Job Requirements
Redstone Arsenal, AL
Secret CI Polygraph
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Summary
OT/ICS SOC Analyst
Huntsville, Alabama
Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employer's core culture? If so, Chenega Military, Intelligence & Operations Support (MIOS) could be the place for you! Join our team of professionals who support large-scale government operations by leveraging cutting-edge technology and take your career to the next level!
Chronos Operations (CO) is a wholly-owned subsidiary of Chenega Corporation, an Alaska Native Corporation based in Anchorage, AK. Belonging to the Military, Intelligence, and Operations Support (MIOS) Strategic Business Unit (SBU), Chronos has a culture rooted in integrity, respect, and exceptional performance. Chronos is headquartered in Colorado Springs, CO, and provides mission-critical services in Advanced Analytics & AI, Software Engineering, Cybersecurity, Information Technology, and Intelligence.
We deliver essential cyber services to our customers in support of their missions to sustain the national security and economic interests of our nation.
The OT / ICS SOC Analyst performs advanced monitoring, threat hunting, anomaly investigation, incident response coordination, and threat analysis across converged IT/OT environments, Industrial Control Systems (ICS), Supervisory Control and Data Acquisition (SCADA) platforms, Distributed Control Systems (DCS), and mission support networks.
Operating with increased autonomy within established operational authorities and rules of engagement, the analyst correlates telemetry across the Purdue Model (Levels 1-3+), evaluates physical process anomalies alongside digital indicators, ensures response measures prioritize personnel safety and process reliability, and continuously improves OT-specific detection mechanisms, playbooks, and defensive readiness.
Responsibilities
Qualifications
Preferred Qualifications:
Knowledge, Skills and Abilities:
How you'll grow
At Chenega MIOS, our professional development plan focuses on helping our team members at every level of their careers to identify and use their strengths to do their best work every day. From entry-level employees to senior leaders, we believe there's always room to learn.
We offer opportunities to help sharpen skills in addition to hands-on experience in the global, fast-changing business world. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their careers.
Benefits
At Chenega MIOS, we know that great people make a great organization. We value our team members and offer them a broad range of benefits.
Learn more about what working at Chenega MIOS can mean for you.
Chenega MIOS's culture
Our positive and supportive culture encourages our team members to do their best work every day. We celebrate individuals by recognizing their uniqueness and offering them the flexibility to make daily choices that can help them be healthy, centered, confident, and aware. We offer well-being programs and continuously look for new ways to maintain a culture where we excel and lead healthy, happy lives.
Corporate citizenship
Chenega MIOS is led by a purpose to make an impact that matters. This purpose defines who we are and extends to relationships with our clients, our team members, and our communities. We believe that business has the power to inspire and transform. We focus on education, giving, skill-based volunteerism, and leadership to help drive positive social impact in our communities.
Learn more about Chenega's impact on the world.
Chenega MIOS News- https://chenegamios.com/news/
Tips from your Talent Acquisition Team
We want job seekers exploring opportunities at Chenega MIOS to feel prepared and confident. To help you with your research, we suggest you review the following links:
Chenega MIOS web site - www.chenegamios.com
Glassdoor - https://www.glassdoor.com/Overview/Working-at-Chenega-MIOS-EI_IE369514.11,23.htm
LinkedIn - https://www.linkedin.com/company/1472684/
Facebook - https://www.facebook.com/chenegamios/
#Chronos Operations, LLC
OT/ICS SOC Analyst
Huntsville, Alabama
Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employer's core culture? If so, Chenega Military, Intelligence & Operations Support (MIOS) could be the place for you! Join our team of professionals who support large-scale government operations by leveraging cutting-edge technology and take your career to the next level!
Chronos Operations (CO) is a wholly-owned subsidiary of Chenega Corporation, an Alaska Native Corporation based in Anchorage, AK. Belonging to the Military, Intelligence, and Operations Support (MIOS) Strategic Business Unit (SBU), Chronos has a culture rooted in integrity, respect, and exceptional performance. Chronos is headquartered in Colorado Springs, CO, and provides mission-critical services in Advanced Analytics & AI, Software Engineering, Cybersecurity, Information Technology, and Intelligence.
We deliver essential cyber services to our customers in support of their missions to sustain the national security and economic interests of our nation.
The OT / ICS SOC Analyst performs advanced monitoring, threat hunting, anomaly investigation, incident response coordination, and threat analysis across converged IT/OT environments, Industrial Control Systems (ICS), Supervisory Control and Data Acquisition (SCADA) platforms, Distributed Control Systems (DCS), and mission support networks.
Operating with increased autonomy within established operational authorities and rules of engagement, the analyst correlates telemetry across the Purdue Model (Levels 1-3+), evaluates physical process anomalies alongside digital indicators, ensures response measures prioritize personnel safety and process reliability, and continuously improves OT-specific detection mechanisms, playbooks, and defensive readiness.
Responsibilities
- Monitor and analyze security telemetry across network, endpoint, identity, cloud, application, email, and other enterprise sources using approved SIEM, XDR, NDR, and security analytics platforms.
- Investigate escalated or complex cybersecurity events to determine validity, scope, affected assets and identities, potential mission impact, and required response actions.
- Correlate alerts with asset criticality, vulnerability information, threat intelligence, user behavior, and historical activity to develop evidence-based analytical conclusions.
- Lead or perform incident triage and analysis; collect, preserve, and document relevant evidence in accordance with established procedures and evidence-handling requirements.
- Execute authorized containment and response actions, including host isolation, account restriction, indicator blocking, or other approved measures, and coordinate eradication and recovery activities with responsible stakeholders.
- Develop clear incident records, analytical findings, timelines, and technical reports; communicate status, risk, and recommended actions to SOC leadership and mission stakeholders.
- Apply threat intelligence, indicators of compromise, adversary tactics, techniques, and procedures, and frameworks such as MITRE ATT&CK to identify related activity and support defensive recommendations.
- Review and validate findings, recommendations, and summaries generated by automated analytics, machine learning, or AI-enabled cybersecurity capabilities before operational use.
- Tune alerts and detection logic, recommend telemetry improvements, and help reduce false positives, coverage gaps, and analyst workload in coordination with detection engineering or platform owners.
- Develop, test, maintain, and improve incident response playbooks, standard operating procedures, queries, dashboards, and repeatable analytical workflows.
- Participate in or facilitate post-incident reviews and lessons-learned activities; translate findings into corrective actions and measurable operational improvements.
- Mentor SOC Analyst I personnel, provide quality reviews of escalated cases, and share technical knowledge across shifts and teams.
- Support cyber exercises, readiness assessments, recovery validation, and continuous improvement activities as directed by the SOC Lead.
- Perform additional duties as assigned.
Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Technology, Software Engineering, Data Science, or a related field and 3+ years of relevant experience.
- Or applicants may meet one of the following substitutions:
- Associate's degree and 5+ years of relevant experience.
- High school diploma or GED equivalent and 7+ years of relevant experience.
- Relevant experience must include cybersecurity operations, security monitoring, network defense, incident response, threat analysis, system administration, or a closely related information technology discipline. At least 2+ years must involve SOC, cyber defense, or incident response functions.
- Active DOD IAT Level II Certification or higher is required.
- Active Secret clearance with the ability to obtain and maintain TS/SCI eligibility.
Preferred Qualifications:
- Active TS/SCI clearance.
- 5+ or more years of relevant cybersecurity experience, including 2+ or more years in a SOC, cyber defense, or incident response environment.
- Experience investigating endpoint, network, identity, cloud, email, or application security events using SIEM, EDR/XDR, NDR, SOAR, vulnerability management, or threat intelligence platforms.
- OT/ICS Security Tooling: Hands-on operational experience with leading OT security and asset inventory platforms such as Dragos Platform, Claroty Continuous Threat Detection (CTD), Nozomi Networks Guardian, Tenable OT (Indegy), or ForeScout eyeInspect.
- Working familiarity with programmable logic controllers (PLCs), remote terminal units (RTUs), human-machine interfaces (HMIs), distributed control systems (DCS), and safety instrumented systems (SIS) manufactured by vendors such as Rockwell Automation/Allen-Bradley, Siemens, Schneider Electric, Emerson, or GE.
- Experience developing or tuning detection logic, analytical queries, dashboards, automation, or incident response playbooks.
- Experience applying MITRE ATT&CK, threat intelligence, and adversary behaviors to investigations and defensive recommendations.
- Experience supporting the Department of Defense, Federal Civilian, Intelligence Community, or critical infrastructure missions.
- Role-Specific Certifications:
- GIAC Global Industrial Cyber Security Professional (GICSP)
- GIAC Response and Industrial Defense (GRID)
- GIAC Critical Infrastructure Protection (GCIP)
- ISA/IEC 62443 Cyber Security Specialist/Expert
- GIAC Certified Incident Handler (GCIH) or CISSP
Knowledge, Skills and Abilities:
- OT/ICS Protocol Analysis: Demonstrated ability to dissect and analyze industrial protocol traffic (Modbus TCP/RTU, DNP3, CIP, Ethernet/IP, OPC, BACnet, PROFINET, S7comm) and identify anomalies such as unauthorized command functions or out-of-spec register writes.
- Purdue Model & Boundary Defense: Advanced understanding of industrial network segmentation, IDMZs, jump hosts, dual-homed servers, unidirectional security gateways (data diodes), and boundary firewall rulebases separating Level 4/5 IT from Level 0-3 OT.
- Safe Operational Response: Strict appreciation of the primacy of safety, physical reliability, and process availability over data confidentiality, understanding that standard IT containment methods (e.g., abrupt host isolation or aggressive vulnerability scanning) can cause equipment trips or physical hazards.
- Adversary Tradecraft in ICS: Knowledge of real-world OT/ICS threat actors, destructive malware families (e.g., Industroyer/CrashOverride, TRITON/Trisis, INCONTROLLER/Pipedream), living-off-the-land techniques in engineering environments, and supply chain threats.
- Packet & Tooling Competency: Advanced proficiency in Wireshark, tcpdump, and specialized dissectors, combined with scripting capabilities (Python, PowerShell, Bash) and query building (KQL, SPL, Lucene).
- Interdisciplinary Collaboration: Proven ability to bridge the cultural and technical gap between cybersecurity teams and operational plant/controls engineers, translating cyber events into operational and physical consequences.
How you'll grow
At Chenega MIOS, our professional development plan focuses on helping our team members at every level of their careers to identify and use their strengths to do their best work every day. From entry-level employees to senior leaders, we believe there's always room to learn.
We offer opportunities to help sharpen skills in addition to hands-on experience in the global, fast-changing business world. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their careers.
Benefits
At Chenega MIOS, we know that great people make a great organization. We value our team members and offer them a broad range of benefits.
Learn more about what working at Chenega MIOS can mean for you.
Chenega MIOS's culture
Our positive and supportive culture encourages our team members to do their best work every day. We celebrate individuals by recognizing their uniqueness and offering them the flexibility to make daily choices that can help them be healthy, centered, confident, and aware. We offer well-being programs and continuously look for new ways to maintain a culture where we excel and lead healthy, happy lives.
Corporate citizenship
Chenega MIOS is led by a purpose to make an impact that matters. This purpose defines who we are and extends to relationships with our clients, our team members, and our communities. We believe that business has the power to inspire and transform. We focus on education, giving, skill-based volunteerism, and leadership to help drive positive social impact in our communities.
Learn more about Chenega's impact on the world.
Chenega MIOS News- https://chenegamios.com/news/
Tips from your Talent Acquisition Team
We want job seekers exploring opportunities at Chenega MIOS to feel prepared and confident. To help you with your research, we suggest you review the following links:
Chenega MIOS web site - www.chenegamios.com
Glassdoor - https://www.glassdoor.com/Overview/Working-at-Chenega-MIOS-EI_IE369514.11,23.htm
LinkedIn - https://www.linkedin.com/company/1472684/
Facebook - https://www.facebook.com/chenegamios/
#Chronos Operations, LLC
group id: 10125215
Chenega Corporation - Snapshot