OT / ICS SOC Analyst
Chenega Corporation
Job Description
Job Description
Overview
OT/ICS SOC Analyst
Huntsville, Alabama
Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employer’s core culture? If so, Chenega Military, Intelligence & Operations Support (MIOS) could be the place for you! Join our team of professionals who support large-scale government operations by leveraging cutting-edge technology and take your career to the next level!
Chronos Operations (CO) is a wholly-owned subsidiary of Chenega Corporation, an Alaska Native Corporation based in Anchorage, AK. Belonging to the Military, Intelligence, and Operations Support (MIOS) Strategic Business Unit (SBU), Chronos has a culture rooted in integrity, respect, and exceptional performance. Chronos is headquartered in Colorado Springs, CO, and provides mission-critical services in Advanced Analytics & AI, Software Engineering, Cybersecurity, Information Technology, and Intelligence.
We deliver essential cyber services to our customers in support of their missions to sustain the national security and economic interests of our nation.
The OT / ICS SOC Analyst performs advanced monitoring, threat hunting, anomaly investigation, incident response coordination, and threat analysis across converged IT/OT environments, Industrial Control Systems (ICS), Supervisory Control and Data Acquisition (SCADA) platforms, Distributed Control Systems (DCS), and mission support networks.
Operating with increased autonomy within established operational authorities and rules of engagement, the analyst correlates telemetry across the Purdue Model (Levels 1–3+), evaluates physical process anomalies alongside digital indicators, ensures response measures prioritize personnel safety and process reliability, and continuously improves OT-specific detection mechanisms, playbooks, and defensive readiness.
Responsibilities
- Monitor and analyze security telemetry across network, endpoint, identity, cloud, application, email, and other enterprise sources using approved SIEM, XDR, NDR, and security analytics platforms.
- Investigate escalated or complex cybersecurity events to determine validity, scope, affected assets and identities, potential mission impact, and required response actions.
- Correlate alerts with asset criticality, vulnerability information, threat intelligence, user behavior, and historical activity to develop evidence-based analytical conclusions.
- Lead or perform incident triage and analysis; collect, preserve, and document relevant evidence in accordance with established procedures and evidence-handling requirements.
- Execute authorized containment and response actions, including host isolation, account restriction, indicator blocking, or other approved measures, and coordinate eradication and recovery activities with responsible stakeholders.
- Develop clear incident records, analytical findings, timelines, and technical reports; communicate status, risk, and recommended actions to SOC leadership and mission stakeholders.
- Apply threat intelligence, indicators of compromise, adversary tactics, techniques, and procedures, and frameworks such as MITRE ATT&CK to identify related activity and support defensive recommendations.
- Review and validate findings, recommendations, and summaries generated by automated analytics, machine learning, or AI-enabled cybersecurity capabilities before operational use.
- Tune alerts and detection logic, recommend telemetry improvements, and help reduce false positives, coverage gaps, and analyst workload in coordination with detection engineering or platform owners.
- Develop, test, maintain, and improve incident response playbooks, standard operating procedures, queries, dashboards, and repeatable analytical workflows.
- Participate in or facilitate post-incident reviews and lessons-learned activities; translate findings into corrective actions and measurable operational improvements.
- Mentor SOC Analyst I personnel, provide quality reviews of escalated cases, and share technical knowledge across shifts and teams.
- Support cyber exercises, readiness assessments, recovery validation, and continuous improvement activities as directed by the SOC Lead.
- Perform additional duties as assigned.
Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Information Technology, Software Engineering, Data Science, or a related field and 3+ years of relevant experience.
- Or applicants may meet one of the following substitutions:
- Associate's degree and 5+ years of relevant experience.
- High school diploma or GED equivalent and 7+ years of relevant experience.
- Relevant experience must include cybersecurity operations, security monitoring, network defense, incident response, threat analysis, system administration, or a closely related information technology discipline. At least 2+ years must involve SOC, cyber defense, or incident response functions.
- Active DOD IAT Level II Certification or higher is required.
- Active Secret clearance with the ability to obtain and maintain TS/SCI eligibility.
Preferred Qualifications:
- Active TS/SCI clearance.
- 5+ or more years of relevant cybersecurity experience, including 2+ or more years in a SOC, cyber defense, or incident response environment.
- Experience investigating endpoint, network, identity, cloud, email, or application security events using SIEM, EDR/XDR, NDR, SOAR, vulnerability management, or threat intelligence platforms.
- OT/ICS Security Tooling: Hands-on operational experience with leading OT security and asset inventory platforms such as Dragos Platform, Claroty Continuous Threat Detection (CTD), Nozomi Networks Guardian, Tenable OT (Indegy), or ForeScout eyeInspect.
- Working familiarity with programmable logic controllers (PLCs), remote terminal units (RTUs), human-machine interfaces (HMIs), distributed control systems (DCS), and safety instrumented systems (SIS) manufactured by vendors such as Rockwell Automation/Allen-Bradley, Siemens, Schneider Electric, Emerson, or GE.
- Experience developing or tuning detection logic, analytical queries, dashboards, automation, or incident response playbooks.
- Experience applying MITRE ATT&CK, threat intelligence, and adversary behaviors to investigations and defensive recommendations.
- Experience supporting the Department of Defense, Federal Civilian, Intelligence Community, or critical infrastructure missions.
- Role-Specific Certifications:
- GIAC Global Industrial Cyber Security Professional (GICSP)
- GIAC Response and Industrial Defense (GRID)
- GIAC Critical Infrastructure Protection (GCIP)
- ISA/IEC 62443 Cyber Security Specialist/Expert
- GIAC Certified Incident Handler (GCIH) or CISSP
Knowledge, Skills and Abilities:
- OT/ICS Protocol Analysis: Demonstrated ability to dissect and analyze industrial protocol traffic (Modbus TCP/RTU, DNP3, CIP, Ethernet/IP, OPC, BACnet, PROFINET, S7comm) and identify anomalies such as unauthorized command functions or out-of-spec register writes.
- Purdue Model & Boundary Defense: Advanced understanding of industrial network segmentation, IDMZs, jump hosts, dual-homed servers, unidirectional security gateways (data diodes), and boundary firewall rulebases separating Level 4/5 IT from Level 0–3 OT.
- Safe Operational Response: Strict appreciation of the primacy of safety, physical reliability, and process availability over data confidentiality, understanding that standard IT containment methods (e.g., abrupt host isolation or aggressive vulnerability scanning) can cause equipment trips or physical hazards.
- Adversary Tradecraft in ICS: Knowledge of real-world OT/ICS threat actors, destructive malware families (e.g., Industroyer/CrashOverride, TRITON/Trisis, INCONTROLLER/Pipedream), living-off-the-land techniques in engineering environments, and supply chain threats.
- Packet & Tooling Competency: Advanced proficiency in Wireshark, tcpdump, and specialized dissectors, combined with scripting capabilities (Python, PowerShell, Bash) and query building (KQL, SPL, Lucene).
- Interdisciplinary Collaboration: Proven ability to bridge the cultural and technical gap between cybersecurity teams and operational plant/controls engineers, translating cyber events into operational and physical consequences.
How you’ll grow
At Chenega MIOS, our professional development plan focuses on helping our team members at every level of their careers to identify and use their strengths to do their best work every day. From entry-level employees to senior leaders, we believe there’s always room to learn.
We offer opportunities to help sharpen skills in addition to hands-on experience in the global, fast-changing business world. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their careers.
Benefits
At Chenega MIOS, we know that great people make a great organization. We value our team members and offer them a broad range of benefits.
Learn more about what working at Chenega MIOS can mean for you.
Chenega MIOS’s culture
Our positive and supportive culture encourages our team members to do their best work every day. We celebrate individuals by recognizing their uniqueness and offering them the flexibility to make daily choices that can help them be healthy, centered, confident, and aware. We offer well-being programs and continuously look for new ways to maintain a culture where we excel and lead healthy, happy lives.
Corporate citizenship
Chenega MIOS is led by a purpose to make an impact that matters. This purpose defines who we are and extends to relationships with our clients, our team members, and our communities. We believe that business has the power to inspire and transform. We focus on education, giving, skill-based volunteerism, and leadership to help drive positive social impact in our communities.
Learn more about Chenega’s impact on the world.
Chenega MIOS News-
Tips from your Talent Acquisition Team
We want job seekers exploring opportunities at Chenega MIOS to feel prepared and confident. To help you with your research, we suggest you review the following links:
Chenega MIOS web site -
Glassdoor - -at-Chenega-MIOS- EI_IE369514.11,23.htm
LinkedIn -
Facebook -
#Chronos Operations, LLC
- Kforce has a client in Huntsville, AL that is seeking a SOC Watchfloor Analyst - Cybersecurity Analyst for a long-term contract role. This company offers excellent growth potential within a mission-critical federal program. Overview: We are seeking a Mid-Level Cybersecurity...SuggestedLong term contractTemporary work
- ...network sensor dataValidate threats, document findings, and report risk to mission stakeholders in a timely mannerExecute established SOC playbooks and support root cause analysis, threat hunting, and development of indicators of compromise (IOCs)Contribute to detection...SuggestedLocal area
- ...and endpoint scan diagnostics for senior analyst review. Document daily scanning and tracking... ...IT helpdesk, system administration, or SOC experience. ~ Familiarity with DISA... ...and SCAP compliance validation tools. ~ OT/ICS Experience: Familiarity with Industrial...SuggestedWork at officeNight shiftWeekend work
- ...Engineer III to support the our Client's Operational Technology (OT) Monitoring program. In this role, you will help monitor security... ...security events across AMC networks, systems, and mission data using SOC platforms and network security toolsTriaging alerts, validating...SuggestedLocal area
- ...Job Description Job Description Job Title: SOC Operations Analyst Location: Huntsville, Virginia Type: Direct Hire Compensation: Work Model: Onsite – onsite Hours: 40.0 Security Clearance: Top Secret with the ability to sit for the CI Poly Responsibilities...SuggestedLocal area
- ...mediocrity. Strive for excellence and consider joining our growing team today! JOB OVERVIEW MartinFed has an opening for a Junior SOC Analyst to join our team of talented and diverse individuals supporting the NASA Security Operations Center (SOC). The Triage Analyst...Local areaShift workNight shiftRotating shiftDay shiftAfternoon shift
- ...Senior Operations Research AnalystLocation: Redstone Arsenal Position Type: Full-TimeCandidate will serve as the Sr Operations Research Analyst to an Army Product Office responsible for the development and defense of cost estimates to support acquisition decision-making....Work experience placementRelocationFlexible hours
- ...excitement of being on a team that wins. Job Description Position Summary Teledyne Brown Engineering is hiring an Operations Research (OR) Analyst to join our Medical Modeling, Simulation, and Analysis team in support of the Naval Health Research Center (NHRC). The OR Analyst...Work experience placementLocal area
- ...Senior Operations Research Analyst OASYS, INC. , a Leading-Edge Government contractor in Huntsville Alabama, is seeking applicants for a Senior Operations Research Analyst position supporting our US Army customer. Job Responsibilities include: The Senior Operations...Temporary workFor contractorsWork experience placementWork at officeFlexible hours
- ...risks, exposure, framework, and compliance levels ● Advise on risk mitigation and remediation plans Required Qualifications ● SOC (Security Operations Center) knowledge and understanding of services within ● 2 or more (2+) years of experience in the...For contractorsWork at office
- Job TitleMid All Source Analyst - CI/HUMINTLocationHuntsville, AL 35649 US (Primary)CategoryIntelligenceJob TypeFull-TimeCareer LevelStaffEducationBachelor... ...and coordinating CI and HUMINT-focused analysis with other IC analysts, and providing J2X administrative support.Analyzes...Contract work
$110k - $135k
Check out this new opportunity!Joint Systems Data Analyst (IAMD)Full-Time with an Employee Owned and Best Places to Work ContractorOnsite at Redstone Arsenal | Salary Range: $110,000-$135,000Seeking an experienced Data Analyst or Systems Engineer to support advanced DoD...Full time- ...for a career with purpose — and help shape the future.Department Summary:This is an opportunity for a motivated Operations Research Analyst to join MITRE’s Operations Analysis department. We are a large group of over 60 operations research professionals, including over 2...Work experience placementLocal areaRemote work
- DCS is seeking a skilled Configuration Management/Data Management (CMDM) Analyst to support a fast-paced Army product management office in Huntsville, AL. In this role you will develop systems engineering documents, processes, and procedures, perform configuration management...Full timeFor contractorsWork at office
- INTUITIVE is a nationally recognized Best Place to Work that provides solutions from design through production to sustainment by delivering targeted results. Our approach couples the latest technology with engineering expertise and analytical proficiency while remaining...Full timeContract workStart working todayWork at office
- ...Job Description Job Description Operational Research/System Analyst responsible for providing quantitative and qualitative analysis in support of U.S. Army strategic sustainment operations, with a focus on war plans. Support military decision making processes by...
- Job TitleData Analyst - MidLocationHuntsville, AL 35808 US (Primary)CategoryInformation TechnologyJob TypeFull-timeCareer LevelStaffEducationBachelor's DegreeTravelNoneSecurity Clearance RequiredTSJob DescriptionTMC Technologies is in search of a mid-level Data Analyst...Contract workLocal area
- deciBel Research has an immediate opening for a Radar Data Analyst in Huntsville, AL.Position Description:deciBel Research is seeking an experienced Radar Data Analyst or Systems Engineer to perform analyst functions including information gathering, data modeling, project...Immediate start
$61.9k - $141k
Data Analyst, MidThe Opportunity:As data analyst, you love diving into data and turning it into meaningful insights. With the abundance of structured and unstructured data, you understand the importance of transforming complex data sets into useful information to solve...Full timeContract workPart timeWork at officeLocal areaRemote work- Modern Technology Solutions, Inc. (MTSI) is seeking an analyst to support verification, validation, and accreditation (VV&A) activities associated with Missile Defense System (MDS) modeling and simulation (M&S).Roles and ResponsibilitiesThe candidate will be supporting...
- deciBel Research has an immediate opening for a Radar Data Analyst in Huntsville, AL.Position Description:deciBel Research is seeking an experienced Radar Data Analyst to join a collaborative analysis team supporting the evaluation of Ground Test and Flight Test sensor...Immediate start
$61.9k - $141k
Security Operations Analyst, MidThe Opportunity:Respond to and resolve cybersecurity incidents and proactively prevent the reoccurrence... ...standards for incident response actions and best practices for SOC operationsKnowledge of security operation tools, including SIMs...Full timeContract workPart timeLocal areaRemote work- Modern Technology Solutions, Inc. (MTSI) is seeking a Radar Analyst to support verification, validation, and accreditation (VV&A) activities associated with Missile Defense System (MDS) modeling and simulation (M&S). The candidate will be supporting MDA/SEQV Systems Verification...
- ...Overview Cyber Data Analyst Huntsville, AL Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employer's core culture? If so, Chenega...Night shiftWeekend work
- Job Family:Research and Analysis ConsultingTravel Required:Up to 10%Clearance Required:Active SecretWhat You Will Do:Provide senior-level analytical, research, and executive-decision-support products for senior leaders in client organizationDevelop executive materials such...Full timeContract workFor contractorsFlexible hours
- ...Job Description Mid-Level Operations Research/ Strategic Systems Analyst Location: Huntsville, AL | Onsite Clearance Required:... ...techniques, data mining, modeling and simulation, and military/IC judgment to operational and planning problems. What You Bring...Full timeContract workLocal area
$127k - $150k
Position Summary Healthcare Data Engineer Sr. Consultant Deloitte Consulting's technology professionals help clients identify and solve their most critical information and technological challenges. We provide advisory through end-to-end implementation services as...Local areaVisa sponsorship- ...Job Title: Senior Data Analyst (Defense Sector) Location: Huntsville, AL Security Clearance: Active Secret (Required) Travel: Up to 10% A leading global consultancy and premier federal partner is looking to expand their high-impact data science team in Huntsville...
- ...Degree; FOUR (4) years of additional professional experience in lieu of Bachelor'sMinimum ONE (1) year of experience working as a data analyst, business analyst, or in a similar role supporting reporting and analytics.Proficiency with Microsoft Excel and experience working...Full timeFlexible hours
$115k - $140k
SMX is currently seeking a Senior Intellectual Property / Data Rights Analyst with practical knowledge, technical depth and strong operational experience to perform intellectual property analytical work in a Government weapon system project office in Huntsville, AL. The...Contract workWork experience placementH1bWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to OT / ICS SOC Analyst. Be the first to apply!
- police crime analyst Huntsville, AL
- agriculture analyst Huntsville, AL
- law enforcement response team analyst Huntsville, AL
- audit analyst Huntsville, AL
- manufacturing analyst Huntsville, AL
- investigative analyst Huntsville, AL
- mental health analyst Huntsville, AL
- asap analyst Huntsville, AL
- local content analyst Huntsville, AL
- petroleum analyst Huntsville, AL



