Tier 3 SOC Analyst (On-site, Washington, DC)

Washington, DC, US • Posted 7 hours ago • Updated 7 hours ago
Contract Independent
Contract W2
1 Year
No Travel Required
On-site
$59 - $77/hr
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • SOC Analyst
  • Tier 3 SOC
  • Security Operations Center
  • Incident Response
  • SIEM
  • Threat Hunting
  • Threat Intelligence
  • IOC
  • IOA
  • TTP
  • IDS
  • IPS
  • Firewall
  • NAC
  • DLP
  • DAM
  • Endpoint Protection
  • EDR
  • Vulnerability Management
  • Malware Analysis
  • Digital Forensics
  • TCP/IP
  • PowerShell
  • Perl
  • Regex
  • DDoS
  • Phishing
  • Ransomware
  • C2
  • SANS
  • GCIA
  • GCIH
  • GCED
  • GPEN

Summary

About This Role

The DC Office of the Chief Technology Officer (OCTO) is seeking a Tier 3 SOC Analyst to provide advanced technical and analytical oversight of a Security Operations Center team that monitors, detects, analyzes, remediates, and reports on cybersecurity events and incidents across the District’s technology infrastructure. This is the advanced escalation point above Tier 2, responsible for deep analysis, threat hunting, detection tuning, and incident response. This is a 100% onsite role in Washington, DC.

Responsibilities

  • Serve as the advanced (Tier 3) escalation point: scrutinize and provide corrective analysis to cybersecurity events escalated from Tier 2 and escalate confirmed incidents to the Incident Response Lead
  • Provide in-depth analysis and trending/correlation of large data sets (logs, events, alerts) across network devices and applications to troubleshoot incidents and recommend remediation
  • Proactively threat-hunt through log, network, and system data to find undetected threats
  • Tune security tools: develop and adjust detection rules, build response procedures, and reduce false positives
  • Identify, verify, and ingest indicators of compromise and attack (IOCs, IOAs) into network security tools
  • Quality-proof technical advisories and assessments; provide expert support to resolve confirmed incidents
  • Formulate and coordinate SOC SOPs and runbooks; report trends and propose process and technical improvements

Qualifications

  • Bachelor’s degree in Cyber Security or related area (or equivalent experience)
  • Minimum 5 years of operational experience as a cybersecurity analyst/engineer handling and coordinating incidents in critical environments
  • In-depth understanding of current threats, attacks, and countermeasures (scanning, DDoS, phishing, ransomware, botnets, C2)
  • In-depth hands-on experience analyzing and responding to incidents with SIEM, IDS/IPS, firewalls, NAC, DLP, DAM, content filtering, vulnerability scanning, and endpoint protection
  • Strong knowledge of TCP/IP protocols, services, and networking; forensic analysis techniques for common operating systems
  • 11 to 15 years implementing and operating IS technologies (firewalls, IDS/IPS, SIEM, antivirus, traffic analyzers, malware analysis), scripting/automation (Perl, PowerShell, Regex), and leading incident-response plans
  • Preferred: SANS GCIA, GCED, GPEN, IH (or similar) certification

Required Skills

  • Advanced SOC analysis and incident response (Tier 3 escalation, correlation, containment, eradication)
  • SIEM-based detection and analysis, and SOC detection-rule tuning and false-positive reduction
  • Proactive threat hunting and threat-intelligence analysis (IOCs, IOAs, threat-actor TTPs)
  • Enterprise security technologies: IDS/IPS, firewalls, NAC, DLP, DAM, content filtering, endpoint protection, vulnerability scanning
  • Network and protocol expertise (TCP/IP) and digital-forensics techniques
  • Scripting and automation for security operations (PowerShell, Perl, Regex); SOP and runbook development
  • *Software / tools:* leading SIEM platforms, IDS/IPS, firewalls, EDR/endpoint protection, vulnerability scanners, malware-analysis and network-traffic-analysis tools
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10319786
  • Position Id: 812392
  • Posted 7 hours ago
Contact the job poster
DS

Dexter Spencer

Recruiter @ TECKNOMIC LLC
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Washington, District of Columbia

•

Today

Easy Apply

Contract

50 - 65

Washington, District of Columbia

•

Today

Easy Apply

Full-time, Third Party, Contract

$DOE

Washington, District of Columbia

•

Today

Full-time

Washington, District of Columbia

•

Today

Easy Apply

Full-time

$130,000 - $140,000

Search all similar jobs