SOC Analyst

Valiant Solutions, LLC

• $100K — $120K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years in Security Operations Center roles (Tier II or III).
  • Certification: GCIH, GCIA, CEH, or Security+.
  • Hands-on SIEM platforms and endpoint telemetry experience.
  • Strong knowledge of Windows, Linux internals, and network protocols.
  • Experience with AWS telemetry tools (CloudTrail, GuardDuty, etc.).
  • Ability to lead shifts and ensure effective handovers.
  • Excellent written and verbal communication skills.

Responsibilities

  • Perform Tier III SIEM alert triage and forensic analysis.
  • Act as the escalation point for high-severity events from lower tiers.
  • Maintain situational awareness of SOC tools and alert coverage.
  • Lead shift handovers with comprehensive incident updates.
  • Update SOC standard operating procedures and playbooks regularly.
  • Support Red and Purple Team exercises to enhance detection capabilities.
  • Develop and test custom detection rules working with partner SOCs.

Benefits

  • 99% coverage of Medical, Dental, and Vision for employees.
  • 25% contribution to family health coverage.
  • 100% paid Short Term Disability and Life Insurance for employees.
  • Full reimbursement for certifications.
  • 401K matching up to 4%.
  • Generous Paid Time Off and paid federal holidays.
  • Access to wellness programs and an online training portal.
Full Job Description
Position Description

The SOC Analyst is the senior Tier III analyst on the Security Operations Center floor, providing advanced triage, forensic analysis, and escalation for SIEM alerts and incidents that exceed Tier I and Tier II capability. The analyst is the escalation point for the shift, maintains situational awareness of SOC tools and telemetry, drives shift handovers so incoming analysts inherit full context, and contributes to standard operating procedure and playbook updates that keep detection and response current. The role also supports Red Team and Purple Team exercises, using those engagements to test and improve detection coverage.

Location: The SOC Analyst can expect 100% telework. Remote work requires a high level of trust in our employees, and we strictly adhere to the details outlined in our Remote Work Policy below.

Eligibility Requirements: U.S. Citizenship is required due to federal contract obligations, along with the ability to successfully pass a federal background investigation

Required Experience:
  • Six or more years of Security Operations Center experience, with demonstrated time in a Tier II or Tier III analyst role.
  • At least one of the following certifications: GCIH, GCIA, CEH, or Security+.
  • Hands-on experience with SIEM platforms and endpoint telemetry, including alert tuning, correlation rule review, and use of EDR agents for investigation.
  • Working knowledge of operating systems (Windows and Linux internals, event and audit logs, process and memory artifacts) and networking (TCP/IP, DNS, HTTP/S, common protocols, packet capture analysis).
  • Experience with AWS native capabilities and telemetry, including CloudTrail, GuardDuty, VPC Flow Logs, and CloudWatch, in a monitoring or investigation context.
  • Ability to lead a shift and drive handover discipline across analyst tiers.
  • Strong written and verbal communication skills, including the ability to write clear incident write-ups and shift handover notes.
  • Required to obtain and maintain a Non-Sensitive / High Risk (Public Trust) security clearance, Tier 4/6c.


Preferred Qualifications:
  • Additional certifications such as GCFA, GCFE, GNFA, or GREM.
  • Experience with malware reverse engineering, memory forensics, and network forensics.
  • Familiarity with MITRE ATT&CK and the ability to map alerts and hunt findings to ATT&CK techniques.
  • Working knowledge of NIST SP 800-61 Rev. 2, NIST SP 800-86, and NIST SP 800-137.
  • Experience with SOAR platforms and playbook automation.
  • Familiarity with AWS GovCloud and hybrid cloud detection patterns.


Responsibilities:
  • Provide Tier III support for SIEM alert triage, in-depth forensic analysis, and escalation, including malware reverse engineering, memory forensics, and campaign correlation across the SOC and partner SOC environments.
  • Serve as the shift escalation point for complex or high-severity events raised by Tier I and Tier II analysts, and analyze them within 4 hours per contract SLA.
  • Maintain situational awareness of SOC tools and telemetry, including SIEM, SOAR, EDR, NDR, and CDM data flows, and alert the SOC Manager when tool health or coverage gaps put detection at risk.
  • Lead shift handovers, providing incoming analysts with a written and verbal summary of open incidents, active hunts, tuning changes, and outstanding follow-up items.
  • Contribute to SOC standard operating procedure and playbook updates, with revisions reviewed at least semi-annually and refreshed sooner when new threats, tools, or gaps require it; major changes are reviewed by the Change Control Board.
  • Support Red Team and Purple Team exercises by validating detection coverage during engagement, translating adversary tradecraft into new detection rules, and feeding lessons learned back into playbooks.
  • Support the development and testing of custom detection rules and collaborate with the customer OCIO, OIG, and partner SOCs to strengthen strategic threat awareness.
  • Contribute to monthly threat actor profiles and update detection signatures accordingly.
  • Submit initial incident reports within one hour of confirmation and support delivery of final incident reports within 72 hours, including impact, timeline, and remediation.
  • Participate in post-incident lessons-learned sessions and translate findings into playbooks, runbooks, and detection improvements.
  • Mentor Tier I and Tier II analysts on triage technique, log analysis, and escalation quality.


Benefits Snapshot (includes, but not limited to)
Valiant pays 99% of the Medical, Dental, and Vision Coverage for Full-time Employees
Valiant contributes 25% towards Health Coverage for Family and Dependents
100% Paid Short Term Disability and Life Insurance Policy for Full-time Employees
100% Paid Certifications
401K Matching up to 4%
Paid Time Off
Paid Federal Holidays
Wellness & Fitness Program
Valiant University - Online Education and Training Portal
FSA programs for: Medical Costs, Dependent Care, Transit, and Parking
Referral Bonuses

Remote Work Policy

Remote work necessitates a high level of trust in our employees. To ensure that employee performance does not suffer in a remote work environment, all employees who telecommute are expected to have a quiet and distraction-free workspace with adequate internet, dedicate their full attention and availability to their job duties during working hours, and maintain a schedule during core business hours that align with those of their coworkers and Valiant's clients. In alignment with Valiant's inclusive and engaging environment, cameras are encouraged and can be required to be on during virtual video conferences. Additionally, in alignment with the Office of the Inspector General's effort to eliminate conflicting employment, all Valiant employees are required to disclose any current or future outside employment engagements. During onboarding and throughout employment, employees must disclose any current activities or intent to engage in outside employment or other professional activities and obtain written approval. Employees may not solicit or conduct any outside business during core business hours for Valiant Solutions and our clients.

Physical Demands

Sitting or standing at a desk for prolonged periods of time and consistent operation of a computer. Frequent communication and exchanging of accurate information via electronic communication, phones, and in person. Occasionally lift and/or move moderate amounts of weight, typically less than 20 pounds. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the job.

Authorization to Share Resume and Personal Information

By submitting your resume for this position, you authorize Valiant Solutions to share your resume, as well as, personal information included on the resume, with its subsidiaries, affiliates and teaming partners for the purpose of considering you for this position and other available positions requiring comparable skills, education and experience. Should Valiant Solutions or its affiliates and teaming partners wish to initiate pre-employment discussions, you will be asked to complete an employment application and related employment documents.

#LI-JM1

Similar Jobs

More Jobs at Valiant Solutions, LLC

  • SOC Analyst
    $100K — $120K *
    Washington, DC 20011 (District Of Columbia County)
    Information Technology
    In-Person
  • Cloud Network Engineer
    $137K — $142K *
    Silver Spring, MD 20906 (Montgomery County)
    Education, Government & Non-Profit
    Hybrid
  • Network Operations (Junior)
    $82K — $87K *
    Silver Spring, MD 20906 (Montgomery County)
    Information Technology
    Hybrid
  • Network Operations
    $90K — $95K *
    Silver Spring, MD 20906 (Montgomery County)
    Information Technology
    Hybrid
  • Network Security Engineer
    $130K — $135K *
    Silver Spring, MD 20906 (Montgomery County)
    Information Technology
    Hybrid

More Information Technology Jobs

Find similar SOC Analyst jobs: