Job Summary We are seeking a highly skilled and motivated Tier 3 Security Operations Center (SOC) Analyst to join our dynamic cybersecurity team. In this pivotal role, you will leverage your extensive expertise in cybersecurity tools, network security, and incident response to investigate complex security events, perform vulnerability assessments, and enhance our security posture.
Summary of Key Responsibilities:
Incident Response & Forensics :
Plan, initiate, and conduct forensic investigations on compromised systems; perform root cause and scope-of-impact analysis; create detailed forensic reports
Malware & Tool Analysis :
Support malware analysis of attacker tools and techniques; identify and analyze malicious payloads
Tool & Process Development :
Train SOC analysts on SIEM tools (e.g., Sentinel), develop and tune detection rules, and assist in creating new SOC monitoring processes
Threat Intelligence & Hunting :
Correlate actionable security events, review threat data, develop custom detection signatures, and conduct threat hunting to identify advanced threats
Technical Leadership :
Contribute to technical briefings, develop incident response procedures, and ensure adherence to operational and technical standards
On-Call Support :
May require availability outside regular hours or on weekends to respond to critical incidents
Additional Job Description:
- Assists with the development of Security Operation Center (SOC) tiered monitoring and escalation processes
- Provides support for SOC Analyst Tier 1 & 2 personnel
- Provides technical expertise in the development of existing Cybersecurity projects and initiatives to include but not limited to: End Point Protection and Response, Vulnerability Management, Security Operations Expansion
- Provides technical expertise & support in Cybersecurity monitoring and analysis tool engineering and implementation
- Reviews, evaluates, and triages security alerts in Sentinel using dashboards, reports, and custom queries
- Uses tools, such as captured network traffic, intrusion detection software and Sentinel instrumentation to investigate possible cyber incidents. Other security program development, documentation, security monitoring, threat hunting, vulnerability management, technical and risk assessment, and security engineering duties assigned by OSM SOC and senior management. Required Qualifications
Education :
Bachelor's degree in Computer Science, Information Systems, Engineering, or a related technical/scientific discipline
Experience :
4+ years of relevant experience in cybersecurity, digital forensics, or incident response
Skills :
Proficiency with forensic tools, SIEM platforms (Sentinel), malware analysis, network traffic analysis, and threat intelligence gathering
Certifications :
GREM, CEH, CHFI, GCFE, GIAC, or similar cybersecurity/forensics credentials are preferred
Additional Requirements:
- Hybrid position - Must be able to work at the DoIT Crownsville office 2-3 times a week or rotation schedule with other Tier 3 Analysts.
- Strong leadership and communication skills Join us if you're passionate about cybersecurity defense!
Bring your expertise in network security engineering, vulnerability research, threat detection & response to a team dedicated to protecting vital information assets through innovative solutions and rigorous analysis. Your proactive mindset will help us stay ahead of emerging cyber threats while advancing your career in a fast-paced environment committed to excellence in IT security management.
Pay:
$78,000.00 per year
Work Location:
Hybrid remote in Crownsville, MD 21032