Bachelor's degree in cybersecurity or related field.
5+ years of experience in cybersecurity operations & incident response, with at least 3+ years in a SOC environment and 2+ years in a leadership role.
In-depth knowledge of SIEM technologies (e.g., QRadar, Splunk), EDR (e.g., CrowdStrike), IDS/IPS, and vulnerability management tools (e.g., Tenable).
Experience leading and mentoring junior analysts.
Ability to analyze and triage Indicators of Compromise (IoCs).
Knowledge of current cyber threats, trends, attack lifecycle, and various Tactics, Techniques, and Procedures (TTPs).
Industry-recognized certifications, such as CISSP, CISM, GIAC, or CEH, are preferred.
Responsibilities
Provide subject matter expertise for monitoring and managing threats and incident escalations.
Ensure all security incidents are tracked and documented appropriately.
Continuously monitor SIEM and on-premises/cloud applications for security events and threats.
Coordinate with SOC staff to conduct incident investigations and perform continuous monitoring functions.
Lead root cause analysis and post-mortem discussions after significant events to capture lessons learned.
Develop and maintain standard operating procedures (SOPs) and technical playbooks for SOC operations.
Oversee threat hunting initiatives and provide training and mentorship to SOC analysts.
Benefits
Flexible work schedule to accommodate operational needs.
Opportunity to work remotely.
Engagement in a mature 24/7 Security Operations Center environment.
Professional development through mentorship and leadership opportunities.
Full Job Description
ECS is seeking a Senior SOC Analyst/Lead to work remotely.
Position Summary
ECS is seeking a Senior SOC Analyst (SOC Lead) with demonstrated experience supporting the development of processes, procedures, and automations to rapidly ingest, aggregate, correlate, normalize, analyze event messages to absurdly identify and respond to Indicators of Compromise (IoCs). The ideal candidate is a critical thinker and perpetual learner who is excited to solve some of our clients' toughest challenges. To be successful the candidate must have experience working in a mature 24x7x365 Security Operation Center.
Shift schedule: Mon-Friday, 8AM-4PM ET (subject to change)
Responsibilities
Provides subject matter expertise for monitoring and managing threats, disseminating information, and handling, responding to, and investigating all incident escalations from the Security Operations Center.
Ensures all security incidents are tracked and documented appropriately.
Continuously monitors SIEM and on-premises infrastructure/cloud applications for security events to threats & intrusions, including:
SIEM alert queue
Phishing email inbox
Intel feeds via email and other sources (i.e., US-CERT, MS-ISAC)
Incident ticketing queue (Resilient tickets)
Ensures the SOC manager stays informed of any issues or incidents.
Coordinates with SOC staff to conduct incident/policy violation investigations, report infractions, eradicate/mitigate/remediate Indications of Compromise (IoC), and perform continuous monitoring functions.
Leads root cause analysis and post-mortem dialogue after significant events to capture lessons learned and define process or technology improvements.
Owns the successful completion of all daily operational processes and procedures.
Develops and maintains standard operating procedures (SOPs), technical playbooks and operational run books to support SOC operations and incident response activities.
Conduct follow-up meetings of escalated or noteworthy cases and modifies SOPs and playbooks based on policies, standards and best practices learned from previous cases.
Works in conjunction with SOC and infrastructure management teams to administer and manage the SOC security technologies.
Evaluates Common Vulnerabilities and Exposures (CVE) as a potential internal/external attach vector, develop recommendations to eliminate vulnerability/weakness if present.
Work closely with Cyber Threat Intel to provide information on detection patterns for new upcoming threats.
Oversees threat hunting initiatives and reviews hunt reports that are provided by SOC analysts. Provides training and mentorship to SOC analyst to improve the incident handling capabilities.
Provides guidance for all internal stakeholders for reporting and visualizations that supports SOC goals and objectives to identify and correct gaps.
Develops reports for operational activities to meet SOC and cybersecurity leadership requirements and directives.
Provides extensive knowledge of cybersecurity, incident response, digital forensic analysis and educate personnel on effective SOC searches, reporting, and visualization development.
This role involves shift work schedule to support our 24/7 operation, including weekends and holidays. Candidates must be flexible in their availability. While we make every effort to accommodate individual preferences, it's essential to understand that specific shift requests are not guaranteed and are assigned based on operational needs.
Salary Range: $135,000 - $150,000
General Description of Benefits
Bachelor's degree in cybersecurity or related field.
5+ years of experience in cybersecurity operations & incident response, with at least 3+ years in a SOC environment and 2+ years in a leadership role
Ability to interpret complex cybersecurity topics and effectively communicate or present information to various groups of stakeholders (Executives, SOC, etc.)
In-depth knowledge of SIEM technologies (i.e. QRadar, Splunk), EDR (i.e. CrowdStrike), IDS/IPS, malware analysis, and vulnerability management tools (i.e.Tenable).
Experiencing leading and mentoring junior analysts
Experience with two or more analysis tools used in a CIRT or similar investigative environment.
Ability to analyze and triage IoCs.
Proven understanding of computer and network fundamentals
Ability to perform in-depth research tasks and produce written summaries to include insights and predictions based on an analytical process.
Knowledge of current cyber threats, trends, attack lifecycle, and various Tactics, Techniques, and Procedures (TTPs)
Industry-recognized certifications, such as CISSP, CISM, GIAC, or CEH, are preferred
Excellent leadership, written and oral communication skills, and problem-solving skills
Ability to handle high-stress situations with a calm and methodical approach
About ECS
ECS is a leading provider of digital solutions and services to the federal government. The company was founded in 2001 by Roy Kapani and has since grown to become a trusted partner to a wide range of government agencies. ECS offers a broad range of services, including cloud computing, cybersecurity, and artificial intelligence. The company has been recognized for its innovative solutions and has won numerous awards, including the AWS Public Sector Partner of the Year award.