CACI International

Cyber Monitoring Analyst

CACI International$75K — $158K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Active Top Secret/SCI security clearance.
  • Bachelor’s degree in IT Technology, Computer Science, or related field with 5 years of experience in cyber operations or monitoring, or equivalent experience.
  • DOD 8140 (8570) IAT Level II (Security+ or equivalent).
  • Deep understanding of the Incident Response lifecycle, particularly in detection and escalation.
  • Proficiency in Elastic Stack (Elasticsearch, Logstash, Kibana) for log analysis.
  • Excellent problem-solving and analytical skills.
  • Effective written and verbal communication skills.

Responsibilities

  • Continuously monitor security alerts and logs for potential threats and anomalous activity.
  • Utilize Elastic Stack for real-time log analysis and incident tracking.
  • Document and escalate security events—reporting to tiered cyber analyst teams and external stakeholders.
  • Follow and maintain cybersecurity SOPs and incident response playbooks for effective monitoring.
  • Maintain detailed documentation of monitoring activities and incident timelines.
  • Contribute to proactive threat detection and escalation through alert review and behavioral analysis.
  • Monitor threat intelligence feeds for emerging threats, escalating relevant findings.

Benefits

  • Comprehensive healthcare and wellness benefits.
  • Financial and retirement support options.
  • Family support services.
  • Continuing education opportunities.
  • Paid time off benefits.
Full Job Description
Job Title: Cyber Monitoring Analyst

Job Category: Information Technology

Time Type: Full time

Minimum Clearance Required to Start: TS/SCI

Employee Type: Regular

Percentage of Travel Required: Up to 10%

Type of Travel: Local

* * *


The Opportunity:
Our client is seeking a highly motivated Cyber Monitoring Analyst that will join the Cyber Security Incident Response Team supporting the AF DCGS program located onsite at Langley AFB, Va. The ideal candidate will have intermediate-level skills in Windows, Linux, and Cloud environments, supported by a background in system administration or security monitoring. They should be experienced in using SIEMs or other cyber monitoring tools for real-time threat detection and log analysis. In addition, the candidate must be capable of executing monitoring and escalation procedures in alignment with the established Incident Response Plan (IRP), with minimal oversight.
This position is embedded within a high-tempo operational environment and demands a proactive approach to monitoring, alert triage, and escalation. Candidates must be comfortable working independently during shift rotations and contributing to a shift-based 24/7 monitoring environment, including weekends and holidays.

Responsibilities:
• Continuously monitor security alerts and system logs to identify potential threats and anomalous activity across the OA DCGS weapon system, ensuring its confidentiality, integrity, and availability.
• Utilize ELK/Elastic Stack to conduct real-time log analysis, detect threats, and support investigations; maintain dashboards and incident records for visibility and reporting.
• Escalate and document security events using established ticketing systems, ensuring timely and accurate reporting to internal cyber analyst tiers (T1–T3) and appropriate external stakeholders beyond the Incident Response (IR) team.
• Follow and maintain cybersecurity standard operating procedures (SOPs) and incident response playbooks to ensure consistent and effective monitoring practices.
• Maintain detailed documentation of monitoring activities, incident timelines, and case notes to support post-incident reviews and compliance requirements.
• Contribute to proactive threat detection by reviewing SIEM alerts and security dashboards to identify indicators of compromise (IOCs) and anomalous activity, supporting early escalation through behavioral analysis and correlation techniques.
• Monitor threat intelligence feeds and security news for emerging threats, including Zero-Day vulnerabilities and CVEs, and escalate relevant findings to senior analysts for integration into detection workflows.
• Collaborate with incident response, threat hunting, and vulnerability management teams to ensure seamless handoff and resolution of detected threats.
• Operate independently during assigned shifts, responding to alerts with urgency and precision to minimize potential impact.
• Support penetration testing evaluations by responding to simulated threats in real time, enabling measurement of key performance indicators (KPIs) such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR)

Qualifications:

Required:
• Active Top Secret/SCI security clearance.
• Bachelors degree in IT Technology, Computer Science, or related field with 5 years of experience in cyber operations or monitoring. Degree may be substituted with equivalent experience.
• DOD 8140 (8570) IAT Level II (Security+ or equivalent).
• Deep understanding of the Incident Response lifecycle, especially in detection and escalation phases.
• Proficiency in Elastic Stack (Elasticsearch, Logstash, Kibana) for log analysis.
• Familiarity with cyber security tools and monitoring procedures
• Excellent problem-solving and analytical skills to identify and respond to threats in real time.
• Effective written and verbal communication skills for documentation and collaboration
• Ability to work independently in a shift-based 24/7 monitoring environment, including weekends and holidays.

Desired:

• Experience supporting AF DCGS systems or similar military ISR platforms.
• Proficiency in using the Elastic Stack (Elasticsearch, Logstash, Kibana)
• Experience with AWS or other cloud security platforms

-

What You Can Expect:

A culture of integrity.


Pay Range:

There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits.

The proposed salary range for this position is:

$75,200-$158,100

About CACI International

CACI International Inc is a multinational professional services and information technology company. It provides services to many branches of the federal government including defense, homeland security, intelligence, and healthcare. CACI has approximately 23,000 employees worldwide. The company's mission is to provide enterprise and mission technology services and solutions that best fit the needs of its customers. CACI has been named a Fortune World's Most Admired Company, a Washington Post Top Workplace, and a Forbes Best Employer for Diversity.
Learn more about CACI International
Size
22,000 employees
Market Cap
$7.1 billion
Industry
Net Income
$374.4 million
Founded
1962
5 Year Trend
+7.3%
Revenue
$5.8 billion
NASDAQ

Similar Jobs

More Jobs at CACI International

More Information Technology Jobs

Find similar Cyber Monitoring Analyst jobs: