Haystack
← Back to Jobs
Technology
TE

Tier 3 SOC Analyst (On-site, Washington, DC)

TECKNOMIC LLCWashington, DC🇺🇸United StatesPosted Oct 2, 2026

Why This Role Stands Out

This role offers a fantastic opportunity to become an integral part of a high-impact cybersecurity team within the DC Office of the Chief Technology Officer, where you'll hone your threat hunting and incident response expertise. You'll thrive here if you possess deep analytical skills and a passion for proactively defending critical infrastructure, making this an excellent next step in your cybersecurity career.

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Washington, DC, United States
Posted
1 week ago
TCP/IPPerlPowerShell

Job Description

About This Role

The DC Office of the Chief Technology Officer (OCTO) is seeking a Tier 3 SOC Analyst to provide advanced technical and analytical oversight of a Security Operations Center team that monitors, detects, analyzes, remediates, and reports on cybersecurity events and incidents across the District’s technology infrastructure. This is the advanced escalation point above Tier 2, responsible for deep analysis, threat hunting, detection tuning, and incident response. This is a 100% onsite role in Washington, DC.

Responsibilities

  • Serve as the advanced (Tier 3) escalation point: scrutinize and provide corrective analysis to cybersecurity events escalated from Tier 2 and escalate confirmed incidents to the Incident Response Lead
  • Provide in-depth analysis and trending/correlation of large data sets (logs, events, alerts) across network devices and applications to troubleshoot incidents and recommend remediation
  • Proactively threat-hunt through log, network, and system data to find undetected threats
  • Tune security tools: develop and adjust detection rules, build response procedures, and reduce false positives
  • Identify, verify, and ingest indicators of compromise and attack (IOCs, IOAs) into network security tools
  • Quality-proof technical advisories and assessments; provide expert support to resolve confirmed incidents
  • Formulate and coordinate SOC SOPs and runbooks; report trends and propose process and technical improvements

Qualifications

  • Bachelor’s degree in Cyber Security or related area (or equivalent experience)
  • Minimum 5 years of operational experience as a cybersecurity analyst/engineer handling and coordinating incidents in critical environments
  • In-depth understanding of current threats, attacks, and countermeasures (scanning, DDoS, phishing, ransomware, botnets, C2)
  • In-depth hands-on experience analyzing and responding to incidents with SIEM, IDS/IPS, firewalls, NAC, DLP, DAM, content filtering, vulnerability scanning, and endpoint protection
  • Strong knowledge of TCP/IP protocols, services, and networking; forensic analysis techniques for common operating systems
  • 11 to 15 years implementing and operating IS technologies (firewalls, IDS/IPS, SIEM, antivirus, traffic analyzers, malware analysis), scripting/automation (Perl, PowerShell, Regex), and leading incident-response plans
  • Preferred: SANS GCIA, GCED, GPEN, IH (or similar) certification

Required Skills

  • Advanced SOC analysis and incident response (Tier 3 escalation, correlation, containment, eradication)
  • SIEM-based detection and analysis, and SOC detection-rule tuning and false-positive reduction
  • Proactive threat hunting and threat-intelligence analysis (IOCs, IOAs, threat-actor TTPs)
  • Enterprise security technologies: IDS/IPS, firewalls, NAC, DLP, DAM, content filtering, endpoint protection, vulnerability scanning
  • Network and protocol expertise (TCP/IP) and digital-forensics techniques
  • Scripting and automation for security operations (PowerShell, Perl, Regex); SOP and runbook development
  • *Software / tools:* leading SIEM platforms, IDS/IPS, firewalls, EDR/endpoint protection, vulnerability scanners, malware-analysis and network-traffic-analysis tools

Similar jobs