Haystack
← Back to Jobs
Technology
IM

Tier 3 SOC Analyst

ICT Mondial IncWashington, DC🇺🇸United StatesPosted Oct 5, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Washington, DC, United States
Posted
18 hours ago
TCP/IPPenetration TestingPerlPowerShell

Job Description

Summary

The Tier 3 SOC Analyst is a cybersecurity technical resource who provides technical analytical oversight to a team of SOC analysts. The role monitors, detects, analyzes, remediates, and reports on cybersecurity events and incidents affecting the client's technology infrastructure, and serves as an advanced escalation point.

The ideal candidate has an advanced technical background and significant experience leading a SOC team or unit in an enterprise, responsible for analysis and correlation of cybersecurity event, log, and alert data. The candidate is skilled in recognizing and finding the root cause of exploits, vulnerabilities, and intrusions in host- and network-based systems.

Responsibilities

  • Use advanced technical and incident response experience to scrutinize and provide corrective analysis on cybersecurity events escalated from Tier 2 analysts, distinguish them from benign activity, and escalate confirmed incidents to the Incident Response Lead.
  • Provide in-depth analysis and trending/correlation of large data sets (logs, event data, alerts) from diverse network devices and applications to identify and troubleshoot specific incidents, and make sound technical recommendations for expeditious remediation.
  • Proactively search log, network, and system data to find undetected threats.
  • Support security tool and application tuning with analysts and engineers to develop and adjust rules, develop related response procedures, and reduce false-positive alerts.
  • Identify, verify, and ingest indicators of compromise and attack (IOCs, IOAs), such as malicious IPs and URLs, into network security tools to protect the network.
  • Quality-proof technical advisories and assessments before release from the SOC.
  • Coordinate with and provide expert technical support to enterprise-wide technicians and staff to resolve confirmed incidents.
  • Report common and repeat problems observed through trend analysis to SOC management, and propose process and technical improvements to alert notification and incident handling.
  • Formulate and coordinate technical best-practice SOPs and runbooks for SOC analysts.
  • Respond to inbound requests by phone and other electronic means for technical assistance and resolve problems independently. Coordinate escalations with the Incident Response Lead and collaborate with internal technology teams for timely resolution.

Minimum Qualifications

  • Bachelor's degree in Cyber Security or a related area with a minimum of five years of demonstrated operational experience as a cybersecurity analyst/engineer handling and coordinating incidents and response in critical environments, and/or equivalent knowledge in areas such as technical incident handling and analysis, intrusion detection, log analysis, penetration testing, and vulnerability management.
  • In-depth understanding of current cybersecurity threats, attacks, and countermeasures for adversarial activity such as network probing and scanning, DDoS, phishing, ransomware, botnets, and command and control (C2) activity.
  • In-depth hands-on experience analyzing and responding to security events and incidents with most of the following technologies and techniques: leading SIEM technologies, IDS/IPS, network- and host-based firewalls, network access control (NAC), data leak protection (DLP), database activity monitoring (DAM), web and email content filtering, vulnerability scanning tools, endpoint protection, and secure coding.
  • Strong knowledge of TCP/IP protocols, services, and networking.
  • Knowledge of forensic analysis techniques for common operating systems.
  • Adept at proactive search, solicitation, and detailed analysis of threat intelligence (exploits, IOCs, hacking tools, vulnerabilities, threat actor TTPs) from open-source resources and external entities, to identify threats and derive countermeasures not yet ingested into network security tools.
  • Excellent ability to multitask, prioritize, and manage time and tasks effectively.
  • Ability to work effectively in stressful situations.
  • Strong attention to detail.
  • Strong communication, interpersonal, organizational, oral, and customer service skills.

Required Experience

  • 5 years of hands-on operational experience as a cybersecurity analyst/engineer in a security operations center, or equivalent knowledge
  • 5 years of in-depth understanding of cybersecurity attack countermeasures for adversarial activity such as malicious code, DDoS, and phishing
  • 5 years of in-depth hands-on experience analyzing and responding to security events and incidents with a SIEM
  • 5 years of strong knowledge of cybersecurity attack methodology, including tactics, techniques, and associated countermeasures
  • 5 years of strong knowledge of TCP/IP protocols, services, and networking, and experience identifying, analyzing, containing, and eradicating cybersecurity threats
  • 11 years implementing, administering, and operating information security technology such as firewalls, IDS/IPS, SIEM, antivirus, network traffic analyzers, and malware analysis
  • 11 years of advanced experience with scripting and tool automation such as Perl, PowerShell, and Regex
  • 11 years developing, leading, and executing information security incident response plans
  • 11 years developing standard and complex IT solutions and services driven by business requirements and industry standards

Preferred Education/Certifications

  • Undergraduate degree in computer science, information technology, or a related field (BS in IT, Cybersecurity, Engineering, or equivalent experience highly desired)
  • SANS GCIA, GCED, GPEN, GCIH, or similar industry certification

Similar jobs