Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

OneMain Financial

Washington (District of Columbia)

On-site

USD 140,000 - 190,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

OneMain Financial seeks a senior cybersecurity professional to lead advanced investigations and drive the full incident response lifecycle across on‑premises and cloud environments. You will analyze Windows/Linux infrastructure, AD/AD CS, Microsoft Entra ID, and hybrid cloud platforms, delivering forensics, detections, and proactive threat hunting.

Applicants should have 8+ years of experience in security operations, deep knowledge of MITRE ATT&CK, and mastery of Elastic Security, Defender

Qualifications

  • Expert knowledge of SIEM, SOAR, EDR/XDR, NDR, IDS/IPS, and cloud security technologies.
  • Extensive hands-on experience with Elastic Security, Defender suites, and CrowdStrike.
  • Strong understanding of Windows/Linux, AD, cloud services, containers, and hybrid clouds.
  • Proven ability to lead complex enterprise incident investigations and perform advanced forensics.

Responsibilities

  • Lead advanced investigations involving ransomware, APTs, and data exfiltration.
  • Perform full lifecycle incident response including detection, triage, containment, and recovery.
  • Investigate attacks across on‑premises and cloud environments, AD, AWS, Azure, and SaaS platforms.
  • Perform forensic analysis of systems, endpoints, VMs, and network devices.
  • Analyze telemetry from EDR/XDR, SIEM, firewalls, proxies, and cloud logs.
  • Develop detections and SIEM correlation rules using ELK, KQL, SQL, PowerShell, and Python.
  • Conduct proactive threat hunting using MITRE ATT&CK and threat intelligence.
  • Provide technical leadership and mentoring to Tier 1 and Tier 2 analysts.
  • Produce technical reports detailing timelines, root cause, IOCs, IOAs, and recommendations.

Skills

Threat hunting
Incident response leadership
Technical reporting
Post-incident analysis

Education

Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent experience

Tools

ELK (Elastic Security)
CrowdStrike Falcon
Microsoft Defender XDR / Defender suite
KQL
SQL
PowerShell
Python
Bash

Job description

  • Lead advanced investigations involving ransomware, APTs, zero-day exploits, insider threats, credential theft, lateral movement, cloud compromise, on-premises systems, VDI, SaaS, API abuse, business email compromise, certificate abuse, and data exfiltration.
  • Perform full lifecycle incident response including detection, triage, investigation, containment, eradication, recovery, validation, root cause analysis, and post-incident review.
  • Investigate attacks spanning on-premises infrastructure, Windows and Linux servers, Active Directory, Active Directory Certificate Services (AD CS), Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS platforms, APIs, containers, Kubernetes, databases, enterprise applications, and hybrid cloud environments.
  • Perform forensic analysis of on-premises systems, endpoints, servers, virtual machines, VDI, cloud workloads, identity systems, SaaS applications, APIs, databases, and network devices.
  • Analyze telemetry from EDR/XDR, NDR, SIEM, firewalls, IDS/IPS, WAF, VPN, DNS, DHCP, proxy, email security, cloud audit logs, API gateways, identity providers, application logs, and operating system logs.
  • Develop detections and SIEM correlation rules using Elastic Security, KQL, ES|QL/EQL, SQL, PowerShell, and Python.
  • Conduct proactive threat hunting using MITRE ATT&CK, behavioral analytics, and threat intelligence.
  • Provide technical leadership and mentoring to Tier 1 and Tier 2 analysts.
  • Support management with reporting, including producing technical reports documenting attack timelines, root cause, IOCs, IOAs, TTPs, and recommendations.
Key Responsibilities
  • Lead advanced investigations involving ransomware, APTs, zero-day exploits, insider threats, credential theft, lateral movement, cloud compromise, on-premises systems, VDI, SaaS, API abuse, business email compromise, certificate abuse, and data exfiltration.
  • Perform full lifecycle incident response including detection, triage, investigation, containment, eradication, recovery, validation, root cause analysis, and post-incident review.
  • Investigate attacks spanning on-premises infrastructure, Windows and Linux servers, Active Directory, Active Directory Certificate Services (AD CS), Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS platforms, APIs, containers, Kubernetes, databases, enterprise applications, and hybrid cloud environments.
  • Perform forensic analysis of on-premises systems, endpoints, servers, virtual machines, VDI, cloud workloads, identity systems, SaaS applications, APIs, databases, and network devices.
  • Analyze telemetry from EDR/XDR, NDR, SIEM, firewalls, IDS/IPS, WAF, VPN, DNS, DHCP, proxy, email security, cloud audit logs, API gateways, identity providers, application logs, and operating system logs.
  • Develop detections and SIEM correlation rules using Elastic Security, KQL, ES|QL/EQL, SQL, PowerShell, and Python.
  • Conduct proactive threat hunting using MITRE ATT&CK, behavioral analytics, and threat intelligence.
  • Provide technical leadership and mentoring to Tier 1 and Tier 2 analysts.
  • Support management with reporting, including producing technical reports documenting attack timelines, root cause, IOCs, IOAs, TTPs, and recommendations.
Required Qualifications
  • Expert knowledge of SIEM, SOAR, EDR/XDR, NDR, IDS/IPS, WAF, firewalls, email security, web proxies, CASB, DLP, IAM, PAM, API security, and cloud-native security technologies.
  • Expert experience with Elastic Security (ELK), CrowdStrike Falcon, Microsoft Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud, and Defender for Cloud Apps.
  • Deep understanding of on-premises infrastructure including Windows Server, Linux, Active Directory, Active Directory Certificate Services (AD CS), VMware, Hyper‑V, storage, virtualization, networking, Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS, APIs, containers, Kubernetes, databases, and hybrid cloud architectures.
  • Expert knowledge of TCP/IP, DNS, DHCP, VPN, routing, switching, PKI, Kerberos, NTLM, OAuth, OIDC, SAML, JWT, and certificate‑based authentication.
  • Advanced proficiency investigating on‑premises systems, cloud environments, endpoints, servers, identity platforms, VDI, SaaS applications, APIs, databases, enterprise applications, and AD CS/PKI‑related attacks.
  • Expert proficiency with KQL, ES|QL/EQL, SQL, PowerShell, Python, and Bash.
  • Deep knowledge of MITRE ATT&CK, MITRE D3FEND, Cyber Kill Chain, NIST CSF, NIST 800‑61, OWASP Top 10, malware analysis, digital forensics, and attacker methodologies.
  • Minimum two certifications such as GCFA, GCFE, GCIH, GCIA, GREM, CISSP, SC‑200, SC‑100, AWS Certified Security – Specialty, or equivalent.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent experience.
Preferred Qualifications
  • Experience in financial services or another highly regulated industry.
  • Experience investigating enterprise incidents across Microsoft 365, Azure, AWS, Elastic, CrowdStrike, and hybrid environments.
  • Experience supporting DFIR engagements involving ransomware, nation‑state threats, insider threats, enterprise‑scale incidents, and Active Directory Certificate Services (AD CS) abuse.
Experience Requirements
  • Minimum 8 years of progressive cybersecurity experience.
  • Minimum 6 years of hands‑on Security Operations Center experience.
  • Minimum 4 years leading complex enterprise incident investigations.
  • Minimum 2 years performing advanced digital forensics, threat hunting, and detection engineering.
  • Proven experience independently investigating incidents from initial alert through full remediation across on‑premises infrastructure, enterprise networks, endpoints, identity platforms, Microsoft 365, Azure, AWS, VDI, SaaS applications, APIs, Elastic Security, hybrid cloud environments, and PKI/AD CS.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Analyst
Cybersecurity Analyst

EXOS • Indianapolis (IN)

On-site
USD 90,000 - 120,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
IT Security Operations Analyst
IT Security Operations Analyst

Blackstone Talent Group • San Francisco (CA)

On-site
USD 120,000 - 150,000
Sr. Network Analyst
Sr. Network Analyst

MY HR • Austin (TX)

On-site
USD 110,000 - 150,000
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000
Threat Management Specialist (Tier 2)
Threat Management Specialist (Tier 2)

PlanIT Group, LLC • Reston (VA)

On-site
USD 120,000 - 150,000
Incident Response Engineer - Cyber Defense
Incident Response Engineer - Cyber Defense

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Lead Cyber Incident Responder Tier 3
Lead Cyber Incident Responder Tier 3

Compunnel, Inc. • Charlotte (NC), Northern (KY)

Hybrid
USD 120,000 - 170,000
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Lockton • North Kansas City (MO)

On-site
USD 110,000 - 160,000
Senior Security Operations Analyst
Senior Security Operations Analyst

Prosegur Security USA, Inc • Lowell (MA), Northern (KY)

Hybrid
USD 90,000 - 140,000