Netrio

Level 1 Cyber Security Analyst

The SOC Analyst I is an entry-to-early-career security operations role responsible for front-line monitoring, triage, and initial response within Netrio's Government SOC. This role aligns to the DoD 8140/DCWF Cyber Defense Analyst (511) work role and serves as the first line of defense for detecting and escalating potential security incidents across federal and Defense Industrial Base (DIB) client environments hosted in government-authorized cloud platforms.

Key Responsibilities

     Monitor SIEM/XDR and endpoint detection and response (EDR) alerts in real time across assigned client environments

     Perform initial triage and classification of security alerts per documented playbooks and escalation criteria

     Document findings, actions taken, and escalation decisions in the ticketing system with accuracy and completeness

     Escalate confirmed or suspected incidents to Tier 2 analysts per defined SLAs

     Support DFARS 252.204-7012 incident reporting timelines (72-hour DIBNet reporting window) by ensuring timely internal escalation

     Monitor identity and access signals (conditional access alerts, sign-in anomalies) within government-tenant environments

     Maintain situational awareness of ticket queues, shift handoff notes, and open incidents throughout assigned shift

     Participate in shift handoff briefings to ensure continuity of coverage

     Follow chain-of-custody and evidence-handling procedures for any data preserved in support of an investigation

     Adhere to all CMMC Level 2 / NIST SP 800-171 handling requirements for Controlled Unclassified Information (CUI)

Required Qualifications

     0–2 years of experience in a SOC, help desk, IT security, or related technical role (internships and training-equivalent experience considered)

     Working knowledge of networking fundamentals (TCP/IP, DNS, common ports/protocols) and Windows/Linux operating systems

     Basic understanding of the cyber threat landscape (phishing, malware, common attack techniques)

     Ability to follow structured playbooks and escalation procedures precisely

     Strong written communication skills for ticket documentation and shift handoff

     U.S. Citizenship (required for access to government client environments)

     Ability to pass a background investigation as required by client contracts

Required Certifications (DoD 8140/DCWF Alignment)

CompTIA Security+ or (ISC)² Certified in Cybersecurity (CC).

If not held at hire, certification must be obtained within the first 6 months of employment as a condition of continued assignment to government client accounts (DoD 8140 baseline certification requirement).

Preferred Qualifications

     Prior exposure to a SIEM or EDR platform (any vendor)

     Familiarity with ITIL-based ticketing/service management processes

     Coursework or certifications in cybersecurity fundamentals (e.g., Network+, CySA+ in progress)

     Prior experience in a regulated or government-adjacent environment

Work Environment & Physical Requirements

     Extended periods at a workstation monitoring multiple screens/dashboards

     Ability to work rotating shifts, including nights, weekends, and holidays

     Ability to respond to off-hours pages/alerts during on-call rotation

     This is a 24/7 operational function — reliable attendance and shift punctuality are essential job functions

This job requisition is intended to describe the general nature of the work performed. It is not an exhaustive list of all duties, responsibilities, and qualifications required.

 

Netrio is a leading MSP in North America, specializing in IT solutions for small- to mid-market enterprises. We serve over 1,000 clients across industries with services including managed IT, cybersecurity, cloud, connectivity, voice, and custom application development.

Service Delivery

McKinney, TX

Partilhar em:

Termos de serviço.PrivacidadeCookiesDesenvolvido pela Rippling