SOC Analyst

Expression

Washington (District of Columbia)

On-site

USD 110,000 - 150,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

401k matching
PPO and HDHP medical/dental/vision
Education reimbursement up to $10,000/
Complimentary life insurance
Generous PTO and 11 holidays
Onsite gym facility at HQ in DC
Commuter Benefits Plan

Job summary

Expression is seeking a SOC Analyst to join our team in Washington, DC, onsite, to support the NTIA ISCOM Division. You will monitor, analyze, and respond to cyber threats to bolster federal network resilience and situational awareness.

The role covers Tier 1/2 operations, malware analysis, network forensics, threat hunting, and collaboration with cyber teams to improve detection content and SOC playbooks. Active Secret or Top Secret clearance is required.

Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or related field.
  • OR equivalent certifications (CompTIA Security+, CISSP, GCIH, GCIA).
  • Minimum of 4 years of experience in security operations, incident response, or cyber threat analysis.
  • Strong knowledge of SOC operations, incident detection, and response workflows.
  • Familiarity with malware analysis, network forensics, and packet-level inspection.
  • Excellent analytical, problem-solving, and communication skills.

Responsibilities

  • Monitor, detect, and analyze security threats, risks, and alerts using SOC tools, and initiate escalation as required.
  • Conduct cyber threat analysis and contribute to reports for program situational awareness.
  • Provide Tier 1 response to security incidents and support escalation to Tier 2 during high-volume or critical events.
  • Conduct functional incident response teams during shifts, ensuring accountability and effective resolution.
  • Conduct malware analysis (static and dynamic) and assess Indicators of Compromise (IOCs).
  • Perform network forensics and deep packet inspection to investigate intrusions.
  • Implement remediation strategies and support recovery activities after incidents.
  • Recommend process improvements and create new detection content to strengthen SOC operations.
  • Conduct proactive monthly threat hunts and provide reports to stakeholders.
  • Collaborate with cyber teams for incident escalation, coordinated responses, and SOC policy/procedure development.

Skills

SOC operations
Incident detection
Threat analysis
Communication skills
Problem solving
Team collaboration

Education

Bachelor’s degree in Cybersecurity/CS/IS
Certifications such as Security+, CISSP, GCIH, GCIA

Tools

SIEM platforms
IDS/IPS
Endpoint monitoring tools

Job description

SOC Analyst Expression is seeking a SOC Analyst to join our team in support of the National Telecommunications and Information Administration (NTIA) ISCOM Division. In this role, you will provide cyber threat monitoring, analysis, and incident response support that strengthens program situational awareness and ensures resilience of critical federal networks. You will support Tier 1 and Tier 2 SOC operations, contribute to SOC playbook development, and help mature cyber defense strategies in a mission-focused environment.

Location and Clearance Washington, DC – OnsiteActive Secret or Top Secret clearance required (U.S. Citizenship required)

Responsibilities
  • Monitor, detect, and analyze security threats, risks, and alerts using SOC tools, and initiate escalation as required.
  • Conduct cyber threat analysis and contribute to reports for program situational awareness.
  • Provide Tier 1 response to security incidents and support escalation to Tier 2 during high-volume or critical events.
  • Conduct functional incident response teams during shifts, ensuring accountability and effective resolution.
  • Conduct malware analysis (static and dynamic) and assess Indicators of Compromise (IOCs).
  • Perform network forensics and deep packet inspection to investigate intrusions.
  • Implement remediation strategies and support recovery activities after incidents.
  • Recommend process improvements and create new detection content to strengthen SOC operations.
  • Conduct proactive monthly threat hunts and provide reports to stakeholders.
  • Collaborate with cyber teams for incident escalation, coordinated responses, and SOC policy/procedure development.
Qualifications
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or related field;
  • OR equivalent certifications (CompTIA Security+, CISSP, GCIH, GCIA).
  • Minimum of 4 years of experience in security operations, incident response, or cyber threat analysis.
  • Strong knowledge of SOC operations, incident detection, and response workflows.
  • Familiarity with malware analysis, network forensics, and packet-level inspection.
  • Excellent analytical, problem-solving, and communication skills.
Preferred Experience
  • Advanced certifications such as CISSP, GCFA, GCIH, GCIA, or equivalent.
  • Prior experience supporting NTIA, Department of Commerce, or other federal civilian agencies.
  • Hands-on experience with SIEM platforms, IDS/IPS, and endpoint monitoring tools.
  • Familiarity with the NIST Cybersecurity Framework and Risk Management Framework (RMF).
  • Experience developing and maturing SOC playbooks, processes, and detection capabilities.
Benefits

Expression offers highly competitive salaries, performance-based incentives, and additional benefits, such as:

  • 401k matching
  • PPO and HDHP medical/dental/vision insurance
  • Education reimbursement up to $10,000/yr
  • Complimentary life insurance
  • Generous PTO and 11 days of holiday leave
  • Onsite gym facility at our HQ office in Washington DC
  • Commuter Benefits Plan
About Expression

Founded in 1997 and headquartered in Washington, DC, Expression provides data fusion, data analytics, AI/ML, software engineering, information technology, and electromagnetic spectrum management solutions to the U.S. Department of Defense, Department of State, and national security community.

Our culture emphasizes creating immediate and sustainable value for our clients through agile delivery of tailored solutions and constant engagement.

We were ranked #1 on the Washington Technology Fast 50 list of fastest-growing small business Government contractors and recognized as a Top 20 Big Data Solutions Provider by CIO Review.

At Expression, we ensure every team member has the tools and opportunities to grow while working with the newest technologies in the industry.

We celebrate milestones, accomplishments, promotions, and collaborative achievements that make our workplace engaging and rewarding.

Equal Opportunity Employer/Veterans/Disabled

Expression is an Equal Opportunity Employer. If you require a reasonable accommodation during the application or interview process, please submit your request to our Human Resources department through the application portal.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Advisor
Information Security Advisor

NTT DATA, Inc. • Merrifield (VA)

On-site
USD 100,000 - 130,000
Federal SOC Analyst: Threat Detection, IR & Forensics
Federal SOC Analyst: Threat Detection, IR & Forensics

Expression • Washington

On-site
USD 110,000 - 150,000
401k matching
PPO and HDHP medical/dental/vision
Education reimbursement up to $10,000/
+4
SOC Analyst
SOC Analyst

Tactibit • Suitland (MD)

On-site
USD 85,000 - 110,000
SOC Analyst
SOC Analyst

NTG • Alexandria (VA)

On-site
USD 85,000 - 125,000
SOC Analyst - Tier 1
SOC Analyst - Tier 1

Evans & Chambers • Maryland

On-site
USD 88,000 - 118,000
Senior SOC Analyst at NTT DATA, Inc. Merrifield, VA
Senior SOC Analyst at NTT DATA, Inc. Merrifield, VA

Dan Cummins Ford Lincoln • Merrifield (VA)

On-site
USD 140,000 - 180,000
SOC Analyst - Tier 1
SOC Analyst - Tier 1

Evans & Chambers • Fort Meade (MD)

On-site
USD 88,000 - 118,000
SOC Analyst
SOC Analyst

DMI (Digital Management, Inc.) • Crownsville (MD)

On-site
USD 70,000 - 100,000
SOC Analyst
SOC Analyst

Gridiron IT • Huntsville (AL)

On-site
USD 100,000 - 115,000
Tier 3 Cybersecurity Analyst
Tier 3 Cybersecurity Analyst

ActioNet • Rockville (MD)

On-site
USD 130,000 - 170,000
Medical Insurance
Vision Insurance
Life/AD&D Insurance
+7