Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

OneMain Holdings

Key ResponsibilitiesLead advanced investigations involving ransomware, APTs, zero-day exploits, insider threats, credential theft, lateral movement, cloud compromise, on-premises systems, VDI, SaaS, API abuse, business email compromise, certificate abuse, and data exfiltration.Perform full lifecycle incident response including detection, triage, investigation, containment, eradication, recovery, validation, root cause analysis, and post-incident review.Investigate attacks spanning on-premises infrastructure, Windows and Linux servers, Active Directory, Active Directory Certificate Services (AD CS), Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS platforms, APIs, containers, Kubernetes, databases, enterprise applications, and hybrid cloud environments.Perform forensic analysis of on-premises systems, endpoints, servers, virtual machines, VDI, cloud workloads, identity systems, SaaS applications, APIs, databases, and network devices.Analyze telemetry from EDR/XDR, NDR, SIEM, firewalls, IDS/IPS, WAF, VPN, DNS, DHCP, proxy, email security, cloud audit logs, API gateways, identity providers, application logs, and operating system logs.Develop detections and SIEM correlation rules using Elastic Security, KQL, ES|QL/EQL, SQL, PowerShell, and Python.Conduct proactive threat hunting using MITRE ATT&CK, behavioral analytics, and threat intelligence.Provide technical leadership and mentoring to Tier 1 and Tier 2 analysts.Support management with reporting, including producing technical reports documenting attack timelines, root cause, IOCs, IOAs, TTPs, and recommendations.Required QualificationsExpert knowledge of SIEM, SOAR, EDR/XDR, NDR, IDS/IPS, WAF, firewalls, email security, web proxies, CASB, DLP, IAM, PAM, API security, and cloud-native security technologies.Expert experience with Elastic Security (ELK), CrowdStrike Falcon, Microsoft Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud, and Defender for Cloud Apps.Deep understanding of on-premises infrastructure including Windows Server, Linux, Active Directory, Active Directory Certificate Services (AD CS), VMware, Hyper-V, storage, virtualization, networking, Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS, APIs, containers, Kubernetes, databases, and hybrid cloud architectures.Expert knowledge of TCP/IP, DNS, DHCP, VPN, routing, switching, PKI, Kerberos, NTLM, OAuth, OIDC, SAML, JWT, and certificate-based authentication.Advanced proficiency investigating on-premises systems, cloud environments, endpoints, servers, identity platforms, VDI, SaaS applications, APIs, databases, enterprise applications, and AD CS/PKI-related attacks.Expert proficiency with KQL, ES|QL/EQL, SQL, PowerShell, Python, and Bash.Deep knowledge of MITRE ATT&CK, MITRE D3FEND, Cyber Kill Chain, NIST CSF, NIST 800-61, OWASP Top 10, malware analysis, digital forensics, and attacker methodologies.Minimum two certifications such as GCFA, GCFE, GCIH, GCIA, GREM, CISSP, SC-200, SC-100, AWS Certified Security – Specialty, or equivalent.Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent experience.Preferred QualificationsExperience in financial services or another highly regulated industry.Experience investigating enterprise incidents across Microsoft 365, Azure, AWS, Elastic, CrowdStrike, and hybrid environments.Experience supporting DFIR engagements involving ransomware, nation-state threats, insider threats, enterprise-scale incidents, and Active Directory Certificate Services (AD CS) abuse.Experience RequirementsMinimum 8 years of progressive cybersecurity experience.Minimum 6 years of hands-on Security Operations Center experience.Minimum 4 years leading complex enterprise incident investigations.Minimum 2 years performing advanced digital forensics, threat hunting, and detection engineering.Proven experience independently investigating incidents from initial alert through full remediation across on-premises infrastructure, enterprise networks, endpoints, identity platforms, Microsoft 365, Azure, AWS, VDI, SaaS applications, APIs, Elastic Security, hybrid cloud environments, and PKI/AD CS.OneMain Holdings, Inc. is an Equal Employment Opportunity (EEO) employer. Qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship status, color, creed, culture, disability, ethnicity, gender, gender identity or expression, genetic information or history, marital status, military status, national origin, nationality, pregnancy, race, religion, sex, sexual orientation, socioeconomic status, transgender or on any other basis protected by law.SummaryLocation: Baltimore, MDType: Full time

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Security Operations Center (SOC) Tier 3 Analyst / Incident Responder in Baltimore, MD vacancy
  • $94.49k - $131.16k

     ...Senior Information Security Analyst is responsible for...  ...with our security operations vendors and providing...  ...threat detection, incident response, and vulnerability...  ...and effectively respond to the evolving...  ...prevention strategies, and SOC (Security Operations Center) operations. Cloud... 
    Suggested
    Full time
    Work at office
    Remote work
    Relocation
    Visa sponsorship
    Relocation package

    DLA Piper

    Baltimore, MD
    5 days ago
  •  ...marketing, data analytics, compliance, security solutions, and cloud expertise. As...  ...the digital era. The Security Operations Center (SOC) Analyst I will assist in identifying and safeguarding...  ..., threat analysis, and our security incident response lifecycle. Coordinate... 
    Suggested
    Full time
    Local area

    Klik Holdings

    Baltimore, MD
    1 day ago
  •  ...SOC Analyst Tuknik Government Services, LLC, a Koniag...  ...and analysis of security event alerts across the...  ...threats using the agency's incident response-ticketing...  ...Work in a Security Operations Center (SOC) environment, providing...  ...investigations, and responding to a wide variety of... 
    Suggested
    Work experience placement
    Local area
    Flexible hours
    Shift work

    Koniag

    Baltimore, MD
    2 days ago
  • $130k - $135k

     ...Qualifications Minimum of 3–5 years of experience in an operational security program. Bachelor’s...  ...aligned to incident response, security operations...  ...initiatives. Background in SOC operations, detection...  ...Vision Care, Onsite Health Centers (MO & IL), Employee... 
    Suggested
    Full time
    Remote work
    Flexible hours
    Shift work
    Weekend work
    Afternoon shift

    World Wide Technology

    Baltimore, MD
    4 days ago
  • $89.9k - $134.9k

     ...advance your career, and contribute to a secure future for generations. Northrop...  ...collaborative teams. As an Industrial Security Analyst - Level 3 or 4 located in Linthicum, MD, you’ll...  ...support all security activities and operations. The selected candidate will be a member... 
    Suggested
    Full time
    Contract work
    For contractors
    Work at office
    Remote work
    Relocation
    Shift work

    Northrop Grumman

    Linthicum, MD
    2 days ago
  • $117.2k - $176.7k

     ...consider applying for a maximum of 3 roles within 12 months to...  ...the status quo, embrace operational excellence best practices and...  ...business partners on adopting new security requirements....  ...monitoring activities, advisory, incident response, adoption of AI, and... 

    Salesforce.Com Inc

    Baltimore, MD
    5 days ago
  • $90k - $100k

     ...trusted advisor supporting the Social Security Administration's (SSA) Continuity of Operations (COOP), Occupant Emergency...  ...continuity planning, exercise management, incident response support, and program...  ...~ Federal Holidays and three (3) weeks’ vacation ~401(k) with... 
    Full time
    For contractors

    MELE Associates, Inc.

    Baltimore, MD
    9 days ago
  • $72.4k - $108.6k

     ...enabling solutions for global security. We have a wide portfolio of secure...  ...our team as a Manufacturing Analyst or Principal Manufacturing...  ...Manufacturing Cell Management, Operations Program Management, Production...  ...Coordination; Master’s degree with 3 years of experience in... 
    Full time
    Relocation
    Shift work

    Northrop Grumman

    Baltimore, MD
    3 days ago
  • $30 - $35 per hour

    The Technical Incident Management (TIM) Analyst is responsible for leading and coordinating the lifecycle of Priority 1-Priority 2 incident, ensuring...  ...Desk, Infrastructure, Application Support, Network Operations, and business stakeholders to minimize business disruption... 
    Contract work
    Temporary work
    Remote work

    TEKsystems

    Catonsville, MD
    2 days ago
  • $90k - $100k

     ...Job Title IT Security Analyst Location Baltimore, MD FLSA Status Exempt...  ...Director, Information Technology Operations Compensation $90,000 – $100...  ..., investigating, and responding to security threats across...  ...detection tools, escalating incidents as appropriate. Investigate... 
    Remote work
    Flexible hours

    Baltimore Orioles

    Baltimore, MD
    4 days ago
  • $88.7k - $147.9k

     ...role in delivering high-quality, innovative security solutions that serve our clients and...  ...participate on the first day of the month following 3 months of service Paid time off – Our PTO...  ...of our clients and partners, we respond to some of the most complex challenges facing... 
    Contract work
    Work at office
    Local area
    3 days per week

    GHD

    Baltimore, MD
    5 days ago
  • $18.75 per hour

     ...Target Security Specialist The Starting Hourly Rate / Salario por Hora...  ...including exterior property. Respond to and accurately document security incidents in a timely manner. Appropriately...  ...on multiple frequency devices and operate handheld scanners, and other... 
    Hourly pay
    Local area
    Flexible hours
    Shift work
    Night shift
    Day shift

    Target

    Middle River, MD
    3 days ago
  • $104k - $166k

     ...seeking a Cyber Data Analyst in our Linthicum,...  ...national security interests by leveraging...  ...Industrial Base partners.Respond to various RFIs,...  ...to automate daily operations and update SOPs...  ...cyber reports and incidents.QualificationsMinimum...  ...years with MS/MA; 3 years with PhD. A... 
    Contract work
    Work at office
    Shift work

    Peraton Corporation

    Linthicum, MD
    2 days ago
  • $89.9k - $134.9k

     ...history.Northrop Grumman is seeking a Principal Industrial Security Analyst 3/CPSO. This CPSO position, for the support of a program(s) as...  ...implements federal security regulations that apply to company operations. Obtains rulings, interpretations, and acceptable deviations... 
    Full time
    Work experience placement
    Relocation
    Shift work

    Northrop Grumman

    Baltimore, MD
    2 days ago
  • $135k - $216k

     ...seeking a Senior Sensor Analyst in our Linthicum, MD...  ...to protecting national security interests by leveraging...  ...intelligence analysis and operational planning to monitor,...  ...with MS/MA; Minimum of 3 years with PhD. Degree...  ...operations and analysis (e.g., incident response & management,... 
    Contract work
    Work at office
    Shift work

    Peraton Corporation

    Linthicum, MD
    2 days ago
  • $69.5k - $118k

     ...contribute to daily risk management, operational oversight, new complex...  ....Partner regularly with securities operations staff, relationship...  ...accounts and trade activity.Respond to queries related to cash breaks...  .... Estimated Time Commitment: 3-5 minutes2. If you are eligible... 
    Full time
    Work at office
    Local area
    Remote work
    1 day per week

    T. Rowe Price

    Baltimore, MD
    4 days ago
  • $96.5k - $164k

     ...Price is seeking an experienced Senior Analyst to partner with business and...  ...It is designed for someone who can operate at the intersection of investments,...  ...invitations for each role and will need to respond to each.Estimated Time Commitment: 3-5 minutes2. If you are eligible,... 
    Full time
    Local area
    Remote work
    3 days per week

    T. Rowe Price

    Baltimore, MD
    4 days ago
  • $105.4k - $207.8k

     ...identity, access, and platform security. Join our team to deliver...  ...improvements, including administrative tiering, role-based access controls,...  ..., assessing, migrating, or operating Microsoft Active Directory...  ...inquiries to the Global Call Center (GCC) at USTalentCICInbox@... 
    Local area
    Visa sponsorship

    Deloitte

    Baltimore, MD
    4 days ago
  • $18.03 per hour

     ...Allied Universal®, North America’s leading security and facility services company, offers...  ...patrols, and help deter security-related incidents. You will provide exceptional customer...  ...authorized personnel to appropriate areas. Respond to access-control concerns, incidents,... 
    Full time
    For contractors
    Local area
    Shift work

    Alliedbarton Security Services

    Dundalk, MD
    5 days ago
  •  ...Executive Advisors is seeking an information security professional in the Baltimore/Washington-Metropolitan region with operations, technical and managerial experience to...  ...regulatory/compliance, threat analytics and incident response to name a few. Qualifications 7+ years... 
    Full time
    Temporary work

    Hartman Executive Advisors

    Baltimore, MD
    1 day ago
  • $110k - $140k

     ...research support for our Technology analystThe Associate Analyst program is a three-to-five-year structured program...  ...receive separate invitations for each role and will need to respond to each. Estimated Time Commitment: 3-5 minutes2. If you are eligible, you will be asked to... 
    Full time
    Work experience placement
    Local area
    Remote work
    1 day per week

    T. Rowe Price

    Baltimore, MD
    2 days ago
  •  ...Senior Analyst - Commercial Collections & Compliance Overview The Commercial...  ...Analyst supports the operational performance of our retail real...  ...schedule available, requires 3 days at our corporate office...  ...portfolio; build proactive workflows, tiering, triggers, and dashboards... 
    Work at office

    Continental Realty Corporation

    Baltimore, MD
    1 day ago
  • $85.5k - $158.7k

    *Please Note: This Analyst position requires work to potentially...  ...to the national security community, the US...  ...periodic background checks. 3+ years previous work...  ...professional manner and respond quickly to their...  ...qualified employees in all our operations around the world... 
    Full time
    Contract work
    Work experience placement
    Work at office
    Local area
    Flexible hours
    2 days per week
    3 days per week

    PowerToFly

    Baltimore, MD
    3 days ago
  •  ...and hands-on experience identifying vulnerabilities, monitoring security events, and providing actionable recommendations to strengthen...  ...Poly, experience with network defense, vulnerability assessment, incident response, and SIEM tools such as Splunk and #J-18808-Ljbffr... 

    PAE Government Services Inc.

    Baltimore, MD
    2 days ago
  •  ...delivers effects-as-a-service to national security partners across five domains and more...  ...the whole stack: designing, building, and operating turnkey capabilities that give our...  ...We are looking for a SIGINT Geospatial Analyst to combine SIGINT observables with geospatial... 
    Full time
    Temporary work
    Work at office
    Monday to Friday
    Flexible hours
    Shift work

    Metrea

    Baltimore, MD
    2 days ago
  • $72k - $90k

     ...globe. Through its Advanced Technology Center, a collaborative ecosystem of the world'...  ...challenges. Position Overview: The Security Analyst supports customer engagements by helping...  ...considered in lieu of a degree. A minimum of 3 years' progressive experience in a... 
    Full time
    Remote work
    Shift work

    World Wide Technology

    Baltimore, MD
    4 days ago
  • $87k - $148k

     ...that enable efficient, scalable, and risk-controlled operations. The position combines deep operational expertise, people...  ...separate invitations for each role and will need to respond to each. Estimated Time Commitment: 3-5 minutes2. If you are eligible, you will be asked... 
    Full time
    Local area
    Remote work
    1 day per week

    T. Rowe Price

    Baltimore, MD
    3 days ago
  •  ...of criminal enterprises. EnProVera, owned and operated by government veterans with extensive backgrounds in Homeland Security, Law Enforcement, the Military, and the Intelligence Community, has a vacancy for a Data Analyst. In this role, you will be supporting the overall... 
    Temporary work
    Work at office
    Local area
    Flexible hours

    FSA

    Baltimore, MD
    14 hours ago
  •  ...Canada. In Europe our operations are supported from Solothurn...  ...Our Global Development Center is located in Mumbai,...  ...in the way we respond to our clients, interact...  ...experience as a business analyst or closely related experience...  ...(ISMS) and CMMI Level 3 certified company.... 
    Work at office

    Trigyn Technologies

    Middle River, MD
    5 days ago
  • $38.7 per hour

     ...WORKFORCE MANAGEMENT ANALYST (WFM / CONTACT CENTER) — REMOTE Location: Remote (U.S.)...  ...plans, create schedules, and respond to ad hoc workforce planning requests...  ...to required experience) 3+ years of experience in service center operations or scheduling/forecasting... 
    Contract work
    Local area
    Remote work

    System One Holdings, LLC

    Baltimore, MD
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Operations Center (SOC) Tier 3 Analyst / Incident Responder. Be the first to apply!