Company Overview
Work Where it Matters
Tuvli, an Akima company, is not just another federal IT contractor. As an Alaska Native Corporation (ANC), our mission and purpose extend beyond our exciting federal projects as we support our shareholder communities in Alaska.
At Tuvli, the work you do every day makes a difference in the lives of our 15,000 Iñupiat shareholders, a group of Alaska natives from one of the most remote and harshest environments in the United States.
For our shareholders, Tuvli provides support and employment opportunities and contributes to the survival of a culture that has thrived above the Arctic Circle for more than 10,000 years.
For our government customers, Tuvli ensures that solutions are strictly aligned with agency processes and desired program outcomes while delivering the best value for technology investments.
As a Tuvli employee, you will be surrounded by a challenging, yet supportive work environment that is committed to innovation and diversity, two of our most important values. You will also have access to our comprehensive benefits and competitive pay in addition to growth opportunities and excellent retirement options.
Description
We are seeking a Cybersecurity Analyst to join our SOC. You will participate in the execution of incident detection, containment, and remediation activities across Windows, Linux, and cloud environments. This role blends hands-on technical response, threat hunting, network analysis, and cross-functional coordination to reduce risk and improve security posture.
Responsibilities
- Incident Response and Network Forensics: Triage, containment, eradication, and recovery for security incidents; perform network-based forensics.
- Detection and Monitoring: Operate and tune SIEM, EDR/XDR, and network detection tools; develop and maintain detection rules, alerts, and dashboards.
- Threat Hunting and Analysis: Proactively hunt for threats using telemetry from endpoints, network devices, cloud services, and logs; map activity to MITRE ATT&CK techniques.
- Malware Analysis: Perform static and dynamic analysis of suspicious binaries and scripts.
- Vulnerability Management: Support vulnerability scanning, prioritize findings, and coordinate remediation with engineering teams.
- Cloud and Identity Security: Investigate incidents in Azure/VMware; analyze identity and access events; support Zero Trust and IAM controls.
- Automation and Playbooks: Create and maintain incident response playbooks and SOAR workflows; automate repetitive tasks with scripting (Python, PowerShell, Bash).
- Logging and Telemetry: Analyze logs from systems and applications.
- Collaboration and Communication: Coordinate with system/network administrators, developers, and external stakeholders; prepare incident reports and brief leads.
- On-call and Emergency Response: On-call for emergencies and respond effectively under pressure to meet critical deadlines.
Qualifications
- Experience: Minimum 5 years working in Windows and Linux environments with hands-on incident response or SOC experience.
- Certifications: CCNA, GCIH, GCIA, OSCP, CEH, Security+ or equivalent.
- Cloud Certifications: AWS/Azure/Oracle security certifications or hands-on cloud security experience.
- Technical Knowledge: Strong understanding of TCP/IP, DNS, SMTP, HTTPS, and other Internet protocols.
- Security Technologies: Practical experience with SIEM, EDR/XDR, firewalls, IDS/IPS, anti-malware, vulnerability scanners, and encryption technologies.
- Network Forensics and Log Analysis: Ability to collect, parse, and interpret logs and artifacts from endpoints, servers, network devices, and cloud services.
- Threat and Exploit Knowledge: Familiarity with common exploitation techniques, software vulnerabilities (e.g., input validation flaws), and attacker tradecraft.
- Scripting and Tools: Proficiency in at least one scripting language (Python, PowerShell, Bash) and experience with forensic and analysis tools (Wireshark, Sysinternals).
- Incident Handling: Familiar with incident response lifecycle, containment/isolation techniques, evidence collection, and chain-of-custody practices.
- Communication: Excellent written and verbal communication skills; able to explain technical decisions clearly to technical and non-technical stakeholders.
- Soft Skills: Strong prioritization, organization, analytical reasoning, attention to detail, and ability to perform under stress.
- Teamwork: Proven ability to collaborate in tightly coordinated teams during emergencies and mentor junior staff.
- Security Mindset: High integrity and ability to handle confidential and sensitive information appropriately.