Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

Peak Technology Solutions, Inc

Tier 3 SOC Analyst

Review key factors to help you decide if the role fits your goals.
Pay Growth
?
out of 5
Not enough data
Not enough info to score pay or growth
Job Security
?
out of 5
Not enough data
Calculating job security score...
Total Score
96
out of 100
Average of individual scores

Were these scores useful?

Job Description

Tier 3 SOC Analyst Peak Technology Solutions, Inc Washington, DC Job Details Full-time $78,900
  • $89,100 a year 21 hours ago Qualifications Investigative forensic analysis Operating systems Bachelor's degree Incident management operations support Security threat response protocols IP networking Cybersecurity investigations Threat intelligence Incident response implementation Open-source intelligence (OSINT) Full Job Description Job Overview We are seeking a highly skilled and motivated Tier 3 SOC (Security Operations Center) Analyst is cybersecurity technical resource responsible for providing technical analytical oversight a team of SOC Analysts to monitor, detect, analyze, remediate, and report on cybersecurity events and incidents impacting the technology infrastructure.
The ideal candidate will have an advanced technical background with significant experience in an enterprise successfully leading a SOC team or unit responsible for analysis and correlation of cybersecurity event, log, and alert data. The candidate will be skilled in understanding, recognition, and root-cause detection of cybersecurity exploits, vulnerabilities, and intrusions in host and network-based systems.
SPECIFIC TASKS
  • Utilize advanced technical background and experience in information technology and incident response handling to scrutinize and provide corrective analysis to escalated cybersecurity events from Tier 2 analysts—distinguishing these events from benign activities, and escalating confirmed incidents to the Incident Response Lead.
  • Provide in-depth cybersecurity analysis, and trending/correlation of large data-sets such as logs, event data, and alerts from diverse network devices and applications within the enterprise to identify and troubleshoot specific cybersecurity incidents, and make sound technical recommendations that enable expeditious remediation.
  • Proactively search through log, network, and system data to find and identify undetected threats.
  • Support security tool/application tuning engagements with analysts and engineers to develop/adjust rules and analyze/develop related response procedures, and reduce false-positives from alerting.
  • Identify, verify, and ingest indicators of compromise and attack (IOC's, IOA's) (e.g., malicious IPs/URLs, etc.) into network security tools/applications to protect the DC network.
  • Quality-proof technical advisories and assessments prior to release from SOC.
  • Coordinate with and provide expert technical support to enterprise-wide technicians and staff to resolve confirmed incidents.
  • Report common and repeat problems, observed via trend analysis, to SOC management and propose process and technical improvements to improve the effectiveness and efficiency of alert notification and incident handling.
  • Formulate and coordinate technical best-practice SOPs and Runbooks for SOC Analysts.
  • Respond to inbound requests via phone and other electronic means for technical assistance, and resolve problems independently.
Coordinate escalations with Incident Response Lead and collaborate with internal technology teams to ensure timely resolution of issues.
MINIMUM QUALIFICATIONS
  • Bachelor's Degree in Cyber Security or related area with minimum Five years of demonstrated operational experience as a cybersecurity analyst/engineer handling and coordinating cybersecurity incidents and response in critical environments, and/or equivalent knowledge in areas such as; technical incident handling and analysis, intrusion detection, log analysis, penetration testing, and vulnerability management.
  • In-depth understanding of current cybersecurity threats, attacks and countermeasures for adversarial activities such as network probing and scanning, distributed denial of service (DDoS), phishing, ransomware, botnets, command and control (C2) activity, etc.
  • In-depth hands-on experience analyzing and responding to security events and incidents with most of the following technologies and/or techniques; leading security information and event management (SIEM) technologies, intrusion detection/prevention systems (IDS/IPS), network
  • and host-based firewalls, network access control (NAC), data leak protection (DLP), database activity monitoring (DAM), web and email content filtering, vulnerability scanning tools, endpoint protection, secure coding, etc.
  • Strong communication, interpersonal, organizational, oral, and customer service skills.
  • Strong knowledge of TCP/IP protocols, services, and networking.
  • Knowledge of forensic analysis techniques for common operating systems.
  • Adept at proactive search, solicitation, and detailed analysis of threat intelligence (e.
g., exploits, IOCs, hacking tools, vulnerabilities, threat actor TTPs) derived from open-source resources and external entities, to identify cybersecurity threats and derive countermeasures, not previously ingested into network security tools/applications, to apply to protect the Government of the District of Columbia network.
  • Excellent ability to multi-task, prioritize, and manage time and tasks effectively.
  • Ability to work effectively in stressful situations.
  • Strong attention to detail.
PREFERRED EDUCATION/CERTIFICATION REQUIREMENTS
  • Undergraduate degree in computer science, information technology, or related field.
  • SANS GCIA, GCED, GPEN, GCIH or similar industry certification desired.
Pay:
$78,900.00
  • $89,100.
00 per year
Education:
Bachelor's (Preferred)
Experience:
cybersecurity analyst/engineer in a SOC or equivalent: 5 years (Preferred) understanding of cybersecurity attack countermeasures: 5 years (Preferred)
Analyzing And Responding To Security Events And Incidents:
5 years (Preferred) cybersecurity attack methodology include tactics/techniques: 5 years (Preferred)
Tcp/Ip Protocols, Services, Networking:
5 years (Preferred) implementing, administering, and operating
IS:
10 years (Preferred) utilizing advanced experience with scripting and tool : 10 years (Preferred) developing, leading/executing information security incident: 10 years (Preferred) developing standard and complex IT solutions & services: 10 years (Preferred)
License/Certification:
SANS GCIA, GCED, GPEN, GCIH or similar (Preferred)
Location:
Washington, DC 20003 (Preferred)
Work Location:
In person