{"id":1948145,"url":"https://alion.io/job/saic-cybersecurity-analyst","title":"Cybersecurity Analyst","company":{"id":58788,"name":"SAIC","domain":"saic.com","url":"https://alion.io/company/saic","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Oracle","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Fayetteville, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":106000,"max_usd":211000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":974},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"MITRE ATT&CK","optional":false},{"name":"SIEM","optional":false},{"name":"Splunk","optional":false},{"name":"YARA","optional":false},{"name":"YARA","optional":false},{"name":"PowerShell","optional":true},{"name":"Python","optional":true}],"status":"live","first_seen_at":"2026-09-29T21:59:08Z","employer_posted_date":"2026-09-29","last_verified_at":"2026-10-06T22:24:52Z","board_verified":true,"closed_at":null,"days_open":7,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":7},"description":"SAIC is seeking a Cybersecurity Analysts to support the Special Operation Command Information Technology Enterprise Contract (SITEC) - 3 EOM. This position is located at Fort Bragg, NC.\nThe purpose of the Special Operations Forces Information Technology Enterprise Contract (SITEC) 3 Enterprise Operations and Maintenance (EOM) Task Order (TO) is to provide USSOCOM, its Component Commands, its Theater Special Operations Commands (TSOCs), and its deployed forces with Operations and Maintenance (O&M) services to maintain Network Operations (NetOps); maintain systems and network infrastructure; provide end user and common device support; provide configuration, change, license, and asset management; conduct training, and perform Install, Move, Add, Change (IMACs) services. The responsibilities and tasks associated with each requirement play a pivotal role to USSOCOM, the CIO/J6 organization, and ultimately the end-user who operate around the globe 24x7x365.\nThis position offers an opportunity for experienced cybersecurity professionals to take on advanced responsibilities in defending USSOCOM’s global operations. The Cybersecurity Analyst will play a pivotal role in enhancing SOC capabilities, mentoring junior team members, and ensuring the security and resilience of systems critical to USSOCOM’s mission success.\nThe Cybersecurity Analyst will be responsible for but not limited to the following duties:\nExpertise in identifying and analyzing sophisticated threats using SIEM platforms, intrusion detection systems (IDS), and other advanced tools.\nStrategic ability to correlate data from multiple sources to uncover advanced persistent threats (APTs) and complex attack patterns.\nProficiency in refining detection rules and alerts to enhance threat identification capabilities. Leadership in managing high-priority security incidents, including coordinating containment, eradication, and recovery strategies.\nAdvanced skills in root cause analysis and delivering actionable recommendations for future mitigation.\nAbility to create detailed post-incident reports to inform organizational strategy and resilience.\nAbility to lead audits and assessments, providing recommendations to enhance compliance and streamline processes.\nAdvanced skills in securing NetOps and systems/network infrastructure against evolving threats.\nLeadership in mentoring junior analysts, fostering their growth and technical expertise.\nStrategic collaboration with SOC team members, IT staff, and stakeholders to develop coordinated threat responses.\nAbility to contribute to cross-functional discussions and drive improvements in SOC operations.\nContinuous Improvement and Research.\nCommitment to staying informed on emerging threats, technologies, and best practices to enhance SOC capabilities.\nStrategic mindset to research and recommend tools, techniques, and strategies for improved operations.\nAbility to deliver training sessions to elevate team knowledge and preparedness.\nOperate within a 24/7 SOC environment, which may require shift work, including nights, weekends, and holidays.\nHandle sensitive and classified information in compliance with DoD and USSOCOM requirements.\nActively perform Cyber, correlate logs, report findings, and coordinate with cyber analysts to contain users/systems and initiate formal CSSP documentation.\nAnalyze network traffic logs and encrypted patterns to identify ongoing threats, anomalous behavior, command-and-control (C2) channels, active exploitation, or data exfiltration attempts.\nMonitor NSA Pulse investigations related to USASOC assets and brief branch chiefs to coordinate mitigation while preventing duplication of effort with Cyber Analysts.\nCoordinate with Cyber Operators for threat intelligence sharing, escalation criteria, and remediation plans.\nDevelop threat hunt playbooks based on industry findings, historical trends, or G639 requirements to systematically search for indicators of compromise.\nContextualize and aggregate logs between Splunk, MDE environments, and other SIE native tools for data generation.\nDevelop and refine advanced detection logic (e.g., Sigma, YARA, or Splunk SPL signatures) based on emerging TTPs to automate the identification of malicious activity.\nMap all hunt findings and defensive gaps to the MITRE ATT&CK Framework to prioritize mission focus areas based on adversary trends.\nEngage in \"Purple Team\" operations alongside adversary emulation cells to verify that security controls are effectively detecting and blocking known exploit techniques.\"\n Required Education:\nBachelor's degree and five (5) years’ experience; additional four (4) years’ experience can be considered in lieu of degree.\nRequired Clearance:\nMust possess an active TS/SCI security clearance with the ability to maintain; US Citizenship required.\nRequired Skills:\nStrong understanding of cybersecurity concepts, including threat detection, malware analysis, and network security.\nProficiency with one or more tools such as SIEM platforms, IDS/IPS, endpoint protection solutions, and forensic analysis tools.\nAdvanced analytical and problem-solving skills with the ability to handle complex incidents and scenarios.\nEffective communication skills, including the ability to create detailed reports and brief stakeholders.\nAbility to work independently and lead initiatives in a fast-paced, team-oriented environment.\nRequired Certifications:\nMust be DoW 8140 compliant under the Work Role Code 531 - Cyber Defense Incident Responder - Intermediate level.\nDesired Skills:\nBachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent experience).\nAdvanced certifications such as CISSP, GIAC (e.g., GCIA, GCIH), or OSCP.\nExperience with scripting or automation tools (e.g., Python, PowerShell) and threat hunting techniques.\nKnowledge of advanced threat intelligence platforms and methodologies.","description_format":"text","description_chars":5900,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":true},"security_clearance":true,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Security","Digital Government","Engineering Services"],"lifecycle":[{"event":"open","at":"2026-10-06T08:16:08Z"}],"visa":[],"liveness":{"score":84,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.839,"p_room":1,"age_days":7,"expected_fill_days":30,"reasons":["conf:1","win:early","comp:brand"],"computed_at":"2026-10-07T00:13:12Z"},"pay":null,"html_url":"https://alion.io/job/saic-cybersecurity-analyst","json_url":"https://alion.io/job/saic-cybersecurity-analyst.json","meta":{"generated_at":"2026-10-07T00:13:12Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":300,"day_limit":5000,"remaining_today":4700,"minute_limit":60,"resets_at":"2026-10-08T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":58788},"rest":"https://alion.io/mcp/rest/get_company?id=58788"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fsaic-cybersecurity-analyst"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fsaic-cybersecurity-analyst"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fsaic-cybersecurity-analyst"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/saic-cybersecurity-analyst\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fsaic-cybersecurity-analyst"}]}