Federal SOC Analyst: Threat Detection, IR & Forensics

Expression

Washington (District of Columbia)

On-site

USD 110,000 - 150,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

401k matching
PPO and HDHP medical/dental/vision
Education reimbursement up to $10,000/
Complimentary life insurance
Generous PTO and 11 holidays
Onsite gym facility at HQ in DC
Commuter Benefits Plan

Job summary

Expression is seeking a SOC Analyst to join our team in Washington, DC, onsite, to support the NTIA ISCOM Division. You will monitor, analyze, and respond to cyber threats to bolster federal network resilience and situational awareness.

The role covers Tier 1/2 operations, malware analysis, network forensics, threat hunting, and collaboration with cyber teams to improve detection content and SOC playbooks. Active Secret or Top Secret clearance is required.

Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or related field.
  • OR equivalent certifications (CompTIA Security+, CISSP, GCIH, GCIA).
  • Minimum of 4 years of experience in security operations, incident response, or cyber threat analysis.
  • Strong knowledge of SOC operations, incident detection, and response workflows.
  • Familiarity with malware analysis, network forensics, and packet-level inspection.
  • Excellent analytical, problem-solving, and communication skills.

Responsibilities

  • Monitor, detect, and analyze security threats, risks, and alerts using SOC tools, and initiate escalation as required.
  • Conduct cyber threat analysis and contribute to reports for program situational awareness.
  • Provide Tier 1 response to security incidents and support escalation to Tier 2 during high-volume or critical events.
  • Conduct functional incident response teams during shifts, ensuring accountability and effective resolution.
  • Conduct malware analysis (static and dynamic) and assess Indicators of Compromise (IOCs).
  • Perform network forensics and deep packet inspection to investigate intrusions.
  • Implement remediation strategies and support recovery activities after incidents.
  • Recommend process improvements and create new detection content to strengthen SOC operations.
  • Conduct proactive monthly threat hunts and provide reports to stakeholders.
  • Collaborate with cyber teams for incident escalation, coordinated responses, and SOC policy/procedure development.

Skills

SOC operations
Incident detection
Threat analysis
Communication skills
Problem solving
Team collaboration

Education

Bachelor’s degree in Cybersecurity/CS/IS
Certifications such as Security+, CISSP, GCIH, GCIA

Tools

SIEM platforms
IDS/IPS
Endpoint monitoring tools

Job description

Expression is seeking a SOC Analyst to join our team in Washington, DC, onsite, to support the NTIA ISCOM Division. You will monitor, analyze, and respond to cyber threats to bolster federal network resilience and situational awareness.

The role covers Tier 1/2 operations, malware analysis, network forensics, threat hunting, and collaboration with cyber teams to improve detection content and SOC playbooks. Active Secret or Top Secret clearance is required.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Analyst
SOC Analyst

Expression • Washington

On-site
USD 110,000 - 150,000
401k matching
PPO and HDHP medical/dental/vision
Education reimbursement up to $10,000/
+4
Onsite SOC Analyst – Secret/TS Clearance
Onsite SOC Analyst – Secret/TS Clearance

Socket.dev • Arlington (VA)

On-site
USD 100,000 - 150,000
Senior SOC Analyst: Threat Detection & Incident Response
Senior SOC Analyst: Threat Detection & Incident Response

ASM Research, An Accenture Federal Services Company • Fairfax (VA)

On-site
USD 100,000 - 120,000
Senior Cybersecurity Analyst: Threat Hunting & IR Lead
Senior Cybersecurity Analyst: Threat Hunting & IR Lead

ActioNet, Inc. • Rockville (MD)

On-site
USD 130,000 - 170,000
Medical Insurance
Vision Insurance
Life and AD&D Insurance
+8
SOC Operations Analyst: Real-Time Cyber Defense & Forensics
SOC Operations Analyst: Real-Time Cyber Defense & Forensics

Open Systems Technologies Corporation • Huntsville (AL)

On-site
USD 90,000 - 130,000
3 weeks paid time off
2 weeks Holiday pay
Medical/dental/vision coverage
+5
Senior SOC Ops Analyst: Incident Response & Forensics
Senior SOC Ops Analyst: Incident Response & Forensics

Peraton • Warrenton (VA)

On-site
USD 86,000 - 138,000
Senior SOC Analyst & Threat Hunter
Senior SOC Analyst & Threat Hunter

Dan Cummins Ford Lincoln • Merrifield (VA)

On-site
USD 140,000 - 180,000
SOC Analyst - Incident Response & Threat Hunting
SOC Analyst - Incident Response & Threat Hunting

Leidos • Alexandria (VA)

On-site
USD 87,000 - 158,000
Competitive compensation
Health and Wellness programs
Retirement benefits
Strategic SOC Analyst: Threat Hunting & Incident Response
Strategic SOC Analyst: Threat Hunting & Incident Response

Everwatch • Corridor North (MD)

On-site
USD 79,000 - 93,000
SOC Analyst: Incident Detection & Response Lead
SOC Analyst: Incident Detection & Response Lead

KeenLogic • Fairfax (CA)

On-site
USD 100,000 - 130,000
Health benefits
PTO
401(k)
+1