6 дней назад
Senior SOC Analyst and Incident Responder
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior SOC Analyst and Incident Responder (Cybersecurity/SIEM): Leading advanced incident detection, forensic investigations, threat hunting, and response activities across enterprise IT endpoints, cloud environments, and OT systems with an accent on SIEM, EDR, threat intelligence, and MITRE ATT&CK analysis. Focus on coordinating containment and recovery, preserving digital evidence, refining SOC detection capabilities, and mentoring analysts during high-impact incidents.
Location: Onsite in Merrifield, Virginia, United States; daily schedule from 7:00 AM to 3:00 PM.
Company
provides cybersecurity support for the Drug Enforcement Administration, including security operations, incident response, forensics, threat detection, and vulnerability management.
What you will do
- Lead advanced incident detection, investigation, root-cause analysis, and impact assessment.
- Correlate SIEM, EDR, IDS/IPS, firewall, telemetry, log, and threat-intelligence data.
- Coordinate containment, eradication, recovery, forensic collection, evidence preservation, and post-incident reviews.
- Conduct proactive threat hunting for advanced persistent threats, indicators of compromise, anomalous activity, and undiscovered vulnerabilities.
- Develop detection rules, alert thresholds, playbooks, SOPs, automation workflows, and SOC training materials.
- Mentor SOC analysts, lead tabletop exercises and red/blue team drills, collaborate with engineering and cloud teams, and brief leadership on security events.
Requirements
- Active Secret or Top Secret clearance required.
- Master’s degree with 8 years of experience, or bachelor’s degree with 11 years of experience.
- Documented experience in information system security, security assessment and authorization, cybersecurity, computer forensics, or insider threat.
- At least one required certification: CBROPS, CFR, CySA+, Security+ CE, CASP+ CE, FITSP-O, GCFA, GCIA, GDSA, GICSP, CCNA Security, CCNP Security, CISSP, CCSP, CISA, SSCP, or CND.
- Experience with incident response, digital forensics, threat hunting, SIEM/SOAR platforms, and cybersecurity tools.
Culture & Benefits
- Full-time position supporting a 24/7/365 Security Operations Center.
- Fortune 500-level health, dental, and vision insurance.
- Paid time off, 401(k), and life insurance.
- Collaborative work with SOC, engineering, threat intelligence, forensics, IT, cloud, and DEA stakeholders.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
7 дней назад
Senior Threat Hunter Analyst (Cybersecurity)
8 дней назад
Security Incident Response Engineer (Cybersecurity)
10 дней назад
Sr. Staff Security Analyst - Incident Commander (Cybersecurity)
145 600 - 209 300$
9 дней назад
SOC Analyst (Cybersecurity)
88 000 - 121 000$
10 дней назад
Associate Solution Consultant – Security Incident Handler (Cybersecurity)
3 дня назад