Tier 3 SOC Analyst

Gointellects Inc.

Washington (District of Columbia)

On-site

USD 110,000 - 150,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Gointellects Inc. seeks a Tier 3 SOC Analyst for a long-term Government contract in Washington, DC. You will provide advanced escalation support, oversee a SOC team, and coordinate incident detection, analysis, remediation, and reporting.

The ideal candidate has extensive experience with SIEM, IDS/IPS, firewalls, and threat intel; strong communication and coordinating skills are essential to operate in a high-pressure government environment.

Qualifications

  • Bachelor's degree in Cyber Security or related field with 5+ years of incident response experience.
  • Deep understanding of threats, attacks and countermeasures across networks and systems.
  • Experience with SIEM, IDS/IPS, firewalls, NAC, DLP and related security tools.
  • Strong communication and customer service skills; able to work under pressure.
  • Knowledge of TCP/IP protocols and networking fundamentals.
  • Experience with threat intel from open-source sources.

Responsibilities

  • Analyze escalated cybersecurity events and coordinate with Tier 2 and Incident Response Lead.
  • Trend and correlate large datasets to identify incidents and recommend remediation.
  • Identify undetected threats by proactive log, network, and system analysis.
  • Tune security tools and develop response procedures to reduce false positives.
  • Ingest indicators of compromise and IOAs into security tools.
  • Prepare advisories and coordinate incident response with technical teams.
  • Develop SOPs and Runbooks for SOC Analysts.
  • Respond to technical requests via phone and other channels.

Skills

Communication skills
Interpersonal skills
Organizational skills
Customer service skills
Attention to detail
Time management
Threat intelligence

Education

Bachelor's degree in Cyber Security or related field
Bachelor's degree in Information Technology or related field
SANS GCIA/GCED/GPEN/GCIH or similar certification

Tools

SIEM
IDS/IPS
Firewalls
NAC
DLP
DAM
Web filtering
Email filtering
Vulnerability scanners
Endpoint protection

Job description

Title

Tier 3 SOC Analyst-Long-Term Contract (Government) Position Title: Tier 3 SOC Analyst

Worksite Address

Washington, DC

Interviews

Webcam Only

Short Description

Monitoring, detecting, analyzing, remediating, and reporting on Cyber events and incidents impacting the tech infrastructure of the District of Columbia. Serves as advanced escalation point.

Complete Description

The SOC Analyst - Tier 3 is cybersecurity technical resource responsible for providing technical analytical oversight a team of SOC Analysts to monitor, detect, analyze, remediate, and report on cybersecurity events and incidents impacting the technology infrastructure of the Government of the District of Columbia. The ideal candidate will have an advanced technical background with significant experience in an enterprise successfully leading a SOC team or unit responsible for analysis and correlation of cybersecurity event, log, and alert data. The candidate will be skilled in understanding, recognition, and root-cause detection of cybersecurity exploits, vulnerabilities, and intrusions in host and network-based systems.

SPECIFIC TASKS
  • Utilize advanced technical background and experience in information technology and incident response handling to scrutinize and provide corrective analysis to escalated cybersecurity events from Tier 2 analysts—distinguishing these events from benign activities, and escalating confirmed incidents to the Incident Response Lead.
  • Provide in-depth cybersecurity analysis, and trending/correlation of large data-sets such as logs, event data, and alerts from diverse network devices and applications within the enterprise to identify and troubleshoot specific cybersecurity incidents, and make sound technical recommendations that enable expeditious remediation.
  • Proactively search through log, network, and system data to find and identify undetected threats.
  • Support security tool/application tuning engagements with analysts and engineers to develop/adjust rules and analyze/develop related response procedures, and reduce false-positives from alerting.
  • Identify, verify, and ingest indicators of compromise and attack (IOC’s, IOA’s) (e.g., malicious IPs/URLs, etc.) into network security tools/applications to protect the Government of the District of Columbia network.
  • Quality-proof technical advisories and assessments prior to release from SOC.
  • Coordinate with and provide expert technical support to enterprise-wide technicians and staff to resolve confirmed incidents.
  • Report common and repeat problems, observed via trend analysis, to SOC management and propose process and technical improvements to improve the effectiveness and efficiency of alert notification and incident handling.
  • Formulate and coordinate technical best-practice SOPs and Runbooks for SOC Analysts.
  • Respond to inbound requests via phone and other electronic means for technical assistance, and resolve problems independently. Coordinate escalations with Incident Response Lead and collaborate with internal technology teams to ensure timely resolution of issues.
MINIMUM QUALIFICATIONS
  • Bachelor's Degree in Cyber Security or related area with minimum Five years of demonstrated operational experience as a cybersecurity analyst/engineer handling and coordinating cybersecurity incidents and response in critical environments, and/or equivalent knowledge in areas such as; technical incident handling and analysis, intrusion detection, log analysis, penetration testing, and vulnerability management.
  • In-depth understanding of current cybersecurity threats, attacks and countermeasures for adversarial activities such as network probing and scanning, distributed denial of service (DDoS), phishing, ransomware, botnets, command and control (C2) activity, etc.
  • In-depth hands-on experience analyzing and responding to security events and incidents with most of the following technologies and/or techniques; leading security information and event management (SIEM) technologies, intrusion detection/prevention systems (IDS/IPS), network- and host-based firewalls, network access control (NAC), data leak protection (DLP), database activity monitoring (DAM), web and email content filtering, vulnerability scanning tools, endpoint protection, secure coding, etc.
  • Strong communication, interpersonal, organizational, oral, and customer service skills.
  • Strong knowledge of TCP/IP protocols, services, and networking.
  • Knowledge of forensic analysis techniques for common operating systems.
  • Adept at proactive search, solicitation, and detailed analysis of threat intelligence (e.g., exploits, IOCs, hacking tools, vulnerabilities, threat actor TTPs) derived from open-source resources and external entities, to identify cybersecurity threats and derive countermeasures, not previously ingested into network security tools/applications, to apply to protect the Government of the District of Columbia network.
  • Excellent ability to multi-task, prioritize, and manage time and tasks effectively.
  • Ability to work effectively in stressful situations.
  • Strong attention to detail.
PREFERRED EDUCATION/CERTIFICATION REQUIREMENTS
  • Undergraduate degree in computer science, information technology, or related field.
  • SANS GCIA, GCED, GPEN, GCIH or similar industry certification desired.
Contract job description
  1. Coordinates it project management, engineering, maintenance, qa, and risk management.
  2. Plans, coordinates, and monitors project activities.
  3. Develops technical applications to support users.
  4. Develops, implements, maintains and enforces documented standards and procedures for the design, development, installation, modification, and documentation of assigned systems.
  5. Provides training for system products and procedures.
  6. Performs application upgrades.
  7. Performs, monitoring, maintenance, or reporting on real- time databases, real-time network and serial data communications, and real-time graphics and logic applications.
  8. Troubleshoots problems.
  9. Ensures project life-cycle is in compliance with district standards and procedures.
Minimum education/certification requirements
  • Bachelor’s degree in information technology or related field or equivalent experience
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Operations Analyst
Security Operations Analyst

AHU Technologies Inc. • Washington

On-site
USD 120,000 - 170,000
SOC Analyst
SOC Analyst

Intone Inc • Washington

Hybrid
USD 100,000 - 140,000
Soc Tier 3 Analyst
Soc Tier 3 Analyst

Global Alliant Inc • Crownsville (MD)

Hybrid
USD 130,000 - 190,000
SOC Analyst Tier 1 (Secret Clearance)
SOC Analyst Tier 1 (Secret Clearance)

ShorePoint • Washington

On-site
USD 65,000 - 90,000
18 days PTO
11 holidays
85% insurance premium covered
+3
SOC Analyst
SOC Analyst

Tactibit • Suitland (MD)

On-site
USD 85,000 - 110,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Ampcus Inc • Washington

On-site
USD 90,000 - 120,000
SOC Analyst Tier 1 (Secret Clearance)
SOC Analyst Tier 1 (Secret Clearance)

ShorePoint, LLC • Washington

On-site
USD 65,000 - 90,000
PTO 18 days
Holidays 11
Insurance premium covered 85%
+3
SOC Analyst - Tier 1
SOC Analyst - Tier 1

Evans & Chambers • Maryland

On-site
USD 88,000 - 118,000
Senior SOC Analyst - Incident Response Lead
Senior SOC Analyst - Incident Response Lead

AHU Technologies Inc. • Washington

On-site
USD 120,000 - 170,000
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

10xTalents • Washington

On-site
USD 80,000 - 110,000