cFocus Software logo
cFocus Software

63 open roles

USAF - Security Operations Analyst

Linthicum Heights, MDPosted Oct 10, 2026

Job description

c. Focus Software seeks a Security Operations Analyst to join our program supporting the United States Air Force (USAF). This position is on-site in Linthicum Heights, MD. This position requires an Active TS/SCI clearance.

Qualifications

Active TS/SCI clearance B.S. Computer Science, Information Technology, or a related field Experience monitoring security events, investigating alerts, and supporting enterprise incident response. Ability to correlate telemetry, assess anomalies, and document investigation findings. Knowledge of network protocols, endpoints, access controls, and cyberattack techniques.

Experience with security monitoring, log analysis, endpoint detection, and vulnerability tools. Ability to hunt threats and apply intelligence to investigations and detection improvements. Understanding of incident response, evidence handling, and approved escalation procedures. Ability to analyze vulnerabilities and coordinate remediation with technical teams.

Strong analytical judgment, collaboration, and writing skills for timely investigations Duties: Monitor and triage security alerts, logs, and events; correlate available telemetry to identify suspicious activity and potential threats. Analyze network, endpoint, application, and cloud security data within assigned environments to determine event validity, severity, scope, and mission impact.

Conduct data and intelligence-driven threat hunting to identify hidden or advanced threats in DC3 IT and OT environments. Investigate anomalous behavior, distinguish false positives from potential incidents, and document evidence, findings, and recommended responses. Detect, analyze, and respond to suspected security incidents; escalate confirmed incidents through established Government-approved procedures.

Perform assigned containment, eradication, and recovery activities upon incident confirmation, within authorized procedures and access permissions. Maintain incident records, timelines, investigation notes, and supporting evidence in accordance with approved handling and documentation procedures. Coordinate incident response and recovery with infrastructure, network, application, cloud, and cybersecurity teams; verify assigned corrective actions.

Analyze vulnerability assessment findings, support risk prioritization and remediation tracking, and coordinate validation with certified assessment specialists. Provide continuous analysis of security events and trends; recommend detection improvements and mitigation actions for Government consideration. Support operation and maintenance of assigned SOC tools and sensors; identify telemetry gaps and coordinate corrective action with responsible teams.

Support SOC coordination with Cybersecurity Service Providers (CSSPs), the AFCYBER Operations Center, and applicable higher headquarters authorities. Track assigned cyber orders and taskers; coordinate status, required actions, and supporting evidence through approved command and control channels. Contribute incident response procedures, lessons learned, security monitoring documentation, and evidence supporting compliance activities.

Research emerging threats, cybersecurity practices, and technologies; document benefits, risks, and implementation recommendations.

Description copied from cFocus Software's careers page. Read the full posting before you apply.

More jobs at cFocus Software

See all openings at cFocus Software