SOC Analyst Tier 3
JFL CONSULTING, LLC · Springfield, VA · 1 wk ago
On-siteInformation Technology$140k–$180k/yrFull-time
About the role
JFL Consulting is seeking a SOC Analyst Tier 3 and Incident Responder, a senior analyst role in the SOC, to lead the response to confirmed security incidents, conduct threat hunting operations, and provide deep technical analysis capability in the operations center.
Responsibilities
- Provide Tier 3 escalation and resolution for the most complex incidents and outages, escalating to the Tier 4 SME as needed with appropriate documentation
- Lead the response to Priority 1 and complex Priority 2 security incidents from detection through remediation
- Conduct proactive threat hunting operations to identify threats that have bypassed automated detection
- Perform advanced PCAP analysis, log analysis, memory forensics, and malware triage
- Contain and eradicate threats while coordinating with engineers for isolation and remediation
- Produce formal incident response reports for Priority 1 and Priority 2 incidents
- Develop and maintain threat hunting TTPs and playbooks
- Build new detection use cases from threat hunting findings and submit to SIEM engineer
- Serve as on-call incident responder
- Brief senior leadership during active high priority incidents
- Mentor Tier 1 and 2 analysts in investigation techniques and escalation decision-making
- Manage and own the SOC Event log for all events during the shifts
- Maintain situational awareness of the threat landscape and active campaigns
- Participate in briefings and training sessions
Requirements
Required qualifications include 5+ years of SOC, threat hunting, or incident response experience, and a Bachelor's degree in Cyber Security, Information Technology, Computer Science, Information Security, or a related field.
- 5+ years of SOC, threat hunting, or incident response type experience
- Bachelor's degree in Cyber Security, Information Technology, Computer Science, Information Security, or related field
- Two of the following certifications, equivalent or better: Sec+, CYSA+, GCIH, SecX, CEH, GCIA, GSOC, CISSP
- Demonstrated hands-on incident response experience including containment, eradication, and recovery
- Proficiency with SIEM platforms and log analysis
- Proficiency with SIEM query languages — SPL, KQL, or equivalent
- Proficiency with PCAP analysis tools (Wireshark, NetworkMiner, or equivalent)
- Experience with EDR, endpoint forensics, memory analysis, and network forensics tools
- Deep understanding of attacker TTPs, kill chain methodology, and MITRE ATT&CK
- Ability to work shifts including nights, weekends, and holidays on rotating shift schedule
Qualifications
Preferred qualifications include GCFA or GCFE certification, active Secret clearance, experience with threat hunting frameworks and platforms, reverse engineering experience, and prior experience on a DFIR team or incident response retainer.
- GCFA or GCFE certification or other forensic certifications
- Active Secret clearance preferred but not required
- Experience with threat hunting frameworks and platforms
- Reverse engineering experience (IDA Pro, Ghidra)
- Prior experience on a DFIR team or incident response retainer
- Experience with malware analysis (static and dynamic)
Benefits
- Salary: $140k- $180k
- 100% employer-paid medical, dental, and vision premiums for employees and dependents
- Flexible Spending Accounts (healthcare, dependent care, and commuter)
- Life insurance, short-term disability and long-term disability
- 401(k) with immediate vesting of company contribution
- Generous PTO policy (15 vacation, 5 sick, 2 personal days, 11 holidays)
- Certification reimbursement, dedicated professional development funding, and company-provided access to online learning platforms