Cyber Security / SOC Analyst (Weekend Nights)

At phia we hire talented and passionate people who are focused on collaborative, meaningful work, providing technical and operational subject matter expertise and support services to our partners and clients.

phia is hiring a Cyber Operations Analyst (SOC Threat Management) to support 24x7 operations in a large Federal agency Cyber Security Operations Center (CSOC). This role focuses on advanced cyber threat monitoring & detection, incident analysis and management, and leveraging AI/ML and automation to enhance SOC efficiency. The ideal candidate will have expertise in IT and cyber incident management, cyber threat intelligence and intrusion analysis, and hands-on experience with modern security tools and cloud environments.

This shift-based position offers REMOTE work flexibility. Qualified candidates will be U.S. Citizens and located in the United States, able to achieve Public Trust security vetting approval.

Weekday Night shift position

This position will have the following primary work hours:

  • Initial Temporary Orientation & Qualification: Monday - Friday, 7:00am-3:30pm (ET)
  • Final Assigned Shift: Monday - Friday, 11:00pm-7:30am (ET)

What You'll Do:

  • Support 24x7 monitoring, detection, and management of advanced cyber threats.
  • Execute operational processes in support of response efforts to identified security incidents.
  • Perform deep-dive incident analysis by correlating data from multiple sources to determine impact on critical systems or datasets.
  • Interpret output from the SIEM, incident reporting platforms and mailboxes, and phone calls to identify potential security incidents.
  • Handle incidents as defined in Playbooks and SOPs.
  • Identify security problems which may require mitigating controls, and advise on remediation actions.
  • Analyze threat intelligence to assess risk and adapt defenses.
  • Provide subject matter expertise on network-based attacks, intrusion methodologies, and threat management.
  • Escalate complex incidents for further investigation and collaborate with other Threat Management team members.
  • Utilize AI/ML-based tools to detect anomalies, automate triage, and improve threat intelligence.
  • Provide input and analysis on how to leverage Artificial Intelligence, Machine Learning, and SOAR capabilities to improve CSOC efficiency and accuracy.
  • Stay current on cybersecurity trends, threat actors, and AI/ML advancements relevant to SOC operations.
  • Tune security policies, maintain visibility into cloud and endpoint environments, and support continuous improvement of the organization's security posture.
  • Identify and support automation use cases, including the use of AI/ML to enhance SOC capabilities.
  • Collaborate across the larger organization to provide SOC enhancement capabilities through the use of automation and AI.

Who You Are:

  • Experienced in cyber/IT security with at least 3 years of experience in IT and/or SOC operations.
  • Familiar with both command and sophisticated threat actor tools and techniques.
  • Skilled in network traffic analysis and threat detection methodologies.
  • Strong understanding of Boolean logic, TCP/IP fundamentals, network-level exploits, and IDS/IPS technologies and signature development & optimization.
  • Familiar with IT control frameworks, risk management techniques, and cloud security (AWS, Azure, GCP).
  • Hands-on experience with cybersecurity automation and SIEM/SOAR platforms.
  • Proficient in using ML frameworks for anomaly detection, threat intelligence and behavioral analysis.
  • Skills in data analysis and feature engineering, with the ability to process and transform large datasets from various sources (e.g., logs, network traffic) to extract relevant features for machine learning models aimed at identifying security incidents and vulnerabilities.
  • Familiarity with the application of AI/ML techniques in cybersecurity, including but not limited to automated threat detection, incident response automation, and predictive analytics. Experience in evaluating the effectiveness of AI/ML solutions in a SOC environment is a plus.
  • Excellent communication, organizational, and interpersonal skills.

Preferred Skills:

  • Experience with Splunk, ProofPoint, Cisco FirePower, SentinelOne, Microsoft Defender Microsoft Defender for Cloud Apps, Defender for Endpoint, Defender XDR, Defender for Office 365, Azure Entra ID, and Google Cloud Security Command Center (SCC).
  • Expertise with IDS/IPS architectures, signature creation, and anomaly-based detection.
  • Strong data analysis and feature engineering skills for ML-based security models.
  • Direct experience with AI/ML applications in SOC environments, including automated threat detection and predictive analytics.

Required Education + Experience:

  • BA/BS in Computer Science, IT, or related field (or equivalent experience) with 3+ years of direct experience in cybersecurity and SOC analysis & operations

...or...

  • 7+ years of experience in cybersecurity and IT and SOC analysis & operations

Certifications (desired, or similar):

  • CompTIA Security+
  • Certified Ethical Hacker (CEH)
  • GIAC Certified Enterprise Defender (GCED)
  • GIAC Certified Intrusion Analyst (GCIA)
  • GIAC Certified Detection Analyst (GCDA)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Defending Advanced Threats (GDAT)
  • GIAC Security Operations Certified (GSOC)
  • Certified Information Systems Security Professional (CISSP)

Security Clearance/Vetting:

  • U.S. Citizenship required
  • Ability to obtain Public Trust clearance

WORK LOCATION: Remote
TRAVEL: N/A
TELEWORK ELIGIBILITY: Yes
SECURITY REQUIREMENTS: Public Trust

Who We Are

phia LLC ("phia") is a Northern Virginia based, small business established in 2011 with focus in Cyber Intelligence, Cyber Security/Defense, Intrusion Analysis & Incident Response, Cyber Architecture & Capability Analysis, Cyber Policy & Strategy, Information Assurance/Security, Compliance, Certification & Accreditation, Communications Security, Traditional Security, and Facilities Security. phia also provides cyber operations support functions such as: Program and Process Management, Engineering, Development, and Systems Administration that allows for Cyber Operations to efficiently integrate our customer's missions and objectives. phia supports various agencies and offices within the Department of Defense (DoD), Federal government, and private/commercial entities.

phia offers excellent benefits to enhance work-life balance, including the following:

  • Medical Insurance
  • Dental Insurance
  • Vision Insurance
  • Life Insurance
  • Short Term & Long Term Disability
  • 401k Retirement Savings Plan with Company Match
  • Paid Holidays
  • Paid Time Off (PTO)
  • Tuition and Professional Development Assistance

phia does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity, or any other reason prohibited by law in the provision of employment opportunities and benefits.

Back to blog

Other Jobs To Apply

Reporter - Fully Remote | Up to $110/hr

Remote Technical Support Specialist - Entry Level, No Degree Required

Overnight Customer Service Specialist - No Experience Needed

[Hiring] Video Content Lead @RemoteJobsOne

Mechatronics & Robotics Tech , RME

Head of Channel Partnerships, MCCF

Call Center Agent (PT or FT - 100% Work From Home)

Part Time Manufacturing Associate - Anna, OH (45350)

Internship Ground Operations Crew Member Job ID- 2913

Virtual Assistant Data Entry Jr (Part-Time)

Flight Attendant Trainee

Aetna Remote Jobs, Aetna Careers Remote – – Job ID – 231 Job ID- 2384

Software Engineer II (REMOTE)

American Airlines Customer Service Jobs - (Work At Home)

Part-time/Weekend SOC Analyst (6522)

Process Assistant

CCC Certified Pharm Tech (Remote), Clinical Customer Care - Amazon Pharmacy

Overnight Warehouse Associate

AI Language Expert - Portuguese

Amazon Warehouse - Shopper / Order Fulfillment Associate $17-$23/hr

SOC Analyst L1

Baltimore Part-Time:Fulfillment Center-Package Sorter

Join Today: Chat Support Remote Agent (Part Time, Entry Level)

Amazon Customer Service - Work From Home $16-$24/hr

Overnight Warehouse Associate(Gig)-Desoto

Amazon Customer Service - Work From Home $16-$35/hr

Farmington,NM:Outbound Dock Worker at Amazon | Hiring

General Warehouse Associate- Weekend Shift

Warehouse Associate (PT/FT with 1st/2nd/3rd shift openings)

Customer Experience Consultant (Remote)

Package Handler - Part Time (Warehouse like)

Virtual Administrative Assistant (Remote, U.S. and Canada Only)

Senior Restaurant Manager

Amazon Customer Service - Work From Home $16-$24/hr

Remote Customer Service Representative – California (100% Remote | Equipment Provided | November 30 Start)

Warehouse Picker Packer - Now Hiring

Remote Customer Service Rep Up To 19Hour No Degree Needed

[Remote] International Health Certificate Project Specialist (Veterinary Technician)

Remote Customer Service Specialist

Work From Home Amazon Jobs Job ID- 1671

Video Content Moderator - Remote

Delivery driver | Miami Beach, FL

Sales Account Manager, Hardlines

Warehouse Operative

Cargo Agent

Facilities Enhancement Technician

Beta Reading

Amazon Delivery Driver

Amazon Delivery Driver

Bilingual Spanish Customer Experience Associate

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...