SOC Analyst

🔥 12 hours ago

🏛️ District of Columbia, Washington – Remote

infoinfo

⏰ Full Time

🟡 Mid-level

🟠 Senior

🛡️ Security Operations

👻 Ghost score 13%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Valiant Solutions

Valiant Solutions

201 - 500 employees

Founded 2005

💼 Consulting

🎖️ Defense

🔒 Cybersecurity

Consulting • Defense • Cybersecurity

Valiant Solutions is a cybersecurity and IT services firm that specializes in securing the future by providing comprehensive and customized solutions to challenges faced by the Federal Government. With a focus on security engineering, operations, and strategic risk governance, the company addresses complex information security challenges through innovative application development and enterprise architecture. Recognized for its commitment to excellence, Valiant Solutions has been awarded numerous contracts and honors for its impactful contributions in the cybersecurity field.

📋 Description

• Provide Tier III support for SIEM alert triage, in-depth forensic analysis, and escalation • Perform malware reverse engineering, memory forensics, and campaign correlation across SOC and partner SOC environments • Serve as the shift escalation point for complex or high-severity events raised by Tier I and Tier II analysts • Analyze escalated events within 4 hours per contract SLA • Maintain situational awareness of SIEM, SOAR, EDR, NDR, and CDM tools and telemetry data flows • Alert the SOC Manager when tool health or coverage gaps put detection at risk • Lead shift handovers with written and verbal summaries of open incidents, active hunts, tuning changes, and follow-up items • Contribute to SOC standard operating procedure and playbook updates • Support Red Team and Purple Team exercises by validating detection coverage and translating adversary tradecraft into detection rules • Support development and testing of custom detection rules • Collaborate with customer OCIO, OIG, and partner SOCs to strengthen strategic threat awareness • Contribute to monthly threat actor profiles and update detection signatures • Submit initial incident reports within one hour of confirmation • Support final incident reports within 72 hours, including impact, timeline, and remediation • Participate in post-incident lessons-learned sessions • Translate findings into playbooks, runbooks, and detection improvements • Mentor Tier I and Tier II analysts on triage technique, log analysis, and escalation quality

🎯 Requirements

• U.S. Citizenship is required due to federal contract obligations • Ability to successfully pass a federal background investigation • Six or more years of Security Operations Center experience, with demonstrated time in a Tier II or Tier III analyst role • At least one of the following certifications: GCIH, GCIA, CEH, or Security+ • Hands-on experience with SIEM platforms and endpoint telemetry, including alert tuning, correlation rule review, and use of EDR agents for investigation • Working knowledge of Windows and Linux internals, event and audit logs, process and memory artifacts • Working knowledge of networking: TCP/IP, DNS, HTTP/S, common protocols, and packet capture analysis • Experience with AWS native capabilities and telemetry, including CloudTrail, GuardDuty, VPC Flow Logs, and CloudWatch, in a monitoring or investigation context • Ability to lead a shift and drive handover discipline across analyst tiers • Strong written and verbal communication skills, including the ability to write clear incident write-ups and shift handover notes • Required to obtain and maintain a Non-Sensitive / High Risk (Public Trust) security clearance, Tier 4/6c • Additional certifications such as GCFA, GCFE, GNFA, or GREM are preferred • Experience with malware reverse engineering, memory forensics, and network forensics is preferred • Familiarity with MITRE ATT&CK is preferred • Working knowledge of NIST SP 800-61 Rev. 2, NIST SP 800-86, and NIST SP 800-137 is preferred • Experience with SOAR platforms and playbook automation is preferred • Familiarity with AWS GovCloud and hybrid cloud detection patterns is preferred • Quiet, distraction-free workspace with adequate internet for telework • Full attention and availability during working hours • Schedule aligned with core business hours of coworkers and clients • Must disclose current or future outside employment and obtain written approval

🏖️ Benefits

• Valiant pays 99% of the Medical, Dental, and Vision Coverage for Full-time Employees • Valiant contributes 25% towards Health Coverage for Family and Dependents • 100% Paid Short Term Disability and Life Insurance Policy for Full-time Employees • 100% Paid Certifications • 401K Matching up to 4% • Paid Time Off • Paid Federal Holidays • Wellness & Fitness Program • Valiant University – Online Education and Training Portal • FSA programs for: Medical Costs, Dependent Care, Transit, and Parking • Referral Bonuses • 100% telework / remote work • Career development opportunities • Work-life balance

Apply Now

Similar Jobs

🕒 Yesterday

Concentric

201 - 500

🔐 Security

💼 Consulting

Program Manager overseeing embedded employees, vendors, and protective operations for Concentric, a global risk consultancy. Managing client relationships, security resources, compliance, and operational delivery.

🕒 Yesterday

Mondelēz International

10,000+ employees

💼 Consulting

📣 Marketing

📦 Logistics

Operations Analyst supporting Mondelēz International’s cyber defense operations. Assessing information security risks, testing controls, implementing security technology, and training teams.

🕒 Yesterday

Samsara

1001 - 5000

📦 Logistics

🏗️ Construction

🏥 Healthcare

Senior Security Operations Engineer monitoring incidents and leading forensics for Samsara’s Connected Operations IoT platform. Building security automation and supporting insider-threat investigations.

🕒 2 days ago

Motive

1001 - 5000

📦 Logistics

🏗️ Construction

🍽️ Food & Beverage

Senior Manager building Motive’s AI-first SOC across cloud, production, enterprise and connected-device environments. Leading detection, incident response, threat hunting and security automation.

🕒 6 days ago

Barnes Aerospace

1001 - 5000

🏭 Manufacturing

📦 Logistics

🚀 Aerospace

Global security operations leader building incident response, detection, and exposure management capabilities. Protecting aerospace intellectual property, manufacturing uptime, and hybrid IT environments.