SOC Analyst IV

ecsfederal

Virginia (MN)

Hybrid

USD 120,000 - 140,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Everforth ECS is seeking a SOC Analyst IV near the National Capital Region to join a premier, enterprise-scale cybersecurity program for a major federal civilian agency.

The role operates at Tier III, leading complex investigations, mentoring junior analysts, and driving playbooks and detection logic improvements within a 24x7 SOC environment.

Qualifications

  • U.S. Citizenship required.
  • 6+ years of SOC experience including Tier III incident response and forensic analysis.
  • Remote but within close proximity to the NCR.
  • Active Public Trust 6c clearance, or ability to obtain one.
  • At least one of GCIA, CEH, or CompTIA Security+ certifications.
  • Hands-on experience with SIEM platforms and endpoint telemetry analysis in federal/enterprise environments.
  • Strong experience with operating systems, networking fundamentals, and AWS native security capabilities.
  • Deep understanding of NIST SP 800-61 incident response framework and its application in tiered SOCs.
  • Experience developing incident response playbooks, SOPs, and lessons-learned docs.
  • Proven ability to lead shift handovers and maintain clear operational documentation.
  • Strong communication, written and verbal skills for technical and executive audiences.

Responsibilities

  • Provide Tier III support for SIEM alert triage, forensics, and escalation.
  • Maintain situational awareness across SOC tools and telemetry sources.
  • Lead shift handovers with thorough documentation.
  • Develop and improve SOPs and incident response playbooks.
  • Support Red Team and Purple Team exercises to validate coverage.
  • Apply MITRE ATT&CK to map TTPs during investigations.
  • Conduct in-depth forensic analysis of endpoint, network, and cloud telemetry.
  • Document and communicate across stages of the NIST IR lifecycle.
  • Mentor Tier I-II SOC analysts to raise team capability.
  • Collaborate with threat hunting, CTI, and security engineering teams.
  • Produce high-quality incident reports and shift logs.

Skills

SOC experience
Tier III
forensic analysis
incident response
documentation
communication

Education

GCIA certification
CEH
CompTIA Security+
Public Trust 6c
U.S. Citizenship

Tools

SIEM platforms
Endpoint telemetry
AWS security

Job description

Everforth ECS is seeking a SOC Analyst IV who lives in close proximity to the National Capital Region (NCR) to join a premier, enterprise-scale cybersecurity program supporting a major federal civilian agency.

Please Note: This position is contingent upon contract award.

Salary Range: $120,000 - $140,000

This flagship initiative unifies 24x7x365 Security Operations (SOC), proactive threat hunting, and advanced Security Engineering and Architecture into a cohesive defensive mission. As a senior technical contributor on this program, you will drive the protection of highly sensitive, national-level financial, and personally identifiable information (PII). You will be at the forefront of modernizing the agency's cyber posture, implementing advanced automation, and ensuring continuous operational resilience across a massive, highly complex federal IT enterprise.

As a SOC Analyst IV, you will operate at the Tier III level, serving as one of the most technically advanced analysts on the team and a cornerstone of the SOC's detection, triage, and response capability. Working alongside the SOC Manager, threat hunting teams, and security engineers, you will lead the most complex investigations, mentor junior analysts, and contribute directly to the continuous improvement of the SOC's playbooks, detection logic, and operational procedures. When the most sophisticated threats emerge, you will be the analyst the team turns to for deep technical expertise, sound judgment, and decisive action.

Position Responsibilities:
  • Provide Tier III support for SIEM alert triage, forensic analysis, and escalation, handling the most complex and high-priority security events within the SOC environment.
  • Maintain situational awareness across all SOC tools and telemetry sources, ensuring continuous visibility into the agency's security posture.
  • Lead shift handovers with clear, thorough documentation, ensuring seamless operational continuity across all SOC shifts.
  • Contribute to the development, review, and ongoing improvement of standard operating procedures (SOPs) and incident response playbooks to ensure they remain current, accurate, and operationally effective.
  • Support Red Team and Purple Team exercises to validate detection coverage, improve response procedures, and identify gaps in the SOC's defensive capabilities.
  • Apply the MITRE ATT&CK framework to map adversary tactics, techniques, and procedures (TTPs) during investigations, turning fragmented alerts into clear and actionable threat narratives.
  • Conduct in-depth forensic analysis of endpoint, network, and cloud telemetry to support incident investigations and root cause analysis activities.
  • Support and contribute to the four phases of the NIST SP 800-61 incident response lifecycle, Preparation, Detection and Analysis, Containment/Eradication/Recovery, and Post-Incident Activity, ensuring thorough documentation and stakeholder communication at each stage.
  • Mentor and provide technical guidance to Tier I and Tier II SOC analysts, supporting their professional development and improving overall team capability.
  • Collaborate with threat hunting, CTI, and security engineering teams to operationalize new detection logic and ensure the SOC benefits from the latest intelligence.
  • Produce high-quality incident reports, shift logs, and technical documentation for both technical teams and senior government officials.

Contribute to detection engineering and automation initiatives to reduce manual workload and improve analyst efficiency across the SOC.

  • U.S. Citizenship required.
  • 6+ years of SOC experience, with demonstrated expertise in Tier III incident response, forensic analysis, and SIEM operations.
  • Remote but within close proximity to the NCR.
  • Active Public Trust 6c clearance, or the ability to obtain and maintain one.
  • At least one of the following certifications: GCIA, CEH, or CompTIA Security+.
  • Hands-on experience with SIEM platforms and endpoint telemetry analysis in a federal or enterprise environment.
  • Strong experience with operating systems, networking fundamentals, and AWS native security capabilities.
  • Deep understanding of the NIST SP 800-61 incident response framework and its practical application within a tiered SOC environment.
  • Demonstrated ability to apply the MITRE ATT&CK framework to real-world incident investigations and detection improvement activities.
  • Experience contributing to or developing incident response playbooks, SOPs, and lessons-learned documentation.
  • Proven ability to lead shift handovers and maintain clear, accurate operational documentation in a 24x7x365 environment.
  • Strong written and verbal communication skills, with the ability to translate complex technical findings into actionable language for both technical and executive audiences.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Incident Detection/Response Manager (SOC Manager)
Incident Detection/Response Manager (SOC Manager)

ecsfederal • Virginia (MN)

Hybrid
USD 140,000 - 160,000
SOC Analyst
SOC Analyst

Tactibit • Suitland (MD)

On-site
USD 85,000 - 110,000
SOC Analyst
SOC Analyst

Tactibit Technologies LLC. • Suitland (MD), Northern (KY)

Hybrid
USD 95,000 - 125,000
Soc Tier 3 Analyst
Soc Tier 3 Analyst

Global Alliant Inc • Crownsville (MD)

Hybrid
USD 130,000 - 190,000
IT SOC Engineer I
IT SOC Engineer I

ecsfederal • Virginia (MN)

Hybrid
USD 100,000 - 120,000
Security Operations Center Analyst
Security Operations Center Analyst

Oxford Global Resources • Virginia (MN)

On-site
USD 120,000 - 180,000
Senior SOC Analyst (Direct Hire EAD OKAY)
Senior SOC Analyst (Direct Hire EAD OKAY)

Confidential • United States

Hybrid
USD 120,000 - 180,000
SOC Analyst I
SOC Analyst I

SOClogix, Inc. • Catonsville (MD)

On-site
USD 55,000 - 75,000
Health insurance
Dental insurance
Vision insurance
+6
Senior SOC Analyst
Senior SOC Analyst

KeenLogic • Merrifield (VA)

On-site
USD 120,000 - 160,000
Health/dental/vision benefits
PTO
401k
+1
Senior SOC Analyst (Direct Hire Fortune 100CO)
Senior SOC Analyst (Direct Hire Fortune 100CO)

Confidential • Houston (TX)

Hybrid
USD 110,000 - 150,000