Job Title: SOC Analyst Tier 3
Place of Performance: Springfield, VA
Experience Level: 5-8 years of experience
Job Overview:We're looking for a
SOC Analyst Tier 3 and Incident Responder, a senior analyst role in the SOC. This role leads the response to confirmed security incidents, conducts threat hunting operations, and provides deep technical analysis capability in the operations center. Tier 3/IR analysts are activated for severe incidents and are the primary interface to the Tier 4 SME and external response resources when needed.
Key Responsibilities:- Provide Tier 3 escalation and resolution for the most complex incidents and outages escalating to the Tier 4 SME as needed with appropriate documentation
- Lead the response to Priority 1 and complex Priority 2 security incidents from detection through remediation
- Conduct proactive threat hunting operations to identify threats that have bypassed automated detection
- Perform advanced PCAP analysis, log analysis, memory forensics, and malware triage
- Contain and eradicate threats while coordinating with engineers for isolation and remediation
- Produce formal incident response reports for Priority 1 and Priority 2 incidents
- Develop and maintain threat hunting TTPs and playbooks
- Build new detection use cases from threat hunting findings and submit to SIEM engineer
- Serve as on-call incident responder
- Brief senior leadership during active high priority incidents
- Mentor Tier 1 and 2 analysts in investigation techniques and escalation decision-making
- Manage and own the SOC Event log for all events during the shifts
- Maintain situational awareness of the threat landscape and active campaigns
- Participate briefings and training sessions
Requirements
Required Qualifications:- 5+ years of SOC, threat hunting or incident response type experience
- Bachelor's degree in Cyber Security, Information Technology, Computer Science, Information Security, or related field. In lieu of degree, four additional years of experience in a NOC, SOC, IT security, or network engineering role
- Two of the following certifications, equivalent or better: Sec+, CYSA+, GCIH, SecX, CEH, GCIA, GSOC, CISSP
- Demonstrated hands-on incident response experience including containment, eradication, and recovery
- Proficiency with SIEM platforms and log analysis
- Proficiency with SIEM query languages - SPL, KQL, or equivalent
- Proficiency with PCAP analysis tools (Wireshark, NetworkMiner, or equivalent)
- Experience with EDR, endpoint forensics, memory analysis, and network forensics tools
- Deep understanding of attacker TTPs, kill chain methodology, and MITRE ATT&CK
- Ability to work shifts including nights, weekends, and holidays on rotating shift schedule
Preferred Qualifications- GCFA or GCFE certification or other forensic certifications
- Active Secret clearance preferred but not required
- Experience with threat hunting frameworks and platforms
- Reverse engineering experience (IDA Pro, Ghidra)
- Prior experience on a DFIR team or incident response retainer
- Experience with malware analysis (static and dynamic)
Salary Description $140k- $180k