Tier 3 SOC Analyst (On-site, Washington, DC)
tecknomicAlexandria, VA
Tier 3 SOC Analyst (On-site, Washington, DC)
L6
tecknomicAlexandria, VA2 days ago
Industries
Computer Systems Design ServicesOther Computer Related ServicesOther Scientific and Technical Consulting ServicesThe DC Office of the Chief Technology Officer (OCTO) needs a Tier 3 SOC Analyst to provide advanced technical and analytical oversight of a SOC team monitoring, detecting, analyzing, and responding to cybersecurity incidents across the District’s infrastructure. This is the advanced escalation point above Tier 2: deep analysis, threat hunting, detection tuning, and incident response. 100% onsite in Washington, DC.
What you’ll do:
Serve as the advanced (Tier 3) escalation point: scrutinize and provide corrective analysis to cybersecurity events escalated from Tier 2 and escalate confirmed incidents to the Incident Response Lead Provide in-depth analysis and trending/correlation of large data sets (logs, events, alerts) across network devices and applications to troubleshoot incidents and recommend remediation Proactively threat-hunt through log, network, and system data to find undetected threats Tune security tools: develop and adjust detection rules, build response procedures, and reduce false positives Identify, verify, and ingest indicators of compromise and attack (IOCs, IOAs) into network security tools Quality-proof technical advisories and assessments; provide expert support to resolve confirmed incidents
What you need:
Bachelor’s degree in Cyber Security or related area (or equivalent experience)Minimum 5 years of operational experience as a cybersecurity analyst/engineer handling and coordinating incidents in critical environments In-depth understanding of current threats, attacks, and countermeasures (scanning, DDoS, phishing, ransomware, botnets, C2)In-depth hands-on experience analyzing and responding to incidents with SIEM, IDS/IPS, firewalls, NAC, DLP, DAM, content filtering, vulnerability scanning, and endpoint protection Strong knowledge of TCP/IP protocols, services, and networking; forensic analysis techniques for common operating systems 11 to 15 years implementing and operating IS technologies (firewalls, IDS/IPS, SIEM, antivirus, traffic analyzers, malware analysis), scripting/automation (Perl, Power Shell, Regex), and leading incident-response plans
Required skills:
Advanced SOC analysis and incident response (Tier 3 escalation, correlation, containment, eradication)SIEM-based detection and analysis, and SOC detection-rule tuning and false-positive reduction Proactive threat hunting and threat-intelligence analysis (IOCs, IOAs, threat-actor TTPs)Enterprise security technologies: IDS/IPS, firewalls, NAC, DLP, DAM, content filtering, endpoint protection, vulnerability scanning Network and protocol expertise (TCP/IP) and digital-forensics techniques Scripting and automation for security operations (Power Shell, Perl, Regex); SOP and runbook development
Apply now
Level
LeadL6
Location
Alexandria, VA
Occupation
Information Security Analysts
Industry
Computer Systems Design Services
Posted
2 days ago
To get sharper similar jobs, create your profile using the link below.