ECS

SOC Analyst

ECS$70K — $95K *
US-AnywhereRemote in Virginia, US
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-5 years of experience in cybersecurity, ideally in security operations or incident response.
  • Hands-on experience with monitoring security alerts and investigating suspicious activities using security tools.
  • Strong analytical skills to assess logs, alerts, and telemetry data for malicious activity.
  • Proficiency in using enterprise security platforms such as SIEM and endpoint detection systems.
  • Familiarity with incident response processes and threat detection methodologies.
  • Knowledge of cybersecurity frameworks such as NIST or CIS controls.
  • Experience documenting investigations in case management systems.

Responsibilities

  • Monitor security alerts and telemetry to identify potential threats.
  • Investigate legitimacy and impact of security alerts on systems.
  • Identify indicators of compromise and malicious behavior.
  • Support incident response during cybersecurity incidents.
  • Analyze security telemetry and logs to understand attacker tactics.
  • Contribute to improving detection rules based on investigative findings.
  • Engage in proactive threat hunting to uncover undetected adversary behavior.
  • Review escalated alerts from the MSSP for further investigation.
  • Document findings and response actions in the SOC case management platform.
  • Implement improvements for operational effectiveness and automation in SOC processes.

Benefits

  • Opportunities for professional development and continuous learning.
  • Access to comprehensive security training and certifications.
  • Collaborative work environment with a focus on team-based investigations.
  • Participation in cutting-edge detection engineering projects.
  • On-call support for incident response with clear protocols and guidance.
Full Job Description
The SOC Analyst is responsible for enterprise security monitoring, alert investigation, and incident response activities within the Everforth Security Operations Center (SOC). This role supports the continuous monitoring of enterprise systems and security telemetry to identify potential threats and suspicious activity. SOC Analysts perform investigative analysis of security alerts, participate in incident response activities, and contribute to detection engineering efforts that improve the organization's ability to detect malicious activity.

This role reports to the SOC Manager and works closely with Senior SOC Analysts, the Security Engineering team, enterprise IT operations teams, and the MSSP to ensure effective monitoring, investigation, and response across the enterprise environment.

Responsibilities
  • Security Monitoring: Monitor enterprise security telemetry and alerts generated by security platforms to identify potential threats or suspicious activity.
  • Alert Investigation: Conduct investigations of security alerts to determine legitimacy, scope, and potential impact to enterprise systems.
  • Incident Detection: Identify indicators of compromise, malicious behavior, and suspicious activity within enterprise environments.
  • Incident Response Support: Support investigation and response activities during confirmed or suspected cybersecurity incidents.
  • Threat Analysis: Analyze security telemetry, logs, and alerts to determine attacker behavior, indicators of compromise, and potential attack vectors.
  • Detection Engineering Support: Contribute to the development and refinement of detection rules and monitoring analytics based on investigation findings.
  • Threat Hunting: Participate in proactive threat hunting activities to identify adversary behavior that may not be detected through automated monitoring.
  • MSSP Escalation Review: Review and investigate alerts escalated by the MSSP after-hours monitoring team.
  • Investigation Documentation: Document investigations, findings, and response actions within the SOC case management platform.
  • Operational Effectiveness: Contributes to SOC process improvements by supporting automation efforts, implementing AI-assisted workflows, identifying efficiency opportunities, and helping enhance detection and response operations.
  • Playbook Execution: Execute SOC operational playbooks and investigation procedures during alert triage and incident response.
  • Operational Collaboration: Work closely with IT operations, infrastructure teams, and security engineering to support investigation and remediation activities.
  • Continuous Improvement: Identify opportunities to improve monitoring coverage, investigation processes, and detection capabilities.
  • On-Call Support: Participates in on-call support to assist with security incident response, operational issues, and investigation activities to maintain continuous SOC coverage and response capability.


    • Experience: Minimum of 3-5 years of cybersecurity experience, with experience in security operations, threat monitoring, or incident response environments.
    • Security Monitoring Experience: Experience monitoring security alerts and investigating suspicious activity using enterprise security tools.
    • Investigation Skills: Ability to analyze security alerts, logs, and telemetry to determine potential malicious activity.
    • Security Technology Experience: Experience working with enterprise security tools such as SIEM platforms, endpoint detection and response (EDR), and log analysis tools.
    • Log Analysis Knowledge: Experience reviewing system logs, authentication activity, endpoint telemetry, and network security events.
    • Incident Investigation Awareness: Understanding of basic incident response processes and investigation workflows.
    • Threat Detection Awareness: Familiarity with common attacker techniques and indicators of compromise.
    • Security Framework Awareness: Familiarity with cybersecurity frameworks such as NIST Cybersecurity Framework or CIS Critical Security Controls.
    • Investigation Documentation: Experience documenting investigations and response actions in case management platforms.

    Other Requirements of the position include:
    • Able and willing to obtain a US Security Clearance.
    • This role may require occasional on-call support during off-hours to respond to security incidents.

About ECS

ECS is a leading provider of digital solutions and services to the federal government. The company was founded in 2001 by Roy Kapani and has since grown to become a trusted partner to a wide range of government agencies. ECS offers a broad range of services, including cloud computing, cybersecurity, and artificial intelligence. The company has been recognized for its innovative solutions and has won numerous awards, including the AWS Public Sector Partner of the Year award.
Learn more about ECS
Size
2,000 employees
Industry

Similar Jobs

More Jobs at ECS

  • ECS
    SOC Analyst
    $70K — $95K *
    Remote
    Information Technology
    Remote in Virginia, US
  • ECS
    Full Stack Developer
    $120K — $165K *
    Remote
    Information Technology
    Remote
  • ECS
    Senior Elastic Engineer
    $140K — $180K *
    Remote
    Healthcare
    Remote in Virginia, US
  • ECS
    Business Analyst
    $120K — $140K *
    Arlington, VA 22204 (Arlington County)
    Business Services
    In-Person
  • ECS
    Agile Program Manager
    $130K — $150K *
    Orlando, FL 32828 (Orange County)
    Education, Government & Non-Profit
    In-Person

More Information Technology Jobs

Find similar SOC Analyst jobs: