user avatar

OT / ICS SOC Analyst

Chenega Corporation

Posted today

Job Requirements

Redstone Arsenal, AL
Secret CI Polygraph
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries

Job Description

Summary

OT/ICS SOC Analyst

Huntsville, Alabama

Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employer's core culture? If so, Chenega Military, Intelligence & Operations Support (MIOS) could be the place for you! Join our team of professionals who support large-scale government operations by leveraging cutting-edge technology and take your career to the next level!

Chronos Operations (CO) is a wholly-owned subsidiary of Chenega Corporation, an Alaska Native Corporation based in Anchorage, AK. Belonging to the Military, Intelligence, and Operations Support (MIOS) Strategic Business Unit (SBU), Chronos has a culture rooted in integrity, respect, and exceptional performance. Chronos is headquartered in Colorado Springs, CO, and provides mission-critical services in Advanced Analytics & AI, Software Engineering, Cybersecurity, Information Technology, and Intelligence.

We deliver essential cyber services to our customers in support of their missions to sustain the national security and economic interests of our nation.

The OT / ICS SOC Analyst performs advanced monitoring, threat hunting, anomaly investigation, incident response coordination, and threat analysis across converged IT/OT environments, Industrial Control Systems (ICS), Supervisory Control and Data Acquisition (SCADA) platforms, Distributed Control Systems (DCS), and mission support networks.

Operating with increased autonomy within established operational authorities and rules of engagement, the analyst correlates telemetry across the Purdue Model (Levels 1-3+), evaluates physical process anomalies alongside digital indicators, ensures response measures prioritize personnel safety and process reliability, and continuously improves OT-specific detection mechanisms, playbooks, and defensive readiness.

Responsibilities

  • Monitor and analyze security telemetry across network, endpoint, identity, cloud, application, email, and other enterprise sources using approved SIEM, XDR, NDR, and security analytics platforms.
  • Investigate escalated or complex cybersecurity events to determine validity, scope, affected assets and identities, potential mission impact, and required response actions.
  • Correlate alerts with asset criticality, vulnerability information, threat intelligence, user behavior, and historical activity to develop evidence-based analytical conclusions.
  • Lead or perform incident triage and analysis; collect, preserve, and document relevant evidence in accordance with established procedures and evidence-handling requirements.
  • Execute authorized containment and response actions, including host isolation, account restriction, indicator blocking, or other approved measures, and coordinate eradication and recovery activities with responsible stakeholders.
  • Develop clear incident records, analytical findings, timelines, and technical reports; communicate status, risk, and recommended actions to SOC leadership and mission stakeholders.
  • Apply threat intelligence, indicators of compromise, adversary tactics, techniques, and procedures, and frameworks such as MITRE ATT&CK to identify related activity and support defensive recommendations.
  • Review and validate findings, recommendations, and summaries generated by automated analytics, machine learning, or AI-enabled cybersecurity capabilities before operational use.
  • Tune alerts and detection logic, recommend telemetry improvements, and help reduce false positives, coverage gaps, and analyst workload in coordination with detection engineering or platform owners.
  • Develop, test, maintain, and improve incident response playbooks, standard operating procedures, queries, dashboards, and repeatable analytical workflows.
  • Participate in or facilitate post-incident reviews and lessons-learned activities; translate findings into corrective actions and measurable operational improvements.
  • Mentor SOC Analyst I personnel, provide quality reviews of escalated cases, and share technical knowledge across shifts and teams.
  • Support cyber exercises, readiness assessments, recovery validation, and continuous improvement activities as directed by the SOC Lead.
  • Perform additional duties as assigned.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Technology, Software Engineering, Data Science, or a related field and 3+ years of relevant experience.
  • Or applicants may meet one of the following substitutions:
    • Associate's degree and 5+ years of relevant experience.
    • High school diploma or GED equivalent and 7+ years of relevant experience.
    • Relevant experience must include cybersecurity operations, security monitoring, network defense, incident response, threat analysis, system administration, or a closely related information technology discipline. At least 2+ years must involve SOC, cyber defense, or incident response functions.
  • Active DOD IAT Level II Certification or higher is required.
  • Active Secret clearance with the ability to obtain and maintain TS/SCI eligibility.


Preferred Qualifications:
  • Active TS/SCI clearance.
  • 5+ or more years of relevant cybersecurity experience, including 2+ or more years in a SOC, cyber defense, or incident response environment.
  • Experience investigating endpoint, network, identity, cloud, email, or application security events using SIEM, EDR/XDR, NDR, SOAR, vulnerability management, or threat intelligence platforms.
  • OT/ICS Security Tooling: Hands-on operational experience with leading OT security and asset inventory platforms such as Dragos Platform, Claroty Continuous Threat Detection (CTD), Nozomi Networks Guardian, Tenable OT (Indegy), or ForeScout eyeInspect.
  • Working familiarity with programmable logic controllers (PLCs), remote terminal units (RTUs), human-machine interfaces (HMIs), distributed control systems (DCS), and safety instrumented systems (SIS) manufactured by vendors such as Rockwell Automation/Allen-Bradley, Siemens, Schneider Electric, Emerson, or GE.
  • Experience developing or tuning detection logic, analytical queries, dashboards, automation, or incident response playbooks.
  • Experience applying MITRE ATT&CK, threat intelligence, and adversary behaviors to investigations and defensive recommendations.
  • Experience supporting the Department of Defense, Federal Civilian, Intelligence Community, or critical infrastructure missions.
  • Role-Specific Certifications:
    • GIAC Global Industrial Cyber Security Professional (GICSP)
    • GIAC Response and Industrial Defense (GRID)
    • GIAC Critical Infrastructure Protection (GCIP)
    • ISA/IEC 62443 Cyber Security Specialist/Expert
    • GIAC Certified Incident Handler (GCIH) or CISSP


Knowledge, Skills and Abilities:

  • OT/ICS Protocol Analysis: Demonstrated ability to dissect and analyze industrial protocol traffic (Modbus TCP/RTU, DNP3, CIP, Ethernet/IP, OPC, BACnet, PROFINET, S7comm) and identify anomalies such as unauthorized command functions or out-of-spec register writes.
  • Purdue Model & Boundary Defense: Advanced understanding of industrial network segmentation, IDMZs, jump hosts, dual-homed servers, unidirectional security gateways (data diodes), and boundary firewall rulebases separating Level 4/5 IT from Level 0-3 OT.
  • Safe Operational Response: Strict appreciation of the primacy of safety, physical reliability, and process availability over data confidentiality, understanding that standard IT containment methods (e.g., abrupt host isolation or aggressive vulnerability scanning) can cause equipment trips or physical hazards.
  • Adversary Tradecraft in ICS: Knowledge of real-world OT/ICS threat actors, destructive malware families (e.g., Industroyer/CrashOverride, TRITON/Trisis, INCONTROLLER/Pipedream), living-off-the-land techniques in engineering environments, and supply chain threats.
  • Packet & Tooling Competency: Advanced proficiency in Wireshark, tcpdump, and specialized dissectors, combined with scripting capabilities (Python, PowerShell, Bash) and query building (KQL, SPL, Lucene).
  • Interdisciplinary Collaboration: Proven ability to bridge the cultural and technical gap between cybersecurity teams and operational plant/controls engineers, translating cyber events into operational and physical consequences.


How you'll grow

At Chenega MIOS, our professional development plan focuses on helping our team members at every level of their careers to identify and use their strengths to do their best work every day. From entry-level employees to senior leaders, we believe there's always room to learn.

We offer opportunities to help sharpen skills in addition to hands-on experience in the global, fast-changing business world. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their careers.

Benefits

At Chenega MIOS, we know that great people make a great organization. We value our team members and offer them a broad range of benefits.

Learn more about what working at Chenega MIOS can mean for you.

Chenega MIOS's culture

Our positive and supportive culture encourages our team members to do their best work every day. We celebrate individuals by recognizing their uniqueness and offering them the flexibility to make daily choices that can help them be healthy, centered, confident, and aware. We offer well-being programs and continuously look for new ways to maintain a culture where we excel and lead healthy, happy lives.

Corporate citizenship

Chenega MIOS is led by a purpose to make an impact that matters. This purpose defines who we are and extends to relationships with our clients, our team members, and our communities. We believe that business has the power to inspire and transform. We focus on education, giving, skill-based volunteerism, and leadership to help drive positive social impact in our communities.

Learn more about Chenega's impact on the world.

Chenega MIOS News- https://chenegamios.com/news/

Tips from your Talent Acquisition Team

We want job seekers exploring opportunities at Chenega MIOS to feel prepared and confident. To help you with your research, we suggest you review the following links:

Chenega MIOS web site - www.chenegamios.com

Glassdoor - https://www.glassdoor.com/Overview/Working-at-Chenega-MIOS-EI_IE369514.11,23.htm

LinkedIn - https://www.linkedin.com/company/1472684/

Facebook - https://www.facebook.com/chenegamios/

#Chronos Operations, LLC
group id: 10125215

Chenega Corporation - Snapshot

job ad image
Find Chenega Corporation on Social Media
Recruiters
user avatar
About Us
Chenega figures prominently in the diverse government services contracting marketplace supporting defense, intelligence, and federal civilian customers. This business model is executed through a family of companies under four strategic business units. Chenega employs over 6,000 individuals across the U.S. and in 10 countries. We are known for our exceptional employees, fiscal strength, creativity and innovation, and for providing excellent cost and performance value to our customers and business partners. Chenega, an Alaska Native Village Corporation, works to achieve sustainable growth in our businesses to support shareholders in their journey to self-sufficiency, actively manage our lands, and uphold our cultural traditions and values. Chenega Corporation was established in 1974 pursuant to the Alaska Native Claims Settlement Act.
job ad2 image

Chenega Corporation Jobs


Clearance Level
Secret