Why CDM Smith?:
Check out this video and find out why our team loves to work here!
Join Us! CDM Smith – where amazing career journeys unfold.
Imagine a place committed to offering an unmatched employee experience. Where you work on projects that are meaningful to you. Where you play an active part in shaping your career journey. Where your co-workers are invested in you and your success. Where you are encouraged and supported to do your very best and given the tools and resources to do so. Where it’s a priority that the company takes good care of you and your family.
Our employees are the heart of our company. As an employer of choice, our goal is to provide a challenging, progressive and inclusive work environment which fosters personal leadership, career growth and development for every employee. We value passionate individuals who challenge the norm, deliver world-class solutions and bring diverse perspectives. Join our team, and together we will make a difference and change the world.
Job Description:
The Senior Cyber Operations Analyst is an experienced team member responsible for monitoring, detecting and responding to cybersecurity threats and incidents in a fast-paced environment. This role requires advanced skills in analyzing, triaging and resolving investigations and incidents. The senior analyst uses a combination of commercial and open-source tools, including AI-powered solutions, to automate repetitive tasks, enhance threat detection and improve response effectiveness. They correlate alerts and events, execute queries and apply behavior-based and anomaly detection techniques to support timely response actions. This role requires experience across multiple technologies, including SOARs, SIEMs, MCP solutions, endpoints, applications, network devices, cloud infrastructure and threat intelligence feeds. As a senior team member, the analyst also supports escalation workflows, assists less experienced analysts, and handles complex incidents.
The senior analyst is also responsible for mentoring junior team members to strengthen overall team capability. In this role, they will identify opportunities to use automation technologies & [RJ1] AI to automate repetitive tasks, enabling the team to focus on more complex analysis and response activities, which contributes to a more resilient security posture. The senior analyst operates in a cross-functional capacity, working across diverse technologies to support and secure business operations. They are expected to apply critical thinking and serve as the human in the loop when using AI-enabled tools and making security decisions. Strong communication skills are essential, along with the ability to understand and respond to emerging cybersecurity threats at scale. This role operates within an advanced cybersecurity program designed to keep pace with adversaries using both traditional and AI-enabled attack techniques. The role reports to the manager or director of security operations.
- Serve as a subject matter expert for a team of analysts supporting managed 24/7/365 monitoring and response operations.
- Investigate and respond to cybersecurity incidents, including participating in off-hours and on-call rotations.
- Act as an escalation point for day-to-day SOC operations and identify opportunities to automate.
- Assess program strengths and weaknesses and recommend AI solutions to improve team skills and knowledge.
- Stay current on emerging cybersecurity threats, AI developments, risks and vulnerabilities that may impact services.
- Automate repetitive tasks within SOAR environments using Cloud technologies, ML and AI to improve efficiency.
- Develop detection capabilities aligned with the MITRE ATT&CK framework and enhance them using automation/AI.
- Validate alerts by interpreting confidence scores, risk ratings and recommended actions.
- Use NLP tools to analyze events alongside threat intelligence data.
- Improve AI model performance and alert tuning by labeling events and validating true and false positives.
- Use multiple-agent collaboration using MCP solutions within security workflows.
- Collaborate with data science and engineering teams to improve AI models used in SOC operations.
- Refine playbooks, policies, procedures and guidelines in alignment with industry best practices and AI capabilities.
- Partner with security engineering, incident response and IT teams to improve monitoring, workflows and response processes.
- Support the development and tracking of metrics, KPIs and service-level objectives for security events.
- Participate in tabletop exercises to identify gaps, improve skills and strengthen communication.
- Review reports from tabletop exercises, vulnerability assessments and penetration tests to drive improvements.
- Evaluate logging coverage to identify potential gaps in detection capabilities.
- Examine log data across endpoints, databases, applications, identity systems, networks, mobile platforms and cloud environments.
- Recommend adjustments to security tools to reduce false positives.
- Provide guidance on monitoring, logging, identity, data protection and detection strategies, including preventive controls.
- Report on SOC performance and posture to cybersecurity leaders and stakeholders as needed.
#LI-LP1
#LI-REMOTE
Skills & Abilities:
- Experience in SOC monitoring and response or related experience.
- Working knowledge of ML and AI, as well as their application in security operations.
- Experience using NLP, query construction and AI-powered tools to analyze logs, threat intelligence and incident data.
- Experience using MCP servers and purpose-built agents to support investigation and response activities.
- Hands-on experience with AI assistants and platforms for investigation, security analysis and response.
- Demonstrated technical understanding of emerging cybersecurity threats, including adversary use of AI.
- Ability to develop detections aligned with the MITRE ATT&CK framework and relevant open-source AI frameworks.
- Proficient in scripting languages such as Python, Bash, JavaScript or PowerShell, as well as experience with KQL.
- Experience with SOAR, SIEM, threat intelligence platforms, identity systems, sandboxes, vulnerability management and EDR/XDR tools.
- Strong understanding of threats, vulnerabilities, and incident response principles.
- Familiar with one or more frameworks or regulations, such as CMMC, NIST CSF, CIS, GDPR, CCPA.
- Strong judgment and ability to make timely decisions in complex situations.
- Experience with Azure, AWS, and GCP. Bonus points for Gov Cloud deployments
- Experience managing/collaborating with MSSPs
- Exceptional written and verbal communication skills across multiple levels of the organization.
- Excellent written and verbal communication skills, with the ability to clearly communicate cybersecurity incidents and document post-incident reviews and root cause analyses.
- Strong analytical and problem-solving skills, with the ability to evaluate complex issues and recommend practical solutions.
- Highly organized and efficient, with the ability to manage multiple priorities and meet deadlines in a fast-paced environment.
- Ability to apply both strategic and tactical thinking to support effective security operations and continuous improvement.
- Ability to remain calm and focused under pressure while managing time-sensitive priorities and deadlines.
- Effective decision-making skills in complex and time-sensitive situations.
Qualifications:
- Bachelor's degree.
- 6 years of related experience.
- Equivalent additional directly related experience will be considered in lieu of a college degree.
Domestic and/or international travel may be required. The frequency of travel is contingent on specific duties, responsibilities, and the essential functions of the position, which may vary depending on workload and project demands.
Preferred Qualifications:
- One or more GIAC certifications: GCED, GCIH, GDAT, Microsoft Security Operations Analyst Associate
- Experience managing security information and event management (SIEM) systems, threat intelligence platforms, security automation and orchestration solutions, intrusion detection and prevention systems (IDS/IPS), file integrity monitoring (FIM), data loss prevention (DLP) and other network and system monitoring tools.
- Experience in investigations using formal chain-of-custody methods, forensic tools and best practices.
Amount of Travel Required:
No Travel is required
EEO Statement:
We attract the best people in the industry, supporting their efforts to learn and grow. We strive to create a challenging and progressive work environment. We provide career opportunities that span a variety of disciplines and geographic locations, with projects that our employees plan, design, build and operate as diverse as the needs of our clients. CDM Smith Inc. and its divisions and subsidiaries are an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, pregnancy related conditions, childbirth and related medical conditions, sexual orientation, gender identity or gender expression), national origin, age, marital status, physical or mental disability, veteran status, citizenship status, genetic information or any other characteristic protected by applicable law.
Background Check and Drug Testing Information:
CDM Smith Inc. and its divisions and subsidiaries (hereafter collectively referred to as “CDM Smith”) reserves the right to require background checks including criminal, employment, education, licensure, etc. as well as credit and motor vehicle when applicable for certain positions. In addition, CDM Smith may conduct drug testing for designated positions. Background checks are conducted after an offer of employment has been made in the United States. The timing of when background checks will be conducted on candidates for positions outside the United States will vary based on country statutory law but in no case, will the background check precede an interview. CDM Smith will conduct interviews of qualified individuals prior to requesting a criminal background check, and no job application submitted prior to such interview shall inquire into an applicant's criminal history. If this position is subject to a background check for any convictions related to its responsibilities and requirements, employment will be contingent upon successful completion of a background investigation including criminal history. Criminal history will not automatically disqualify a candidate. In addition, during employment individuals may be required by CDM Smith or a CDM Smith client to successfully complete additional background checks, including motor vehicle record as well as drug testing.
Massachusetts Applicants:
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Additional Compensation :
All bonuses at CDM Smith are discretionary and may or may not apply to this position.
Pay Range Min:
USD $102,170.00
Pay Range Max:
USD $178,776.00
Visa Sponsorship Available :
No-We will not support sponsorship in the United States, i.e. H-1B or TN Visas for this position