ARNG SOC works to monitor enterprise systems, defend against security breaches, and identify, investigate, and mitigate cybersecurity threats. In support of the SOC, the Watch SOC Team staff shall:\nManage the operation of the SOC and the performance of traditional SOC activities on behalf of ARNG 24/7/365 to protect DoD information systems and infrastructure.\nDevelop a SOC Communications Plan.\nSupport the RCC-NG in the execution of traditional SOC activities during COOP exercises at a designated COOP site. If it becomes necessary to temporarily relocate SOC operations to a selected alternate site for emergency or test scenarios, support and extend normal SOC operations to that remote location.\nProvide technical reports to analyze and summarize the impact of each significant incident and the recovery costs; the capability and effectiveness of Computer Network Defense (CND) sensor coverage and the O&M costs; and the number and categories of threats of concern identified by the SOC and supplied to the SOC by external Government agencies\nAuthor and implement custom detection content (e.g., reports, assets, cases, connectors, customers, dashboards, field sets, files, filters, integration commands, knowledge base, lists, notifications, pattern discovery, query viewers, reports, rules, stages, and users).\nTune the SIEM and IDS/IPS events to minimize false positives.\nAnalyze and review monitoring SOC metrics.\nEvaluate and analyze hardware and software in coordination with and support of the RCC-NG.\nImprove processes including developing and refining analysis techniques.\nCoordinate and report ISS-related incidents.\nProvide support in assembling, evaluating, and monitoring various intrusion detection sensors or tools and associated software applications\nProvide DMA support services involving forensic analyses on a variety of digital media devices and mediums to identify, reverse engineer, and de-obfuscate content related to an incident, such as malicious content\nRequired Experience/Qualifications\nBachelor's degree required\nWillingness to work the required shift of Thursday through Saturday (12-hour shifts) and every other Wednesday (8-hour shift)\nMinimum 5 years IT relevent experience and 3 years SOC operations support\nExperience managing firewall, IDS/IPS, and router ACL policies\nExperience with vulerability management assessment and mitgation\nPossess the appropriate DoD 8570 CSSP Analyst, Infrastructure, or Incident Responder certification e.g., CEH, CySA+, CCNA+, SSCP, CGIA. \nPreferred Experience/Qualifications\nCisco Certification\nPalo Alto Certification\nPossess an ITIL® v3 or ITIL® 4 Foundation or a higher certification in either category\nSpecial Requirements/Security Clearance\nActive SECRET DoD clearance or higher\nSalary Range\nSalary Minimum: $85,000\nSalary Maximum: $115,000\nThe annual base salary provided is a guideline for this position and is not a guarantee of compensation or salary. When extending an offer, By Light also considers other variables such as (but not limited to) work experience, education, training, skill set, internal peer equity, clearance level, and market conditions. In addition, By Light provides an extensive selection of benefits and offerings to our employees.","description_format":"text","description_chars":4433,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":true,"languages":[]},"benefits":["Equity"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":true,"industries":["Incident Response","Cybersecurity","Military","Science & Engineering"],"lifecycle":[{"event":"open","at":"2026-09-30T04:41:54Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":1,"expected_fill_days":30,"reasons":["conf:15","velocity","win:early"],"computed_at":"2026-10-01T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/by-light-cnd-analyst-soc","json_url":"https://alion.io/job/by-light-cnd-analyst-soc.json","meta":{"generated_at":"2026-10-02T01:16:57Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1511,"day_limit":5000,"remaining_today":3489,"minute_limit":60,"resets_at":"2026-10-03T00:00:00Z"}}}