Senior SOC Analyst

KeenLogic

Merrifield (VA)

On-site

USD 120,000 - 160,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health/dental/vision benefits
PTO
401k
Life Insurance

Job summary

KeenLogic seeks a Senior SOC Analyst & Incident Responder to join the DEA-facing 24/7/365 Security Operations Center. The role includes advanced investigations, threat hunting, and operational leadership within enterprise IT, cloud, and OT environments.

The position is onsite in Merrifield, VA, with a 7 AM to 3 PM schedule and Fortune 500‑level benefits including health/dental/vision, PTO, 401k and life insurance.

Qualifications

  • Active Secret or Top Secret clearance is required.
  • Master’s degree with 8 years or Bachelor's degree with 11 years in Information Systems, Cybersecurity, or related field.
  • One of the following certifications or equivalents is required (examples listed in ad).

Responsibilities

  • Lead advanced incident detection, investigation, and analysis.
  • Coordinate and direct complex incident response activities with SOC, forensics, and engineering teams.
  • Mentor and train SOC analysts to improve investigative capabilities.
  • Develop and refine SOC processes, playbooks, and detection capabilities.
  • Perform threat intelligence collection, analysis, and dissemination.
  • Collaborate with stakeholders to strengthen cybersecurity posture.
  • Maintain documentation and reporting for SOC operations.

Skills

Clearance awareness
Mentoring & leadership
Incident response
Threat hunting

Education

Master’s degree + 8 years
Bachelor’s degree + 11 years

Tools

SIEM/SOAR platforms
Forensics tooling
Threat intelligence platforms

Job description

Senior SOC Analyst and Incident Responder

KeenLogic is seeking to hire a Senior SOC Analyst & Incident Responder to join our team at the Drug Enforcement Administration. All the duties listed support one or more of the following cybersecurity‑related functions; information security, SPAA, incident response, cyber security, insider threat, computer forensics, vulnerability assessment and management, network data capture, intrusion detection, log management, auditing, security incident and event management (SIEM), and penetration testing.

This is a full‑time position offering Fortune 500‑level health/dental/vision, PTO, 401k, and Life Insurance. This onsite role, with a daily schedule from 7 AM to 3 PM, based in Merrifield, VA.

Position Summary

The Senior SOC Analyst is a key member of the 24/7/365 Security Operations Center, which serves as the escalation point for advanced investigations, incident response, and proactive threat hunting. This role conducts higher‑level analysis than other analysts on the team. A senior SOC analyst performs deep forensic investigations, correlates multi‑source threat intelligence information, and guides containment and remediation strategies. The Senior SOC Analyst identifies and mitigates advanced threats across enterprise IT endpoints, cloud environments, and OT systems. They leverage frameworks like the MITRE ATT&CK framework and others to detect, disrupt, and prevent malicious activity from occurring in the enterprise environment.

They work closely with the SOC manager and leads. They mentor junior staff, assist to refine SOC processes, and ensures the organization maintains a strong cybersecurity posture. They collaborate with engineers, threat intelligence and forensics teams to enhance detection capabilities, improve incident response readiness, and deliver actionable security insights to leadership.

Required Qualifications
  • Active Secret or Top Secret clearance
  • Master’s degree and 8 years or Bachelor's degree and 11 years
    • Documented work experience performing any combination of Information System Security, Security Assessment & Authorization, Cybersecurity, Computer Forensics, or Insider Threat
  • One of the following required:
    • CBROPS
    • CFR
    • CompTIA: CySA+, Security + CE, CASP+CE
    • FITSP-O
    • SANS: GCFA, GCIA, GDSA, GICSP
    • CCNA‑Security, CCNP Security
    • CISSP (or associate), CCSP
    • CISA
    • SSCP
    • CND
Duties and Responsibilities
  1. Lead advanced incident detection, investigation, and analysis efforts.
    1. Correlate SIEM, EDR, IDS/IPS, and firewall data to identify and analyze potential incidents.
  2. Perform deep‑Dive investigations to determine root cause, scope, and impact of incidents.
    1. Apply MITRE ATT&CK and other frameworks for adversary TTP identification.
    2. Conduct kill‑chain and supply chain analysis to understand and counter threats.
  3. Coordinate and direct complex incident response activities.
    1. Guide preparation, identification, containment, eradication, and recovery actions in collaboration with SOC, forensics, and engineering teams.
    2. Serve as the primary escalation point for high‑impact or advanced incidents.
    3. Ensure incident handling aligns with established guidelines, response plans, and playbooks.
  4. Conduct proactive threat hunting to identify emerging risks.
    1. Analyze telemetry, logs, and behavioral patterns for indicators of compromise or attack.
    2. Hunt for advanced persistent threats and undiscovered vulnerabilities.
    3. Use advanced queries in SOC cybersecurity tools to detect anomalous or suspicious activity.
  5. Work with forensic teams to ensure proper forensic collection, preservation, and analysis of digital evidence.
    1. Coordinate with forensics teams to ensure chain‑of‑custody and evidence integrity.
    2. Extract and analyze relevant artifacts to support investigations and post‑incident reviews.
    3. Document and communicate forensic findings to stakeholders.
  6. Develop and enhance SOC processes, playbooks, and detection capabilities.
    1. Refine detection rules, alert thresholds, and automation workflows in SIEM/SOAR platforms and other cybersecurity tools.
    2. Create SOPs, knowledge base articles, and training materials for SOC staff.
    3. Recommend and guide implementation of new detection and analysis tools.
  7. Perform threat intelligence collection, analysis, and dissemination.
    1. Gather threat data from internal, classified, and open‑source intelligence feeds.
    2. Analyze and contextualize intelligence to produce actionable recommendations.
    3. Share relevant threat information with SOC, leadership, and partner teams.
  8. Mentor and train SOC analysts to improve investigative capabilities and analytical thought process.
    1. Provide real‑time guidance during active incidents.
    2. Conduct regular training sessions, tabletop exercises, and red/blue team drills.
    3. Validate analyst findings and provide feedback to designed to provoke thought, improve accuracy, and investigative thoroughness.
  9. Collaborate with stakeholders to strengthen overall cybersecurity posture.
    1. Work with engineering, IT, and cloud teams to address identified vulnerabilities.
    2. Participate in tool evaluations, recommending solutions that enhance SOC capabilities and identify capability overlap.
    3. Support internal coordination with DEA sections, divisions, and external entities.
  10. Maintain documentation and reporting for SOC operations.
    1. Record investigative steps, evidence, and incident timelines in case management systems.
    2. Generate incident reports, trend analyses, and post‑mortem summaries.
    3. Provide executive‑level briefings on security events and SOC performance.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SOC Analyst (Direct Hire Fortune 100CO)
Senior SOC Analyst (Direct Hire Fortune 100CO)

Confidential • Houston (TX)

Hybrid
USD 110,000 - 150,000
Senior SOC Analyst (Direct Hire EAD OKAY)
Senior SOC Analyst (Direct Hire EAD OKAY)

Confidential • United States

Hybrid
USD 120,000 - 180,000
Information Security Advisor
Information Security Advisor

NTT DATA, Inc. • Merrifield (VA)

On-site
USD 100,000 - 130,000
Senior Security Operations Analyst
Senior Security Operations Analyst

Prosegur Security USA, Inc • Lowell (MA), Northern (KY)

Hybrid
USD 90,000 - 140,000
Security Operations Center Technical Lead
Security Operations Center Technical Lead

Invictus International Consulting, LLC • Colorado Springs (CO)

On-site
USD 200,000 - 230,000
SOC Analyst 2
SOC Analyst 2

Mbi Llc • Harrisburg

On-site
USD 60,000 - 90,000
Security Operations Center Technical Lead
Security Operations Center Technical Lead

Invictus International Consulting, LLC. • Colorado Springs (CO)

On-site
USD 120,000 - 170,000
SOC Manager with BS Degree
SOC Manager with BS Degree

Acumenz Consulting • United States

Remote
USD 120,000 - 150,000
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

10xTalents • Washington

On-site
USD 80,000 - 110,000
Security Operations Center Technical Lead
Security Operations Center Technical Lead

Invictus International • Colorado Springs (CO)

On-site
USD 130,000 - 180,000