Why This Role Stands Out
This role offers a fantastic opportunity to become an integral part of a high-impact cybersecurity team within the DC Office of the Chief Technology Officer, where you'll hone your threat hunting and incident response expertise. You'll thrive here if you possess deep analytical skills and a passion for proactively defending critical infrastructure, making this an excellent next step in your cybersecurity career.
Quick Overview
Job Description
About This Role
The DC Office of the Chief Technology Officer (OCTO) is seeking a Tier 3 SOC Analyst to provide advanced technical and analytical oversight of a Security Operations Center team that monitors, detects, analyzes, remediates, and reports on cybersecurity events and incidents across the District’s technology infrastructure. This is the advanced escalation point above Tier 2, responsible for deep analysis, threat hunting, detection tuning, and incident response. This is a 100% onsite role in Washington, DC.
Responsibilities
- Serve as the advanced (Tier 3) escalation point: scrutinize and provide corrective analysis to cybersecurity events escalated from Tier 2 and escalate confirmed incidents to the Incident Response Lead
- Provide in-depth analysis and trending/correlation of large data sets (logs, events, alerts) across network devices and applications to troubleshoot incidents and recommend remediation
- Proactively threat-hunt through log, network, and system data to find undetected threats
- Tune security tools: develop and adjust detection rules, build response procedures, and reduce false positives
- Identify, verify, and ingest indicators of compromise and attack (IOCs, IOAs) into network security tools
- Quality-proof technical advisories and assessments; provide expert support to resolve confirmed incidents
- Formulate and coordinate SOC SOPs and runbooks; report trends and propose process and technical improvements
Qualifications
- Bachelor’s degree in Cyber Security or related area (or equivalent experience)
- Minimum 5 years of operational experience as a cybersecurity analyst/engineer handling and coordinating incidents in critical environments
- In-depth understanding of current threats, attacks, and countermeasures (scanning, DDoS, phishing, ransomware, botnets, C2)
- In-depth hands-on experience analyzing and responding to incidents with SIEM, IDS/IPS, firewalls, NAC, DLP, DAM, content filtering, vulnerability scanning, and endpoint protection
- Strong knowledge of TCP/IP protocols, services, and networking; forensic analysis techniques for common operating systems
- 11 to 15 years implementing and operating IS technologies (firewalls, IDS/IPS, SIEM, antivirus, traffic analyzers, malware analysis), scripting/automation (Perl, PowerShell, Regex), and leading incident-response plans
- Preferred: SANS GCIA, GCED, GPEN, IH (or similar) certification
Required Skills
- Advanced SOC analysis and incident response (Tier 3 escalation, correlation, containment, eradication)
- SIEM-based detection and analysis, and SOC detection-rule tuning and false-positive reduction
- Proactive threat hunting and threat-intelligence analysis (IOCs, IOAs, threat-actor TTPs)
- Enterprise security technologies: IDS/IPS, firewalls, NAC, DLP, DAM, content filtering, endpoint protection, vulnerability scanning
- Network and protocol expertise (TCP/IP) and digital-forensics techniques
- Scripting and automation for security operations (PowerShell, Perl, Regex); SOP and runbook development
- *Software / tools:* leading SIEM platforms, IDS/IPS, firewalls, EDR/endpoint protection, vulnerability scanners, malware-analysis and network-traffic-analysis tools
Similar jobs
- AM
Systems Administrator with Security Clearance
NewAmentum
Vandenberg Space Force Base, CA🇺🇸HybridYesterdayMicrosoft OfficeTechnology - PS
Database Administrator/Developer with Security Clearance
NewPlateau Software Inc
Fairfax, VA🇺🇸HybridYesterdaySQLSQL ServerETL+1Technology - AM
Quality Assurance Specialist with Security Clearance
NewAmentum
Fort Meade, MD🇺🇸HybridYesterdayConfluenceJiraTechnology - SD
Sr Network Administrator with Security Clearance
NewSMS Data Products Group, Inc
Springfield, OH🇺🇸On-siteYesterdaySplunkTechnology - CG
CYBERSECURITY ENGINEER (2) - Secret Cleared with Security Clearance
NewCGI
Columbus, OH🇺🇸$127.5k/yrHybridYesterdayTechnology - SD
Sr Network Administrator with Security Clearance
NewSMS Data Products Group, Inc
Columbus, OH🇺🇸On-siteYesterdaySplunkTechnology - HS
Lead Appian Developer AI with Security Clearance
NewHumanIT Solutions LLC
Hampton, VA🇺🇸HybridYesterdayTechnology - AM
Content Developer I with Security Clearance
NewAmentum
Curtis Bay, MD🇺🇸HybridYesterdayTechnology - AV
Software Engineer with Security Clearance
NewAV, Inc.
Albuquerque, NM🇺🇸$60.5k - $92.5k/yrOn-siteYesterdayDockerAgileC+++3Technology - XT
Senior Systems Engineer/Senior DevOps Engineer with Security Clearance
NewX Technologies, Inc
San Antonio, TX🇺🇸HybridYesterdayDockerAnsibleBash+5Technology - BA
Embedded Developer with Security Clearance
NewBooz Allen Hamilton
El Segundo, CA🇺🇸$69.4k - $158k/yrOn-siteYesterdaySwiftAgileC+++5Technology - BA
Information Systems Security Manager with Security Clearance
NewBooz Allen Hamilton
Honolulu, HI🇺🇸$86.9k - $198k/yrOn-siteYesterdayGCPAWSAzureTechnology