Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

OneMain Financial

Lead advanced investigations involving ransomware, APTs, zero-day exploits, insider threats, credential theft, lateral movement, cloud compromise, on-premises systems, VDI, SaaS, API abuse, business email compromise, certificate abuse, and data exfiltration. Perform full lifecycle incident response including detection, triage, investigation, containment, eradication, recovery, validation, root cause analysis, and post-incident review. Investigate attacks spanning on-premises infrastructure, Windows and Linux servers, Active Directory, Active Directory Certificate Services (AD CS), Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS platforms, APIs, containers, Kubernetes, databases, enterprise applications, and hybrid cloud environments. Perform forensic analysis of on-premises systems, endpoints, servers, virtual machines, VDI, cloud workloads, identity systems, SaaS applications, APIs, databases, and network devices. Analyze telemetry from EDR/XDR, NDR, SIEM, firewalls, IDS/IPS, WAF, VPN, DNS, DHCP, proxy, email security, cloud audit logs, API gateways, identity providers, application logs, and operating system logs. Develop detections and SIEM correlation rules using Elastic Security, KQL, ES|QL/EQL, SQL, PowerShell, and Python. Conduct proactive threat hunting using MITRE ATT&CK, behavioral analytics, and threat intelligence. Provide technical leadership and mentoring to Tier 1 and Tier 2 analysts. Support management with reporting, including producing technical reports documenting attack timelines, root cause, IOCs, IOAs, TTPs, and recommendations. Key Responsibilities Lead advanced investigations involving ransomware, APTs, zero-day exploits, insider threats, credential theft, lateral movement, cloud compromise, on-premises systems, VDI, SaaS, API abuse, business email compromise, certificate abuse, and data exfiltration. Perform full lifecycle incident response including detection, triage, investigation, containment, eradication, recovery, validation, root cause analysis, and post-incident review. Investigate attacks spanning on-premises infrastructure, Windows and Linux servers, Active Directory, Active Directory Certificate Services (AD CS), Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS platforms, APIs, containers, Kubernetes, databases, enterprise applications, and hybrid cloud environments. Perform forensic analysis of on-premises systems, endpoints, servers, virtual machines, VDI, cloud workloads, identity systems, SaaS applications, APIs, databases, and network devices. Analyze telemetry from EDR/XDR, NDR, SIEM, firewalls, IDS/IPS, WAF, VPN, DNS, DHCP, proxy, email security, cloud audit logs, API gateways, identity providers, application logs, and operating system logs. Develop detections and SIEM correlation rules using Elastic Security, KQL, ES|QL/EQL, SQL, PowerShell, and Python. Conduct proactive threat hunting using MITRE ATT&CK, behavioral analytics, and threat intelligence. Provide technical leadership and mentoring to Tier 1 and Tier 2 analysts. Support management with reporting, including producing technical reports documenting attack timelines, root cause, IOCs, IOAs, TTPs, and recommendations. Required Qualifications Expert knowledge of SIEM, SOAR, EDR/XDR, NDR, IDS/IPS, WAF, firewalls, email security, web proxies, CASB, DLP, IAM, PAM, API security, and cloud-native security technologies. Expert experience with Elastic Security (ELK), CrowdStrike Falcon, Microsoft Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud, and Defender for Cloud Apps. Deep understanding of on-premises infrastructure including Windows Server, Linux, Active Directory, Active Directory Certificate Services (AD CS), VMware, Hyper‑V, storage, virtualization, networking, Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS, APIs, containers, Kubernetes, databases, and hybrid cloud architectures. Expert knowledge of TCP/IP, DNS, DHCP, VPN, routing, switching, PKI, Kerberos, NTLM, OAuth, OIDC, SAML, JWT, and certificate‑based authentication. Advanced proficiency investigating on‑premises systems, cloud environments, endpoints, servers, identity platforms, VDI, SaaS applications, APIs, databases, enterprise applications, and AD CS/PKI‑related attacks. Expert proficiency with KQL, ES|QL/EQL, SQL, PowerShell, Python, and Bash. Deep knowledge of MITRE ATT&CK, MITRE D3FEND, Cyber Kill Chain, NIST CSF, NIST 800‑61, OWASP Top 10, malware analysis, digital forensics, and attacker methodologies. Minimum two certifications such as GCFA, GCFE, GCIH, GCIA, GREM, CISSP, SC‑200, SC‑100, AWS Certified Security – Specialty, or equivalent. Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent experience. Preferred Qualifications Experience in financial services or another highly regulated industry. Experience investigating enterprise incidents across Microsoft 365, Azure, AWS, Elastic, CrowdStrike, and hybrid environments. Experience supporting DFIR engagements involving ransomware, nation‑state threats, insider threats, enterprise‑scale incidents, and Active Directory Certificate Services (AD CS) abuse. Experience Requirements Minimum 8 years of progressive cybersecurity experience. Minimum 6 years of hands‑on Security Operations Center experience. Minimum 4 years leading complex enterprise incident investigations. Minimum 2 years performing advanced digital forensics, threat hunting, and detection engineering. Proven experience independently investigating incidents from initial alert through full remediation across on‑premises infrastructure, enterprise networks, endpoints, identity platforms, Microsoft 365, Azure, AWS, VDI, SaaS applications, APIs, Elastic Security, hybrid cloud environments, and PKI/AD CS. #J-18808-Ljbffr OneMain Financial

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Security Operations Center (SOC) Tier 3 Analyst / Incident Responder in Washington DC vacancy
  • $131.3k - $237.35k

     ...communities, and operate sustainable. Everything...  ...for a Senior Incident Response Analyst to support the...  ...Department of Homeland Security (DHS), Security Operations Center (SOC) Support Services...  ..., mitigate, and respond to cyber threats...  ...for at least 3 days with an anticipated... 
    Suggested
    Full time
    Flexible hours

    Leidos

    Arlington, VA
    13 hours ago
  • $140k - $180k

     ...Job Title: SOC Analyst Tier 3 Place of Performance:...  ...more than 20 years of securing some of the U.S. Department...  ...Our cybersecurity operators are experts at...  ...Analyst Tier 3 and Incident Responder , a senior analyst...  ...capability in the operations center. Tier 3/IR analysts... 
    Suggested
    Temporary work
    Local area
    Immediate start
    All shifts
    Flexible hours
    Shift work
    Night shift
    Rotating shift

    JFL Consulting

    Springfield, VA
    2 days ago
  • $70k - $80k

     ...Requisition #: 1778 Job Title: Tier 1 SOC Analyst Location: On-Site,...  ...Required Certification(s): Security + or equivalent...  ...positives, and escalating confirmed incidents according to established playbooks...  ...threats to Tier 2 and Tier 3 teams. Education and... 
    Suggested
    Temporary work

    Agile Defense

    Washington DC
    1 day ago
  • Chenega MIOS in Arlington, VA seeks a Security Operations Center Analyst to monitor, detect, and respond to cyber threats across program networks. The role includes SIEM monitoring, incident handling, log analysis, and coordination with stakeholders to contain and recover... 
    Suggested

    NJVC

    Arlington, VA
    13 hours ago
  • $120k - $135k

     ...Senior Incident Response Analyst Tetrad Digital Integrity (TDI) is a cybersecurity...  ...program. As part of the Security Operations Center, you will help monitor, detect, investigate, and respond to cybersecurity threats...  ...scripts to strengthen SOC monitoring capabilities.... 
    Suggested
    Permanent employment
    Contract work
    Remote work
    2 days per week

    Tetrad Digital Integrity

    Arlington, VA
    1 day ago
  • $92k - $153k

     ...TrustWhat You Will Do:Monitor security alerts and events in the Security Operations Center (SOC) and perform initial...  ...potential security incidents using SIEM, endpoint,...  ...incidents to senior analysts or incident response teams...  ...to prioritize and respond to alerts in a fast-paced... 
    Full time
    Work experience placement
    Flexible hours
    Shift work

    Guidehouse

    Washington DC
    3 days ago
  •  ...Connectors is seeking a seasoned Cybersecurity Analyst - Tier 2 (Incident Responder) to support a Federal information security program. The role conducts advanced incident...  ...cloud resources. The candidate will work with SOC personnel, engineers, threat hunters, ISSOs, and... 

    Digital Global Connectors

    Mc Lean, VA
    1 day ago
  • cFocus Software seeks an Incident Response Analyst (Tier 2) to join our program supporting the AOUSC. This role...  ...in-depth IR activities, analyze security incidents, and coordinate with federal teams. Candidates should have 3+ years IR experience, strong scripting... 

    cFocus Software Incorporated

    Washington DC
    1 day ago
  • $85k - $110k

     ...currently seeking a Tier II Incident Response Analyst to provide...  ...management, and SOC operations. Promote and drive...  ...to leverage in Security Operations. Develop...  ...monitoring and responding to threats in...  ...Security Operations Center (SOC) operations...  ...at CMMI Level 3 Maturity for Development... 
    Contract work

    Edgewater Federal Solutions

    Bethesda, MD
    2 days ago
  • $131.3k - $237.35k

     ...our communities, and operate sustainably. Everything...  ...critical need for a Senior Incident Response Analyst to support the DHS...  ...of Homeland Security (DHS), Security Operations Center (SOC) Support Services is a...  ...analyze, mitigate, and respond to cyber threats and adversarial... 
    Flexible hours

    Leidos

    Arlington, VA
    1 day ago
  •  ...About the job Security Operations Center (SOC) Analyst Job Description: We are seeking a skilled and detail-oriented Security Operations...  ...be responsible for monitoring, analyzing, and responding to security incidents and threats within our organization. You will... 

    4 Staffing Corp

    Washington DC
    5 days ago
  •  ...change).Who are you?Security-cleared...  ...'s Degree with 3 years of experience...  ...maintaining SOC oriented services...  ...engineering, operations, and managementTechnologies...  ...threats, and respond to agency and...  ...cybersecurity incidents and provide...  ...by the SOC analyst teamPrepare, provide... 
    Temporary work
    Work at office
    Remote work

    Fusion Technology

    Washington DC
    2 days ago
  • $124.2k - $186.2k

     ...The Information Security organization advances...  ...to monitor and respond to attacks...  ...Rubrik's Security Operations Center (SOC) plays a strategic...  ...to cyber security incidents, report on cyber...  ...equivalent experience. ~3+ years of...  ...Sensitive, Low Risk, Tier 1 Incumbents... 
    Local area
    Remote work

    Rubrik

    Washington DC
    1 day ago
  • $52 per hour

    Overview Security Operations Center Analyst (SOC) Arlington, VA Are you ready to enhance your skills and build...  ...program networks Perform event and incident management in accordance with...  ...SIEM toolsets Detect, analyze, and respond to incidents, coordinate with other... 

    Chenega MIOS SBU

    Arlington, VA
    1 day ago
  • SkyePoint Decisions seeks a CIRT Tier 2 Analyst to support the Diplomatic Security Cyber Mission (DSCM) program. The role is on-site in Beltsville, MD, with...  ...2:00-6:00 EST) five days a week. You will detect and respond to cyber events, analyze logs, perform malware and IOC... 
    Shift work

    SkyePoint Decisions

    Laurel, MD
    13 hours ago
  • Cybersecurity Analyst - Tier 1 (Security Operations Center Analyst) Location: Bethesda, MD (Hybrid...  ...program. The Tier 1 SOC Analyst serves as the first...  ...security tools, initial incident triage, alert validation,...  ...Support Tier 2 Incident Responders during security investigations... 
    Full time
    Work at office
    Shift work
    Rotating shift
    Afternoon shift

    Digital Global Connectors

    Mc Lean, VA
    1 day ago
  •  ...insightful market intelligence has secured long‑term partnerships with...  ...Title: Information Security Operations Center - Incident Handler III Location:...  ...OSI model, layer 2 and layer 3 concepts Understanding of...  ...Experience with CERT/CSIRT/CIRT/SOC Certification Requirements:... 
    Shift work
    Rotating shift
    Weekend work

    Artech Information System LLC

    Washington DC
    1 day ago
  • $102.5k - $188.9k

     ...enable our clients to operate with resilience,...  ...manage to secure success.Cyber threats...  ...identify, analyze, and respond to exploitation...  ...Cyber Exploitation Analyst, you will support...  ...activity, investigating incidents, assessing...  ...to the Global Call Center (GCC) at USTalentCICInbox... 
    Work at office

    Deloitte

    Rosslyn, VA
    2 days ago
  • A leading social media company is seeking a Lead Cyber Security Operations Center Analyst to oversee incident responses and investigations. This role involves leading a team of analysts, developing detection strategies, and ensuring the safety of user data on the platform... 

    Tik Tok

    Washington DC
    4 days ago
  •  ...seeking a Threat Detection & Response Analyst to monitor enterprise systems, investigate security events, and respond to cybersecurity incidents. The Analyst collaborates with Incident...  ...citizenship and experience with MITRE ATT&CK, SOC processes, and cloud/network/endpoint... 
    Remote job

    SkyePoint Decisions

    Bethesda, MD
    3 days ago
  •  ...Title: Information Security Analyst Location:...  ...Support the company’s Incident Response procedures...  ...breaches. Triage and respond to security alerts...  ...standard operating procedures for security...  ...experience. ~2-3 years of...  ...experience working in a SOC or Security Incident... 
    Permanent employment
    Contract work
    Temporary work
    For contractors
    Work experience placement
    Local area

    System One

    Washington DC
    20 days ago
  • $87.1k - $157.45k

     ...opportunities available for SOC Analysts to join our team...  ...least 2 years of incident handling/response...  ...(such as CompTIA Security+ CE, ISC2 SSCP,...  ...(Protect, Detect, Respond and Sustain)...  ...engineering, and operations of at least one enterprise...  ...open for at least 3 days with an... 
    Full time
    Work experience placement
    All shifts
    Shift work

    Leidos

    Alexandria, VA
    3 days ago
  • $80k - $128k

     ...seeking a Risk and Vulnerability Analyst. Location: Chandler, AZ or...  ...Analyst supports a 24x7 Security Operations Center (SOC) by identifying, analyzing,...  ...intelligence, and active incidents. Automate vulnerability...  ...Preferred Qualifications 3-5 years of experience in security... 
    Contract work
    Shift work

    Peraton

    Washington DC
    4 days ago
  • Edgewater Federal Solutions seeks a Tier II Incident Response Analyst to support a government contract. US citizenship is required for this role, with...  ..., analyze malware, and drive improvements to toolsets and SOC processes. The candidate should have a bachelor’s degree in... 
    Contract work

    Edgewater Federal Solutions

    Bethesda, MD
    2 days ago
  • Security Operations Center Analyst - High Washington, DC, USA Job Description Posted Wednesday...  ...Operations Center (SOC) Analyst to support the U.S...  ...operations, threat detection, and incident response within complex...  ...operations, with at least 3 years in a senior SOC analyst... 
    Local area
    Flexible hours

    Koniag Services, Inc.

    Washington DC
    13 hours ago
  •  ...SOC Analyst At Accenture Federal Services, nothing matters more...  ...across defense, national security, public safety, civilian,...  ...continuous monitoring and security incident triage through the review...  ...of security incidents to Tier 2 or incident responders. Job Qualifications:... 

    Accenture Federal Services

    Washington DC
    3 days ago
  •  ...of delivering top-tier services to our...  ...& Attack Surface Analyst to help identify,...  ...present the greatest operational threat to the...  ...vulnerability management, incident response, security engineering, RMF,...  ...with incident responders, penetration...  ...webinars, etc.) 3 weeks of PTO starting... 

    True Zero Technologies LLC.

    Bethesda, MD
    4 days ago
  • SkyePoint Decisions is seeking an Incident Response Analyst to support cybersecurity operations by monitoring, analyzing, investigating, and responding to security incidents across enterprise, cloud, network, and endpoint environments. The analyst will work with security... 
    Remote job

    SkyePoint Decisions

    Bethesda, MD
    3 days ago
  • $53.9k - $120.1k

    Cybersecurity Incident Response Triage IR Analyst Arlington, VA The Cybersecurity Incident...  ...and analysis on security-relevant events indicating...  ...Work Actively monitor and respond to cybersecurity incidents...  ...procedures Collaborate with operations teams, legal, human... 
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture Federal Services Careers Marketplace

    Arlington, VA
    13 hours ago
  • SkyePoint Decisions seeks an Incident Response Analyst to monitor, analyze, and respond to security incidents across enterprise, cloud, network, and endpoint environments. The role collaborates with security engineers and government stakeholders to identify threats, contain... 
    Remote job

    SkyePoint Decisions

    Bethesda, MD
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Operations Center (SOC) Tier 3 Analyst / Incident Responder. Be the first to apply!