Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
OneMain Holdings
Key ResponsibilitiesLead advanced investigations involving ransomware, APTs, zero-day exploits, insider threats, credential theft, lateral movement, cloud compromise, on-premises systems, VDI, SaaS, API abuse, business email compromise, certificate abuse, and data exfiltration.Perform full lifecycle incident response including detection, triage, investigation, containment, eradication, recovery, validation, root cause analysis, and post-incident review.Investigate attacks spanning on-premises infrastructure, Windows and Linux servers, Active Directory, Active Directory Certificate Services (AD CS), Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS platforms, APIs, containers, Kubernetes, databases, enterprise applications, and hybrid cloud environments.Perform forensic analysis of on-premises systems, endpoints, servers, virtual machines, VDI, cloud workloads, identity systems, SaaS applications, APIs, databases, and network devices.Analyze telemetry from EDR/XDR, NDR, SIEM, firewalls, IDS/IPS, WAF, VPN, DNS, DHCP, proxy, email security, cloud audit logs, API gateways, identity providers, application logs, and operating system logs.Develop detections and SIEM correlation rules using Elastic Security, KQL, ES|QL/EQL, SQL, PowerShell, and Python.Conduct proactive threat hunting using MITRE ATT&CK, behavioral analytics, and threat intelligence.Provide technical leadership and mentoring to Tier 1 and Tier 2 analysts.Support management with reporting, including producing technical reports documenting attack timelines, root cause, IOCs, IOAs, TTPs, and recommendations.Required QualificationsExpert knowledge of SIEM, SOAR, EDR/XDR, NDR, IDS/IPS, WAF, firewalls, email security, web proxies, CASB, DLP, IAM, PAM, API security, and cloud-native security technologies.Expert experience with Elastic Security (ELK), CrowdStrike Falcon, Microsoft Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud, and Defender for Cloud Apps.Deep understanding of on-premises infrastructure including Windows Server, Linux, Active Directory, Active Directory Certificate Services (AD CS), VMware, Hyper-V, storage, virtualization, networking, Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS, APIs, containers, Kubernetes, databases, and hybrid cloud architectures.Expert knowledge of TCP/IP, DNS, DHCP, VPN, routing, switching, PKI, Kerberos, NTLM, OAuth, OIDC, SAML, JWT, and certificate-based authentication.Advanced proficiency investigating on-premises systems, cloud environments, endpoints, servers, identity platforms, VDI, SaaS applications, APIs, databases, enterprise applications, and AD CS/PKI-related attacks.Expert proficiency with KQL, ES|QL/EQL, SQL, PowerShell, Python, and Bash.Deep knowledge of MITRE ATT&CK, MITRE D3FEND, Cyber Kill Chain, NIST CSF, NIST 800-61, OWASP Top 10, malware analysis, digital forensics, and attacker methodologies.Minimum two certifications such as GCFA, GCFE, GCIH, GCIA, GREM, CISSP, SC-200, SC-100, AWS Certified Security – Specialty, or equivalent.Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent experience.Preferred QualificationsExperience in financial services or another highly regulated industry.Experience investigating enterprise incidents across Microsoft 365, Azure, AWS, Elastic, CrowdStrike, and hybrid environments.Experience supporting DFIR engagements involving ransomware, nation-state threats, insider threats, enterprise-scale incidents, and Active Directory Certificate Services (AD CS) abuse.Experience RequirementsMinimum 8 years of progressive cybersecurity experience.Minimum 6 years of hands-on Security Operations Center experience.Minimum 4 years leading complex enterprise incident investigations.Minimum 2 years performing advanced digital forensics, threat hunting, and detection engineering.Proven experience independently investigating incidents from initial alert through full remediation across on-premises infrastructure, enterprise networks, endpoints, identity platforms, Microsoft 365, Azure, AWS, VDI, SaaS applications, APIs, Elastic Security, hybrid cloud environments, and PKI/AD CS.OneMain Holdings, Inc. is an Equal Employment Opportunity (EEO) employer. Qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship status, color, creed, culture, disability, ethnicity, gender, gender identity or expression, genetic information or history, marital status, military status, national origin, nationality, pregnancy, race, religion, sex, sexual orientation, socioeconomic status, transgender or on any other basis protected by law.SummaryLocation: Baltimore, MDType: Full time
$94.49k - $131.16k
...Senior Information Security Analyst is responsible for... ...with our security operations vendors and providing... ...threat detection, incident response, and vulnerability... ...and effectively respond to the evolving... ...prevention strategies, and SOC (Security Operations Center) operations. Cloud...SuggestedFull timeWork at officeRemote workRelocationVisa sponsorshipRelocation package- ...marketing, data analytics, compliance, security solutions, and cloud expertise. As... ...the digital era. The Security Operations Center (SOC) Analyst I will assist in identifying and safeguarding... ..., threat analysis, and our security incident response lifecycle. Coordinate...SuggestedFull timeLocal area
- ...SOC Analyst Tuknik Government Services, LLC, a Koniag... ...and analysis of security event alerts across the... ...threats using the agency's incident response-ticketing... ...Work in a Security Operations Center (SOC) environment, providing... ...investigations, and responding to a wide variety of...SuggestedWork experience placementLocal areaFlexible hoursShift work
$130k - $135k
...Qualifications Minimum of 3–5 years of experience in an operational security program. Bachelor’s... ...aligned to incident response, security operations... ...initiatives. Background in SOC operations, detection... ...Vision Care, Onsite Health Centers (MO & IL), Employee...SuggestedFull timeRemote workFlexible hoursShift workWeekend workAfternoon shift$89.9k - $134.9k
...advance your career, and contribute to a secure future for generations. Northrop... ...collaborative teams. As an Industrial Security Analyst - Level 3 or 4 located in Linthicum, MD, you’ll... ...support all security activities and operations. The selected candidate will be a member...SuggestedFull timeContract workFor contractorsWork at officeRemote workRelocationShift work$117.2k - $176.7k
...consider applying for a maximum of 3 roles within 12 months to... ...the status quo, embrace operational excellence best practices and... ...business partners on adopting new security requirements.... ...monitoring activities, advisory, incident response, adoption of AI, and...$90k - $100k
...trusted advisor supporting the Social Security Administration's (SSA) Continuity of Operations (COOP), Occupant Emergency... ...continuity planning, exercise management, incident response support, and program... ...~ Federal Holidays and three (3) weeks’ vacation ~401(k) with...Full timeFor contractors$72.4k - $108.6k
...enabling solutions for global security. We have a wide portfolio of secure... ...our team as a Manufacturing Analyst or Principal Manufacturing... ...Manufacturing Cell Management, Operations Program Management, Production... ...Coordination; Master’s degree with 3 years of experience in...Full timeRelocationShift work$30 - $35 per hour
The Technical Incident Management (TIM) Analyst is responsible for leading and coordinating the lifecycle of Priority 1-Priority 2 incident, ensuring... ...Desk, Infrastructure, Application Support, Network Operations, and business stakeholders to minimize business disruption...Contract workTemporary workRemote work$90k - $100k
...Job Title IT Security Analyst Location Baltimore, MD FLSA Status Exempt... ...Director, Information Technology Operations Compensation $90,000 – $100... ..., investigating, and responding to security threats across... ...detection tools, escalating incidents as appropriate. Investigate...Remote workFlexible hours$88.7k - $147.9k
...role in delivering high-quality, innovative security solutions that serve our clients and... ...participate on the first day of the month following 3 months of service Paid time off – Our PTO... ...of our clients and partners, we respond to some of the most complex challenges facing...Contract workWork at officeLocal area3 days per week$18.75 per hour
...Target Security Specialist The Starting Hourly Rate / Salario por Hora... ...including exterior property. Respond to and accurately document security incidents in a timely manner. Appropriately... ...on multiple frequency devices and operate handheld scanners, and other...Hourly payLocal areaFlexible hoursShift workNight shiftDay shift$104k - $166k
...seeking a Cyber Data Analyst in our Linthicum,... ...national security interests by leveraging... ...Industrial Base partners.Respond to various RFIs,... ...to automate daily operations and update SOPs... ...cyber reports and incidents.QualificationsMinimum... ...years with MS/MA; 3 years with PhD. A...Contract workWork at officeShift work$89.9k - $134.9k
...history.Northrop Grumman is seeking a Principal Industrial Security Analyst 3/CPSO. This CPSO position, for the support of a program(s) as... ...implements federal security regulations that apply to company operations. Obtains rulings, interpretations, and acceptable deviations...Full timeWork experience placementRelocationShift work$135k - $216k
...seeking a Senior Sensor Analyst in our Linthicum, MD... ...to protecting national security interests by leveraging... ...intelligence analysis and operational planning to monitor,... ...with MS/MA; Minimum of 3 years with PhD. Degree... ...operations and analysis (e.g., incident response & management,...Contract workWork at officeShift work$69.5k - $118k
...contribute to daily risk management, operational oversight, new complex... ....Partner regularly with securities operations staff, relationship... ...accounts and trade activity.Respond to queries related to cash breaks... .... Estimated Time Commitment: 3-5 minutes2. If you are eligible...Full timeWork at officeLocal areaRemote work1 day per week$96.5k - $164k
...Price is seeking an experienced Senior Analyst to partner with business and... ...It is designed for someone who can operate at the intersection of investments,... ...invitations for each role and will need to respond to each.Estimated Time Commitment: 3-5 minutes2. If you are eligible,...Full timeLocal areaRemote work3 days per week$105.4k - $207.8k
...identity, access, and platform security. Join our team to deliver... ...improvements, including administrative tiering, role-based access controls,... ..., assessing, migrating, or operating Microsoft Active Directory... ...inquiries to the Global Call Center (GCC) at USTalentCICInbox@...Local areaVisa sponsorship$18.03 per hour
...Allied Universal®, North America’s leading security and facility services company, offers... ...patrols, and help deter security-related incidents. You will provide exceptional customer... ...authorized personnel to appropriate areas. Respond to access-control concerns, incidents,...Full timeFor contractorsLocal areaShift work- ...Executive Advisors is seeking an information security professional in the Baltimore/Washington-Metropolitan region with operations, technical and managerial experience to... ...regulatory/compliance, threat analytics and incident response to name a few. Qualifications 7+ years...Full timeTemporary work
$110k - $140k
...research support for our Technology analystThe Associate Analyst program is a three-to-five-year structured program... ...receive separate invitations for each role and will need to respond to each. Estimated Time Commitment: 3-5 minutes2. If you are eligible, you will be asked to...Full timeWork experience placementLocal areaRemote work1 day per week- ...Senior Analyst - Commercial Collections & Compliance Overview The Commercial... ...Analyst supports the operational performance of our retail real... ...schedule available, requires 3 days at our corporate office... ...portfolio; build proactive workflows, tiering, triggers, and dashboards...Work at office
$85.5k - $158.7k
*Please Note: This Analyst position requires work to potentially... ...to the national security community, the US... ...periodic background checks. 3+ years previous work... ...professional manner and respond quickly to their... ...qualified employees in all our operations around the world...Full timeContract workWork experience placementWork at officeLocal areaFlexible hours2 days per week3 days per week- ...and hands-on experience identifying vulnerabilities, monitoring security events, and providing actionable recommendations to strengthen... ...Poly, experience with network defense, vulnerability assessment, incident response, and SIEM tools such as Splunk and #J-18808-Ljbffr...
- ...delivers effects-as-a-service to national security partners across five domains and more... ...the whole stack: designing, building, and operating turnkey capabilities that give our... ...We are looking for a SIGINT Geospatial Analyst to combine SIGINT observables with geospatial...Full timeTemporary workWork at officeMonday to FridayFlexible hoursShift work
$72k - $90k
...globe. Through its Advanced Technology Center, a collaborative ecosystem of the world'... ...challenges. Position Overview: The Security Analyst supports customer engagements by helping... ...considered in lieu of a degree. A minimum of 3 years' progressive experience in a...Full timeRemote workShift work$87k - $148k
...that enable efficient, scalable, and risk-controlled operations. The position combines deep operational expertise, people... ...separate invitations for each role and will need to respond to each. Estimated Time Commitment: 3-5 minutes2. If you are eligible, you will be asked...Full timeLocal areaRemote work1 day per week- ...of criminal enterprises. EnProVera, owned and operated by government veterans with extensive backgrounds in Homeland Security, Law Enforcement, the Military, and the Intelligence Community, has a vacancy for a Data Analyst. In this role, you will be supporting the overall...Temporary workWork at officeLocal areaFlexible hours
- ...Canada. In Europe our operations are supported from Solothurn... ...Our Global Development Center is located in Mumbai,... ...in the way we respond to our clients, interact... ...experience as a business analyst or closely related experience... ...(ISMS) and CMMI Level 3 certified company....Work at office
$38.7 per hour
...WORKFORCE MANAGEMENT ANALYST (WFM / CONTACT CENTER) — REMOTE Location: Remote (U.S.)... ...plans, create schedules, and respond to ad hoc workforce planning requests... ...to required experience) 3+ years of experience in service center operations or scheduling/forecasting...Contract workLocal areaRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Operations Center (SOC) Tier 3 Analyst / Incident Responder. Be the first to apply!
- proposal analyst Baltimore, MD
- client delivery analyst Baltimore, MD
- transportation analyst Baltimore, MD
- growth analyst Baltimore, MD
- entry level program analyst Baltimore, MD
- development analyst Baltimore, MD
- merchandising analyst Baltimore, MD
- behavioral analyst Baltimore, MD
- category analyst Baltimore, MD
- analyst sales operations Baltimore, MD



