Senior SOC Incident Response & Threat Hunter

OneMain Financial

Washington (District of Columbia)

On-site

USD 140,000 - 190,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

OneMain Financial seeks a senior cybersecurity professional to lead advanced investigations and drive the full incident response lifecycle across on‑premises and cloud environments. You will analyze Windows/Linux infrastructure, AD/AD CS, Microsoft Entra ID, and hybrid cloud platforms, delivering forensics, detections, and proactive threat hunting.

Applicants should have 8+ years of experience in security operations, deep knowledge of MITRE ATT&CK, and mastery of Elastic Security, Defender

Qualifications

  • Expert knowledge of SIEM, SOAR, EDR/XDR, NDR, IDS/IPS, and cloud security technologies.
  • Extensive hands-on experience with Elastic Security, Defender suites, and CrowdStrike.
  • Strong understanding of Windows/Linux, AD, cloud services, containers, and hybrid clouds.
  • Proven ability to lead complex enterprise incident investigations and perform advanced forensics.

Responsibilities

  • Lead advanced investigations involving ransomware, APTs, and data exfiltration.
  • Perform full lifecycle incident response including detection, triage, containment, and recovery.
  • Investigate attacks across on‑premises and cloud environments, AD, AWS, Azure, and SaaS platforms.
  • Perform forensic analysis of systems, endpoints, VMs, and network devices.
  • Analyze telemetry from EDR/XDR, SIEM, firewalls, proxies, and cloud logs.
  • Develop detections and SIEM correlation rules using ELK, KQL, SQL, PowerShell, and Python.
  • Conduct proactive threat hunting using MITRE ATT&CK and threat intelligence.
  • Provide technical leadership and mentoring to Tier 1 and Tier 2 analysts.
  • Produce technical reports detailing timelines, root cause, IOCs, IOAs, and recommendations.

Skills

Threat hunting
Incident response leadership
Technical reporting
Post-incident analysis

Education

Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent experience

Tools

ELK (Elastic Security)
CrowdStrike Falcon
Microsoft Defender XDR / Defender suite
KQL
SQL
PowerShell
Python
Bash

Job description

OneMain Financial seeks a senior cybersecurity professional to lead advanced investigations and drive the full incident response lifecycle across on‑premises and cloud environments. You will analyze Windows/Linux infrastructure, AD/AD CS, Microsoft Entra ID, and hybrid cloud platforms, delivering forensics, detections, and proactive threat hunting.

Applicants should have 8+ years of experience in security operations, deep knowledge of MITRE ATT&CK, and mastery of Elastic Security, Defender

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SOC Threat Hunter & Incident Response Engineer
Senior SOC Threat Hunter & Incident Response Engineer

Cetera Financial Group • Dallas (TX)

On-site
USD 90,000 - 130,000
Health insurance
Mental health benefits
PTO & holidays
+1
Senior SOC Analyst - Lead Incident Response & Threat Hunting
Senior SOC Analyst - Lead Incident Response & Threat Hunting

Confidential • United States

Hybrid
USD 120,000 - 180,000
Senior SOC Analyst: Lead Incident Response & Threat Hunting
Senior SOC Analyst: Lead Incident Response & Threat Hunting

Confidential • Houston (TX)

Hybrid
USD 110,000 - 150,000
Senior SOC Analyst: Threat Hunting & Incident Response
Senior SOC Analyst: Threat Hunting & Incident Response

Logicalis GmbH • Beachwood (OH)

On-site
USD 78,000 - 100,000
Senior Threat Hunter — Lead MITRE-Driven Hunt & SOC
Senior Threat Hunter — Lead MITRE-Driven Hunt & SOC

Peraton • Chandler (AZ)

On-site
USD 104,000 - 166,000
Senior SOC Analyst
Senior SOC Analyst

Soni • Philadelphia

On-site
USD 90,000 - 120,000
Senior SOC Lead: Threat Hunting & IR (Remote)
Senior SOC Lead: Threat Hunting & IR (Remote)

SPS Commerce • Minneapolis (MN)

Hybrid
USD 108,000 - 140,000
SOC Threat Hunter & Incident Response Engineer
SOC Threat Hunter & Incident Response Engineer

Cyberdata Technologies, Inc. • Herndon (VA)

On-site
USD 80,000 - 120,000
Sr SOC Analyst
Sr SOC Analyst

Jobgether • United States

On-site
USD 120,000 - 150,000
Professional growth
AI-driven tools
Collaborative team
+1
Hybrid Senior Cyber Defense Analyst - Threat Hunting & IR
Hybrid Senior Cyber Defense Analyst - Threat Hunting & IR

SMBC Group • Charlotte (NC)

Hybrid
USD 120,000 - 150,000