Senior Cybersecurity Operations Center Analyst

Booz Allen Hamilton

Confirmed live today High trust

Quick summary

Work type
On-site
Location
Honolulu, HI
Salary
$99,000–$225,000 / yr
Employment
Full-time
Posted
36 days ago
Freshness
Confirmed live today

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $148k
This role $162k
$84k most similar roles pay here $240k

This role pays more than 68% of similar roles. Most pay $122,275–$174,706 — the shaded band above. At the midpoint, this role pays about $162k versus about $148k for comparable roles.

Based on 240 similar postings.

Employer

About Booz Allen Hamilton

Booz Allen Hamilton is a management and technology consulting firm that provides analytics, digital, engineering, and cybersecurity solutions primarily to U.S. government agencies and commercial clients. Industry: Management & Technology Consulting

Booz Allen Hamilton currently has 1385 open roles on FindRole.

Listed pay typically runs $86,800–$198,000 across 911 roles with salary data.

Most-posted roles

View all roles at Booz Allen Hamilton

At a glance

TL;DR · Senior Cybersecurity Operations Center Analyst

Cybersecurity Operations Center Analyst, Senior serves on the security operations center team to protect critical infrastructure from cyber-attacks. You will lead a professional team in evaluating potential weaknesses and the effectiveness of mitigation strategies for cybersecurity solutions. Daily responsibilities include improving tier monitoring strategies, analyzing threat intelligence and event data to identify attacker patterns, and managing incident response lifecycles including triage, root cause investigation, and recovery efforts. You will also develop standard operating procedures and generate after-action reports while coordinating technical communication with stakeholders. The role requires expertise in cyberspace operations systems to aggregate threat feeds for leadership briefings. Required skills include experience with endpoint tools, network and host-based information for threat hunting, and digital forensics. Technical requirements include a TS/SCI clearance and specific certifications such as Elastic, GCFA, or GNFA.

What you'll do

  • Analyze real-time threats and use advanced tools to identify patterns and stop malicious actors.
  • Lead a team of professionals to evaluate cybersecurity solution weaknesses and mitigation effectiveness.
  • Manage the full incident lifecycle including triage, root cause investigation, containment, and remediation.
  • Develop and refine standard operating procedures (SOPs) for all stages of incident response.
  • Create new detection rules and refine existing alerts to improve monitoring tool accuracy.
  • Coordinate technical responses and communicate status updates to key stakeholders during active incidents.
  • Manage post-compromise activities including the removal of malicious artifacts and recovery of services.
  • Aggregate threat feeds to create information briefings for senior leadership.

What we're looking for

  • 6+ years of experience working in a Security Operations Center (SOC) at a classified level within the Department of Defense.
  • Experience leading every phase of the incident lifecycle, including triage, deep-dive investigation, and remediation strategies.
  • Experience evolving continuous monitoring toolsets by generating new detection rules and refining existing alerts.
  • Experience developing and maturing standard operating procedures (SOPs) and SOC responsibilities across the incident response lifecycle.
  • Ability to manage post-compromise activities, including artifact eradication, service recovery, and generating After-Action Reports.
  • Ability to serve as a primary focal point for technical coordination and communication during active incident response operations.
  • High school diploma or GED.
  • Ability to obtain an 8570 DoW approved CSSP baseline certification before start date.
  • Experience using Elastic for monitoring, analysis, and case management (preferred).
  • Experience using endpoint tools to hunt for adversarial behavior (preferred).
  • Experience with GCFA, GNFA, or equivalent digital forensics (preferred).
  • Ability to conduct threat hunting using network and host-based information (preferred).
  • TS/SCI clearance with a polygraph (preferred).
  • 8570 CSSP Analyst or Incident Responder Certification (preferred).

More like this

Similar roles

Cybersecurity Analyst

Booz Allen Hamilton

Indianapolis, IN +1 2 days ago $69,400–$158,000
Incident Response SIEM Threat Intelligence DoD STIGs SRGs ACAS ESS

Defensive Cyber Operations Analyst

Booz Allen Hamilton

Peterson AFB, CO 5 days ago $69,300–$158,000
Splunk HBSS Microsoft Defender Security Onion SIGACT RALLY Incident Response Threat Intelligence Network Security Cybersecurity Information Assurance NetOps AI
1+ yrs exp

Security Operations Center Analyst

Booz Allen Hamilton

Columbia, MD 22 days ago $69,400–$158,000
Splunk SIEM Incident Response Linux CLI Nix Bro Zeek Suricata Snort Nessus Firewall Configuration SOAR Splunk Phantom Threat Intelligence AI
2+ yrs exp

Cyber Security Analyst

Leidos

Adelphi, MD 40 days ago $87,100–$157,450
SIEM IDS Incident Response NetFlow Packet Capture AWS Microsoft Azure Google Cloud Platform Oracle Cloud TCP/IP Unix Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp Hybrid

Senior Cybersecurity Analyst

Caterpillar

East Peoria, IL +2 3 days ago $112,710–$183,140
Qualys Vulnerability Management ServiceNow AWS Azure Python PowerShell CMDB CI/CD TCP/IP Linux Windows Security Copilot Microsoft Copilot Asset Management Threat Intelligence CVSS ITIL