SOC Analyst Tier 3

JFL Consulting LLC

Springfield (VA)

On-site

USD 140,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Employer-paid medical, dental, vision
FSA (healthcare & dependent care)
Commuter FSA
Life insurance
Short-term disability
Long-term disability
401(k) with immediate vesting
Generous PTO (15 vacation, 5 sick, 2 0
11 holidays
Certification reimbursement
Professional development funding
Company-provided access to online学习

Job summary

JFL Consulting, LLC is seeking a SOC Analyst Tier 3 and Incident Responder in Springfield, VA. The role leads complex security incident response, performs threat hunting, and provides deep technical analysis within the SOC operations center.

The ideal candidate has 5+ years in SOC/security, strong SIEM and PCAP/memory forensics skills, and is capable of coordinating with Tier 4 resources. This is a demanding senior role with night/weekend on-call shifts.

Qualifications

  • 5+ years in SOC, threat hunting or incident response.
  • Bachelor's degree or 4 additional years of relevant experience in lieu of degree.
  • Demonstrated incident response experience with containment and recovery.
  • Proficiency with SIEM platforms and query languages (SPL, KQL).
  • Experience with PCAP analysis and memory forensics.

Responsibilities

  • Provide Tier 3 escalation and resolution for the most complex incidents.
  • Lead response to Priority 1 and complex Priority 2 security incidents.
  • Conduct proactive threat hunting to identify bypassed detections.
  • Perform PCAP, log analysis, memory forensics, and malware triage.
  • Contain threats and coordinate remediation with engineers.
  • Produce incident reports and maintain threat hunting playbooks.
  • Serve as on-call incident responder and brief senior leadership.

Skills

SOC operations
Threat hunting
Incident response
SIEM
PCAP analysis
Memory forensics

Education

Bachelor's degree in Cyber Security/IT/CSE/InfoSec

Tools

Wireshark
NetworkMiner
EDR tools
Memory analysis tools

Job description

About this position

Description:

Job Title: SOC Analyst Tier 3

Place of Performance: Springfield, VA

Experience Level: 5-8 years of experience

About JFL Consulting:

With more than 20 years of securing some of the U.S. Department of Defense and the Intelligence Community’s most critical networks, JFL Consulting, LLC provides advanced network security solutions to a range of US Government and US commercial clients.

Our cybersecurity operators are experts at assessing and defending mission-critical data and the networks that facilitate their operation. We are focused on delivering advanced products and industry best practices that meet each customer’s unique requirements. Visit www.jflconsulting.com

What We Offer
  • Salary: $140k- $180k
  • 100% employer-paid medical, dental, and vision premiums for employees and dependents
  • Flexible Spending Accounts (healthcare, dependent care, and commuter)
  • Life insurance, short-term disability and long-term disability
  • 401(k) with immediate vesting of company contribution
  • Generous PTO policy (15 vacation, 5 sick, 2 personal days, 11 holidays)
  • We support your growth through certification reimbursement, dedicated professional development funding, and company-provided access to online learning platforms
Job Overview

We’re looking for a SOC Analyst Tier 3 and Incident Responder, a senior analyst role in the SOC. This role leads the response to confirmed security incidents, conducts threat hunting operations, and provides deep technical analysis capability in the operations center. Tier 3/IR analysts are activated for severe incidents and are the primary interface to the Tier 4 SME and external response resources when needed.

Key Responsibilities
  • Provide Tier 3 escalation and resolution for the most complex incidents and outages escalating to the Tier 4 SME as needed with appropriate documentation
  • Lead the response to Priority 1 and complex Priority 2 security incidents from detection through remediation
  • Conduct proactive threat hunting operations to identify threats that have bypassed automated detection
  • Perform advanced PCAP analysis, log analysis, memory forensics, and malware triage
  • Contain and eradicate threats while coordinating with engineers for isolation and remediation
  • Produce formal incident response reports for Priority 1 and Priority 2 incidents
  • Develop and maintain threat hunting TTPs and playbooks
  • Build new detection use cases from threat hunting findings and submit to SIEM engineer
  • Serve as on‑call incident responder
  • Brief senior leadership during active high priority incidents
  • Mentor Tier 1 and 2 analysts in investigation techniques and escalation decision-making
  • Manage and own the SOC Event log for all events during the shifts
  • Maintain situational awareness of the threat landscape and active campaigns
  • Participate briefings and training sessions
Required Qualifications
  • 5+ years of SOC, threat hunting or incident response type experience
  • Bachelor’s degree in Cyber Security, Information Technology, Computer Science, Information Security, or related field. In lieu of degree, four additional years of experience in a NOC, SOC, IT security, or network engineering role
  • Two of the following certifications, equivalent or better: Sec+, CYSA+, GCIH, SecX, CEH, GCIA, GSOC, CISSP
  • Demonstrated hands‑on incident response experience including containment, eradication, and recovery
  • Proficiency with SIEM platforms and log analysis
  • Proficiency with SIEM query languages — SPL, KQL, or equivalent
  • Proficiency with PCAP analysis tools (Wireshark, NetworkMiner, or equivalent)
  • Experience with EDR, endpoint forensics, memory analysis, and network forensics tools
  • Deep understanding of attacker TTPs, kill chain methodology, and MITRE ATT&CK
  • Ability to work shifts including nights, weekends, and holidays on rotating shift schedule
Preferred Qualifications
  • GCFA or GCFE certification or other forensic certifications
  • Active Secret clearance preferred but not required
  • Experience with threat hunting frameworks and platforms
  • Reverse engineering experience (IDA Pro, Ghidra)
  • Prior experience on a DFIR team or incident response retainer
  • Experience with malware analysis (static and dynamic)

JFL Consulting, LLC is an Equal Opportunity Employer.

We do not discriminate against any applicant for employment on any legally recognized basis including, but not limited to: race, religion or creed, color, national origin, sex, age, disability, marital status, sexual orientation, genetic information, veteran status, status with regard to public assistance or any other protected class under federal, state or local statute. It is also the policy of JFL Consulting, LLC to provide reasonable accommodations for qualified individuals with disabilities.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Analyst Tier 3
SOC Analyst Tier 3

JFL CONSULTING, LLC • Springfield (VA)

On-site
USD 140,000 - 180,000
Salary: $140k- $180k
100% employer-paid medical, dental, &
SOC Lead
SOC Lead

JFL CONSULTING, LLC • Springfield (VA)

On-site
USD 170,000 - 220,000
Health insurance
Dental & vision
FSAs
+5
Program Manager (Ops Center Manager for SOC & NOC)
Program Manager (Ops Center Manager for SOC & NOC)

JFL CONSULTING, LLC • Springfield (VA)

On-site
USD 180,000 - 250,000
Program Manager (Ops Center Manager for SOC & NOC)
Program Manager (Ops Center Manager for SOC & NOC)

Socket.dev • Springfield (VA)

On-site
USD 180,000 - 250,000
Premium benefits
Health insurance
401(k)
+2
NOC Lead
NOC Lead

JFL Consulting, LLC • Springfield (VA)

On-site
USD 170,000 - 220,000
Health insurance
FSA accounts
Life insurance + disability
+2
NOC Engineer Tier 3
NOC Engineer Tier 3

JFL CONSULTING, LLC • Springfield (VA)

On-site
USD 140,000 - 180,000
Health insurance
Dental and vision coverage paid by the
401(k) with immediate vesting
+2
SOC Analyst Tier 2 (Q Clearance)
SOC Analyst Tier 2 (Q Clearance)

ShorePoint, LLC • North Las Vegas (NV)

On-site
USD 80,000 - 100,000
18 days of PTO
11 holidays
85% of insurance premium covered
+2
Journeyman SOC Analyst (Q Clearance)
Journeyman SOC Analyst (Q Clearance)

ShorePoint, LLC • Las Vegas (NV)

On-site
USD 90,000 - 130,000
PTO 18 days
Health insurance
401k plan
+2
Senior SOC Analyst & Incident Response Lead
Senior SOC Analyst & Incident Response Lead

JFL Consulting LLC • Springfield (VA)

On-site
USD 140,000 - 180,000
Employer-paid medical, dental, vision
FSA (healthcare & dependent care)
Commuter FSA
+9
Tier 3 Cybersecurity Analyst
Tier 3 Cybersecurity Analyst

ActioNet, Inc. • Rockville (MD)

On-site
USD 130,000 - 170,000
Medical Insurance
Vision Insurance
Life and AD&D Insurance
+8