Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
OneMain Financial
Lead advanced investigations involving ransomware, APTs, zero-day exploits, insider threats, credential theft, lateral movement, cloud compromise, on-premises systems, VDI, SaaS, API abuse, business email compromise, certificate abuse, and data exfiltration. Perform full lifecycle incident response including detection, triage, investigation, containment, eradication, recovery, validation, root cause analysis, and post-incident review. Investigate attacks spanning on-premises infrastructure, Windows and Linux servers, Active Directory, Active Directory Certificate Services (AD CS), Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS platforms, APIs, containers, Kubernetes, databases, enterprise applications, and hybrid cloud environments. Perform forensic analysis of on-premises systems, endpoints, servers, virtual machines, VDI, cloud workloads, identity systems, SaaS applications, APIs, databases, and network devices. Analyze telemetry from EDR/XDR, NDR, SIEM, firewalls, IDS/IPS, WAF, VPN, DNS, DHCP, proxy, email security, cloud audit logs, API gateways, identity providers, application logs, and operating system logs. Develop detections and SIEM correlation rules using Elastic Security, KQL, ES|QL/EQL, SQL, PowerShell, and Python. Conduct proactive threat hunting using MITRE ATT&CK, behavioral analytics, and threat intelligence. Provide technical leadership and mentoring to Tier 1 and Tier 2 analysts. Support management with reporting, including producing technical reports documenting attack timelines, root cause, IOCs, IOAs, TTPs, and recommendations. Key Responsibilities Lead advanced investigations involving ransomware, APTs, zero-day exploits, insider threats, credential theft, lateral movement, cloud compromise, on-premises systems, VDI, SaaS, API abuse, business email compromise, certificate abuse, and data exfiltration. Perform full lifecycle incident response including detection, triage, investigation, containment, eradication, recovery, validation, root cause analysis, and post-incident review. Investigate attacks spanning on-premises infrastructure, Windows and Linux servers, Active Directory, Active Directory Certificate Services (AD CS), Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS platforms, APIs, containers, Kubernetes, databases, enterprise applications, and hybrid cloud environments. Perform forensic analysis of on-premises systems, endpoints, servers, virtual machines, VDI, cloud workloads, identity systems, SaaS applications, APIs, databases, and network devices. Analyze telemetry from EDR/XDR, NDR, SIEM, firewalls, IDS/IPS, WAF, VPN, DNS, DHCP, proxy, email security, cloud audit logs, API gateways, identity providers, application logs, and operating system logs. Develop detections and SIEM correlation rules using Elastic Security, KQL, ES|QL/EQL, SQL, PowerShell, and Python. Conduct proactive threat hunting using MITRE ATT&CK, behavioral analytics, and threat intelligence. Provide technical leadership and mentoring to Tier 1 and Tier 2 analysts. Support management with reporting, including producing technical reports documenting attack timelines, root cause, IOCs, IOAs, TTPs, and recommendations. Required Qualifications Expert knowledge of SIEM, SOAR, EDR/XDR, NDR, IDS/IPS, WAF, firewalls, email security, web proxies, CASB, DLP, IAM, PAM, API security, and cloud-native security technologies. Expert experience with Elastic Security (ELK), CrowdStrike Falcon, Microsoft Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud, and Defender for Cloud Apps. Deep understanding of on-premises infrastructure including Windows Server, Linux, Active Directory, Active Directory Certificate Services (AD CS), VMware, Hyper‑V, storage, virtualization, networking, Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS, APIs, containers, Kubernetes, databases, and hybrid cloud architectures. Expert knowledge of TCP/IP, DNS, DHCP, VPN, routing, switching, PKI, Kerberos, NTLM, OAuth, OIDC, SAML, JWT, and certificate‑based authentication. Advanced proficiency investigating on‑premises systems, cloud environments, endpoints, servers, identity platforms, VDI, SaaS applications, APIs, databases, enterprise applications, and AD CS/PKI‑related attacks. Expert proficiency with KQL, ES|QL/EQL, SQL, PowerShell, Python, and Bash. Deep knowledge of MITRE ATT&CK, MITRE D3FEND, Cyber Kill Chain, NIST CSF, NIST 800‑61, OWASP Top 10, malware analysis, digital forensics, and attacker methodologies. Minimum two certifications such as GCFA, GCFE, GCIH, GCIA, GREM, CISSP, SC‑200, SC‑100, AWS Certified Security – Specialty, or equivalent. Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent experience. Preferred Qualifications Experience in financial services or another highly regulated industry. Experience investigating enterprise incidents across Microsoft 365, Azure, AWS, Elastic, CrowdStrike, and hybrid environments. Experience supporting DFIR engagements involving ransomware, nation‑state threats, insider threats, enterprise‑scale incidents, and Active Directory Certificate Services (AD CS) abuse. Experience Requirements Minimum 8 years of progressive cybersecurity experience. Minimum 6 years of hands‑on Security Operations Center experience. Minimum 4 years leading complex enterprise incident investigations. Minimum 2 years performing advanced digital forensics, threat hunting, and detection engineering. Proven experience independently investigating incidents from initial alert through full remediation across on‑premises infrastructure, enterprise networks, endpoints, identity platforms, Microsoft 365, Azure, AWS, VDI, SaaS applications, APIs, Elastic Security, hybrid cloud environments, and PKI/AD CS. #J-18808-Ljbffr OneMain Financial
$131.3k - $237.35k
...communities, and operate sustainable. Everything... ...for a Senior Incident Response Analyst to support the... ...Department of Homeland Security (DHS), Security Operations Center (SOC) Support Services... ..., mitigate, and respond to cyber threats... ...for at least 3 days with an anticipated...SuggestedFull timeFlexible hours$140k - $180k
...Job Title: SOC Analyst Tier 3 Place of Performance:... ...more than 20 years of securing some of the U.S. Department... ...Our cybersecurity operators are experts at... ...Analyst Tier 3 and Incident Responder , a senior analyst... ...capability in the operations center. Tier 3/IR analysts...SuggestedTemporary workLocal areaImmediate startAll shiftsFlexible hoursShift workNight shiftRotating shift$70k - $80k
...Requisition #: 1778 Job Title: Tier 1 SOC Analyst Location: On-Site,... ...Required Certification(s): Security + or equivalent... ...positives, and escalating confirmed incidents according to established playbooks... ...threats to Tier 2 and Tier 3 teams. Education and...SuggestedTemporary work- Chenega MIOS in Arlington, VA seeks a Security Operations Center Analyst to monitor, detect, and respond to cyber threats across program networks. The role includes SIEM monitoring, incident handling, log analysis, and coordination with stakeholders to contain and recover...Suggested
$120k - $135k
...Senior Incident Response Analyst Tetrad Digital Integrity (TDI) is a cybersecurity... ...program. As part of the Security Operations Center, you will help monitor, detect, investigate, and respond to cybersecurity threats... ...scripts to strengthen SOC monitoring capabilities....SuggestedPermanent employmentContract workRemote work2 days per week$92k - $153k
...TrustWhat You Will Do:Monitor security alerts and events in the Security Operations Center (SOC) and perform initial... ...potential security incidents using SIEM, endpoint,... ...incidents to senior analysts or incident response teams... ...to prioritize and respond to alerts in a fast-paced...Full timeWork experience placementFlexible hoursShift work- ...Connectors is seeking a seasoned Cybersecurity Analyst - Tier 2 (Incident Responder) to support a Federal information security program. The role conducts advanced incident... ...cloud resources. The candidate will work with SOC personnel, engineers, threat hunters, ISSOs, and...
- cFocus Software seeks an Incident Response Analyst (Tier 2) to join our program supporting the AOUSC. This role... ...in-depth IR activities, analyze security incidents, and coordinate with federal teams. Candidates should have 3+ years IR experience, strong scripting...
$85k - $110k
...currently seeking a Tier II Incident Response Analyst to provide... ...management, and SOC operations. Promote and drive... ...to leverage in Security Operations. Develop... ...monitoring and responding to threats in... ...Security Operations Center (SOC) operations... ...at CMMI Level 3 Maturity for Development...Contract work$131.3k - $237.35k
...our communities, and operate sustainably. Everything... ...critical need for a Senior Incident Response Analyst to support the DHS... ...of Homeland Security (DHS), Security Operations Center (SOC) Support Services is a... ...analyze, mitigate, and respond to cyber threats and adversarial...Flexible hours- ...About the job Security Operations Center (SOC) Analyst Job Description: We are seeking a skilled and detail-oriented Security Operations... ...be responsible for monitoring, analyzing, and responding to security incidents and threats within our organization. You will...
- ...change).Who are you?Security-cleared... ...'s Degree with 3 years of experience... ...maintaining SOC oriented services... ...engineering, operations, and managementTechnologies... ...threats, and respond to agency and... ...cybersecurity incidents and provide... ...by the SOC analyst teamPrepare, provide...Temporary workWork at officeRemote work
$124.2k - $186.2k
...The Information Security organization advances... ...to monitor and respond to attacks... ...Rubrik's Security Operations Center (SOC) plays a strategic... ...to cyber security incidents, report on cyber... ...equivalent experience. ~3+ years of... ...Sensitive, Low Risk, Tier 1 Incumbents...Local areaRemote work$52 per hour
Overview Security Operations Center Analyst (SOC) Arlington, VA Are you ready to enhance your skills and build... ...program networks Perform event and incident management in accordance with... ...SIEM toolsets Detect, analyze, and respond to incidents, coordinate with other...- SkyePoint Decisions seeks a CIRT Tier 2 Analyst to support the Diplomatic Security Cyber Mission (DSCM) program. The role is on-site in Beltsville, MD, with... ...2:00-6:00 EST) five days a week. You will detect and respond to cyber events, analyze logs, perform malware and IOC...Shift work
- Cybersecurity Analyst - Tier 1 (Security Operations Center Analyst) Location: Bethesda, MD (Hybrid... ...program. The Tier 1 SOC Analyst serves as the first... ...security tools, initial incident triage, alert validation,... ...Support Tier 2 Incident Responders during security investigations...Full timeWork at officeShift workRotating shiftAfternoon shift
- ...insightful market intelligence has secured long‑term partnerships with... ...Title: Information Security Operations Center - Incident Handler III Location:... ...OSI model, layer 2 and layer 3 concepts Understanding of... ...Experience with CERT/CSIRT/CIRT/SOC Certification Requirements:...Shift workRotating shiftWeekend work
$102.5k - $188.9k
...enable our clients to operate with resilience,... ...manage to secure success.Cyber threats... ...identify, analyze, and respond to exploitation... ...Cyber Exploitation Analyst, you will support... ...activity, investigating incidents, assessing... ...to the Global Call Center (GCC) at USTalentCICInbox...Work at office- A leading social media company is seeking a Lead Cyber Security Operations Center Analyst to oversee incident responses and investigations. This role involves leading a team of analysts, developing detection strategies, and ensuring the safety of user data on the platform...
- ...seeking a Threat Detection & Response Analyst to monitor enterprise systems, investigate security events, and respond to cybersecurity incidents. The Analyst collaborates with Incident... ...citizenship and experience with MITRE ATT&CK, SOC processes, and cloud/network/endpoint...Remote job
- ...Title: Information Security Analyst Location:... ...Support the company’s Incident Response procedures... ...breaches. Triage and respond to security alerts... ...standard operating procedures for security... ...experience. ~2-3 years of... ...experience working in a SOC or Security Incident...Permanent employmentContract workTemporary workFor contractorsWork experience placementLocal area
$87.1k - $157.45k
...opportunities available for SOC Analysts to join our team... ...least 2 years of incident handling/response... ...(such as CompTIA Security+ CE, ISC2 SSCP,... ...(Protect, Detect, Respond and Sustain)... ...engineering, and operations of at least one enterprise... ...open for at least 3 days with an...Full timeWork experience placementAll shiftsShift work$80k - $128k
...seeking a Risk and Vulnerability Analyst. Location: Chandler, AZ or... ...Analyst supports a 24x7 Security Operations Center (SOC) by identifying, analyzing,... ...intelligence, and active incidents. Automate vulnerability... ...Preferred Qualifications 3-5 years of experience in security...Contract workShift work- Edgewater Federal Solutions seeks a Tier II Incident Response Analyst to support a government contract. US citizenship is required for this role, with... ..., analyze malware, and drive improvements to toolsets and SOC processes. The candidate should have a bachelor’s degree in...Contract work
- Security Operations Center Analyst - High Washington, DC, USA Job Description Posted Wednesday... ...Operations Center (SOC) Analyst to support the U.S... ...operations, threat detection, and incident response within complex... ...operations, with at least 3 years in a senior SOC analyst...Local areaFlexible hours
- ...SOC Analyst At Accenture Federal Services, nothing matters more... ...across defense, national security, public safety, civilian,... ...continuous monitoring and security incident triage through the review... ...of security incidents to Tier 2 or incident responders. Job Qualifications:...
- ...of delivering top-tier services to our... ...& Attack Surface Analyst to help identify,... ...present the greatest operational threat to the... ...vulnerability management, incident response, security engineering, RMF,... ...with incident responders, penetration... ...webinars, etc.) 3 weeks of PTO starting...
- SkyePoint Decisions is seeking an Incident Response Analyst to support cybersecurity operations by monitoring, analyzing, investigating, and responding to security incidents across enterprise, cloud, network, and endpoint environments. The analyst will work with security...Remote job
$53.9k - $120.1k
Cybersecurity Incident Response Triage IR Analyst Arlington, VA The Cybersecurity Incident... ...and analysis on security-relevant events indicating... ...Work Actively monitor and respond to cybersecurity incidents... ...procedures Collaborate with operations teams, legal, human...Work experience placementLive inWork at officeLocal area- SkyePoint Decisions seeks an Incident Response Analyst to monitor, analyze, and respond to security incidents across enterprise, cloud, network, and endpoint environments. The role collaborates with security engineers and government stakeholders to identify threats, contain...Remote job
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Operations Center (SOC) Tier 3 Analyst / Incident Responder. Be the first to apply!
- nonprofit analyst Washington DC
- provisioning analyst Washington DC
- senior contracts analyst Washington DC
- allocation analyst Washington DC
- sharepoint analyst Washington DC
- corporate strategy analyst Washington DC
- reimbursement analyst Washington DC
- travel and expense analyst Washington DC
- fixed income analyst Washington DC
- contracts analyst Washington DC


