Tier 3 SOC Analyst (On-site, Washington, DC)

Posted 3 days ago

tecknomicAlexandria (VA)

SENIORITY

Lead

Apply

About the role

The DC Office of the Chief Technology Officer (OCTO) needs a Tier 3 SOC Analyst to provide advanced technical and analytical oversight of a SOC team monitoring, detecting, analyzing, and responding to cybersecurity incidents across the District’s infrastructure. This is the advanced escalation point above Tier 2: deep analysis, threat hunting, detection tuning, and incident response. 100% onsite in Washington, DC.
What you’ll do: Serve as the advanced (Tier 3) escalation point: scrutinize and provide corrective analysis to cybersecurity events escalated from Tier 2 and escalate confirmed incidents to the Incident Response LeadProvide in-depth analysis and trending/correlation of large data sets (logs, events, alerts) across network devices and applications to troubleshoot incidents and recommend remediationProactively threat-hunt through log, network, and system data to find undetected threatsTune security tools: develop and adjust detection rules, build response procedures, and reduce false positivesIdentify, verify, and ingest indicators of compromise and attack (IOCs, IOAs) into network security toolsQuality-proof technical advisories and assessments; provide expert support to resolve confirmed incidentsWhat you needBachelor’s degree in Cyber Security or related area (or equivalent experience) Minimum 5 years of operational experience as a cybersecurity analyst/engineer handling and coordinating incidents in critical environmentsIn-depth understanding of current threats, attacks, and countermeasures (scanning, DDoS, phishing, ransomware, botnets, C2) In-depth hands-on experience analyzing and responding to incidents with SIEM, IDS/IPS, firewalls, NAC, DLP, DAM, content filtering, vulnerability scanning, and endpoint protectionStrong knowledge of TCP/IP protocols, services, and networking; forensic analysis techniques for common operating systems11 to 15 years implementing and operating IS technologies (firewalls, IDS/IPS, SIEM, antivirus, traffic analyzers, malware analysis), scripting/automation (Perl, PowerShell, Regex), and leading incident-response plansRequired skillsAdvanced SOC analysis and incident response (Tier 3 escalation, correlation, containment, eradication)SIEM-based detection and analysis, and SOC detection-rule tuning and false-positive reductionProactive threat hunting and threat-intelligence analysis (IOCs, IOAs, threat-actor TTPs) Enterprise security technologies: IDS/IPS, firewalls, NAC, DLP, DAM, content filtering, endpoint protection, vulnerability scanningNetwork and protocol expertise (TCP/IP) and digital-forensics techniquesScripting and automation for security operations (PowerShell, Perl, Regex); SOP and runbook development

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this