ECS

SOC Technician (Shift 1 Lead) - Senior

ECS$75K — $95K *
Aerospace & Defense
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • U.S. Citizenship required
  • Secret Eligible Security Clearance
  • One or more required certifications (e.g., CC, CEH, GFACT, GISF)
  • 1+ years of cybersecurity experience
  • Experience with security log monitoring and anomalous activity detection
  • Proficient in event analysis and log correlation
  • Familiar with DoD/ARNG cybersecurity policies

Responsibilities

  • Monitor security logs and network telemetry to detect anomalies
  • Perform log correlation and pattern analysis for timely detection
  • Document events and findings in case management systems
  • Escalate incidents per established response procedures
  • Support continuous monitoring and maintain records for auditability
  • Assist in tracking evidence for cyber incident responses
  • Coordinate with SOC analysts and cyber teams for comprehensive operations

Benefits

  • Opportunity to work with the Army National Guard's cybersecurity program
  • Contribute to nationwide defense efforts across multiple states
  • Gain exposure to advanced cyber defense technologies and practices
  • Collaborate with a team of cybersecurity professionals
  • Potential for career development in a growing field
Full Job Description
Position Summary

ECS is seeking a SOC Technician (Shift 1 Lead) - Senior to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support (ENOCS) program. In this role, you will support Task 3 - Cybersecurity Operations Support by monitoring security logs, network telemetry, and endpoint alerts; identifying anomalous activity and potential indicators of compromise; performing log correlation and preliminary pattern analysis; documenting findings in case management systems; and escalating events in accordance with established response procedures. This position contributes to ENOCS's 24x7x365 cybersecurity operations by supporting Security Operations Center monitoring and analysis activities that integrate with incident, problem, and change processes across the broader cyber operations team.

This role supports ARNG's mission to defend classified and unclassified network environments across the DoDIN-Army-NG area of responsibility, enabling Title 10 and Title 32 missions, mobilization readiness, domestic emergency response, and classified SIPRNet operations. The SOC Technician helps protect an enterprise serving more than 120,000 users and approximately 141,000 endpoints across about 2,800 sites in 54 states and territories. The position operates within the ENOCS cyber environment that includes Unified Security Information & Event Management (USIEM) analytics, endpoint detection and response, IDS/IPS monitoring, integrated SIEM/C2C/DLP analytics, and coordination with organizations such as the NETCOM Global Cyber Center and DISA DCDC to support Defensive Cyberspace Operations - Internal Defensive Measures (DCO-IDM).

Please Note: This position is contingent upon contract award.

Responsibilities

  • Monitor security logs, network telemetry, and endpoint alerts to identify anomalous activity and potential indicators of compromise across ARNG classified and unclassified environments.
  • Perform log correlation and preliminary pattern analysis using approved analytic rules and established monitoring procedures to support timely detection and escalation.
  • Document observations, findings, and event details in case management systems, ensuring tickets are complete, accurate, and updated throughout the response lifecycle.
  • Escalate incidents and suspicious activity in accordance with established response procedures and Tier 2 incident, problem, and change processes.
  • Support continuous monitoring reporting requirements aligned with DoD and ARNG cybersecurity policy, maintaining accurate records for operational visibility and auditability.
  • Assist with evidence tracking and event documentation to support cyber incident response, follow-on analysis, and lessons learned.
  • Leverage integrated SIEM/C2C/DLP analytics and available security data sources to improve visibility and support threat-informed monitoring within the SOC.
  • Coordinate with SOC analysts, service owners, and supporting cyber teams to support USIEM and endpoint detection activities within ARNG's DCO-IDM mission.
  • Contribute to cybersecurity operations that interface with the NETCOM Global Cyber Center and DISA DCDC in defense of the DoDIN-Army-NG area of responsibility.


Required Qualifications

U.S. Citizenship is required

Security Clearance: Secret Eligible

Required Certifications: DCWF Work Role 511-Cyber Defense Analyst - Basic proficiency; must hold ONE OR MORE of the following: CC, CEH, GFACT, GISF

Experience: 1+ years of experience in cybersecurity
  • Experience monitoring security logs, network telemetry, and endpoint alerts for suspicious or anomalous activity.
  • Ability to perform preliminary event analysis, pattern recognition, and log correlation using approved procedures and analytic rules.
  • Experience documenting findings, maintaining ticket accuracy, and updating case management records throughout event handling activities.
  • Familiarity with continuous monitoring activities in support of DoD or ARNG cybersecurity policy requirements.
  • Ability to support evidence tracking and maintain organized records for incident handling and reporting.
  • Familiarity with classified and unclassified network defense operations in an enterprise cybersecurity environment.
  • Ability to coordinate effectively with incident response, problem management, and change management stakeholders during event escalation.

About ECS

ECS is a leading provider of digital solutions and services to the federal government. The company was founded in 2001 by Roy Kapani and has since grown to become a trusted partner to a wide range of government agencies. ECS offers a broad range of services, including cloud computing, cybersecurity, and artificial intelligence. The company has been recognized for its innovative solutions and has won numerous awards, including the AWS Public Sector Partner of the Year award.
Learn more about ECS
Size
2,000 employees
Industry

Similar Jobs

More Jobs at ECS

  • ECS
    STO Programmatic SETA
    $120K — $150K *
    Arlington, VA 22204 (Arlington County)
    Aerospace & Defense
    In-Person
  • ECS
    AI Methodologist
    $120K — $150K *
    Fairfax, VA 22030 (Fairfax City County)
    Aerospace & Defense
    In-Person
  • ECS
    Software Engineer IV
    $100K — $130K *
    Moorestown, NJ 08057 (Burlington County)
    Aerospace & Defense
    In-Person
  • ECS
    Software Engineer III
    $100K — $130K *
    Moorestown, NJ 08057 (Burlington County)
    Aerospace & Defense
    In-Person
  • ECS
    Program Control Analyst Senior
    $90K — $120K *
    Fairfax, VA 22030 (Fairfax City County)
    Aerospace & Defense
    In-Person

More Aerospace & Defense Jobs

Find similar SOC Technician (Shift 1 Lead) - Senior jobs: