Summary
CACI International Inc is a mission-driven defense and cybersecurity company supporting critical Department of Defense systems. The Security Operations Analyst will monitor and analyze security events across endpoint, network, cloud, and access security platforms, detect and escalate incidents, conduct vulnerability assessments, and report security posture metrics to program leadership.
Responsibilities
- Monitor and analyze security events and alerts using Elastic Security SIEM
- Conduct vulnerability scans with Tenable SC and assess cloud workloads via Tenable Cloud Security
- Manage and enforce endpoint security policies using Trellix ePO or Microsoft Defender for Endpoint (MDE)
- Monitor network security activity across Palo Alto Next-Generation Firewalls
- Analyze secure access traffic through Zscaler Private Access and Internet Access
- Detect, document, and escalate security incidents following established response procedures
- Develop continuous monitoring reports and contribute to security posture dashboards
- Track and present security KPIs to program leadership
Skills
- Active Secret or Top Secret clearance
- 3–5 years of experience in a security operations or SOC environment
- Hands-on experience with a SIEM platform (Elastic Security strongly preferred)
- Working knowledge of vulnerability scanning tools (Tenable SC preferred)
- Familiarity with network security monitoring and firewall technologies
- DoD 8140.03M DCWF Basic Tier Certification — one of: CC, GDSA, or GISF
- DoD 8140 Interim Education Options
- Required to travel to Scott Airforce base on a quarterly basis
- Elastic Certified Analyst or Elastic Certified Engineer
- Experience with Palo Alto NGFW or Zscaler platforms
- Exposure to cloud workload security monitoring
- Bachelor's degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering
- DoD 8140.03M DCWF Intermediate Tier — one of: CEH(P), ECIH, GRID, RCCE Level 1, CBROPS, CCSP, CEH, Cloud+, FITSP-O, GCED, GCIH, GSEC, PenTest+, or Security+
Qualifications
Must Haves
- Active Secret or Top Secret clearance
- 3–5 years of experience in a security operations or SOC environment
- Hands-on experience with a SIEM platform (Elastic Security strongly preferred)
- Working knowledge of vulnerability scanning tools (Tenable SC preferred)
- Familiarity with network security monitoring and firewall technologies
- DoD 8140.03M DCWF Basic Tier Certification — one of: CC, GDSA, or GISF
- DoD 8140 Interim Education Options
- Required to travel to Scott Airforce base on a quarterly basis
Nice to Haves
- Elastic Certified Analyst or Elastic Certified Engineer
- Experience with Palo Alto NGFW or Zscaler platforms
- Exposure to cloud workload security monitoring
- Bachelor's degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering
- DoD 8140.03M DCWF Intermediate Tier — one of: CEH(P), ECIH, GRID, RCCE Level 1, CBROPS, CCSP, CEH, Cloud+, FITSP-O, GCED, GCIH, GSEC, PenTest+, or Security+
Benefits
- A unique flexible time off benefit
- Robust learning resources
- Healthcare benefits
- Wellness benefits
- Financial benefits
- Retirement benefits
- Family support benefits
- Continuing education benefits
- Time off benefits