1-3 years in a SOC, cybersecurity 'blue team', or closely related role. Strong grasp of TCP/IP, OSI model, and common protocols (HTTP, DNS, SMTP). Windows/Linux/macOS fundamentals. Active Directory/Azure AD concepts. Basic cloud logging. Experience with at least one SIEM and one EDR/XDR platform. Experience with ticketing/case management. Ability to craft queries using common languages; comfort with regex, JSON and APIs. Basic scripting in Python/PowerShell/Bash. Excellent analytical, problem-solving, and communication skills. Ability to operate under pressure in a shift or on-call environment. Experience in system and network administration. Ability to work collaboratively. Considerable knowledge/experience of assessing security controls. Experience and skill in conducting audits or reviews of technical systems. Experience working in a government environment. Experience working in a distributed IT environment. Ability to qualify for HSPD-12 card. Able to work both independently and as a contributing member of a small technical team. Able to disseminate knowledge to current staff.