About this role
Job Title: SOC Tier 3 Analyst
Location: Crownsville, MD – Local Candidates Only Onsite Address: DoIT HQ, 100 Community Place, Crownsville, MD Employment Type: Full-Time Work Arrangement: Hybrid
Criteria- Need US citizenship because of federal regulations and the sensitive nature of the work involved
Summary of Key Responsibilities
• Incident Response & Forensics: Plan, initiate, and conduct forensic investigations on compromised systems; perform root cause and scope-of-impact analysis; create detailed forensic reports.
• Malware & Tool Analysis: Support malware analysis of attacker tools and techniques; identify and analyze malicious payloads.
• Tool & Process Development: Train SOC analysts on SIEM tools (e.g., Sentinel), develop and tune detection rules, and assist in creating new SOC monitoring processes.
• Threat Intelligence & Hunting: Correlate actionable security events, review threat data, develop custom detection signatures, and conduct threat hunting to identify advanced threats.
• Technical Leadership: Contribute to technical briefings, develop incident response procedures, and ensure adherence to operational and technical standards.
• On-Call Support: May require availability outside regular hours or on weekends to respond to critical incidents.
Additional Job Description
• Assists with the development of Security Operation Center (SOC) tiered monitoring and escalation processes.
• Provides support for SOC Analyst Tier 1 & 2 personnel.
• Provides technical expertise in the development of existing Cybersecurity projects and initiatives to include but not limited to: End Point Protection and Response, Vulnerability Management, Security Operations Expansion.
• Provides technical expertise & support in Cybersecurity monitoring and analysis tool engineering and implementation.
• Reviews, evaluates, and triages security alerts in Sentinel using dashboards, reports, and custom queries.
• Uses tools, such as captured network traffic, intrusion detection software and Sentinel instrumentation to investigate possible cyber incidents.
• Other security program development, documentation, security monitoring, threat hunting, vulnerability management, technical and risk assessment, and security engineering duties assigned by OSM SOC and senior management.
Required Qualifications
Education:
• Bachelor’s degree in Computer Science, Information Systems, Engineering, or a related technical/scientific discipline.
Experience:
• 10+ years of relevant experience in cybersecurity, digital forensics, or incident response.
Skills:
• Proficiency with forensic tools.
• SIEM platforms (Sentinel).
• Malware analysis.
• Network traffic analysis.
• Threat intelligence gathering.
Certifications:
• GREM, CEH, CHFI, GCFE, GIAC, or similar cybersecurity/forensics credentials are preferred.
Additional Requirements
• Hybrid position – Must be able to work at the Crownsville office 2–3 times a week or rotation schedule with other Tier 3 Analysts.
• Strong leadership and communication skills.
• If interested in applying for the position, please reach out to me at [email protected]
120000