Hiring.Camp

Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

Myhrhome

·

Yesterday

Location
HQ_Baltimore MD Management Office, United States of America
Workplace
Remote, Hybrid
Type
Full-time
Department
Operations
Experience
8+ years
Education
Bachelor
Source
Workday

Description

Key Responsibilities

  • Lead advanced investigations involving ransomware, APTs, zero-day exploits, insider threats, credential theft, lateral movement, cloud compromise, on-premises systems, VDI, SaaS, API abuse, business email compromise, certificate abuse, and data exfiltration.
  • Perform full lifecycle incident response including detection, triage, investigation, containment, eradication, recovery, validation, root cause analysis, and post-incident review.
  • Investigate attacks spanning on-premises infrastructure, Windows and Linux servers, Active Directory, Active Directory Certificate Services (AD CS), Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS platforms, APIs, containers, Kubernetes, databases, enterprise applications, and hybrid cloud environments.
  • Perform forensic analysis of on-premises systems, endpoints, servers, virtual machines, VDI, cloud workloads, identity systems, SaaS applications, APIs, databases, and network devices.
  • Analyze telemetry from EDR/XDR, NDR, SIEM, firewalls, IDS/IPS, WAF, VPN, DNS, DHCP, proxy, email security, cloud audit logs, API gateways, identity providers, application logs, and operating system logs.
  • Develop detections and SIEM correlation rules using Elastic Security, KQL, ES|QL/EQL, SQL, PowerShell, and Python.
  • Conduct proactive threat hunting using MITRE ATT&CK, behavioral analytics, and threat intelligence.
  • Provide technical leadership and mentoring to Tier 1 and Tier 2 analysts.
  • Support management with reporting, including producing technical reports documenting attack timelines, root cause, IOCs, IOAs, TTPs, and recommendations.

Required Qualifications

  • Expert knowledge of SIEM, SOAR, EDR/XDR, NDR, IDS/IPS, WAF, firewalls, email security, web proxies, CASB, DLP, IAM, PAM, API security, and cloud-native security technologies.
  • Expert experience with Elastic Security (ELK), CrowdStrike Falcon, Microsoft Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud, and Defender for Cloud Apps.
  • Deep understanding of on-premises infrastructure including Windows Server, Linux, Active Directory, Active Directory Certificate Services (AD CS), VMware, Hyper-V, storage, virtualization, networking, Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS, APIs, containers, Kubernetes, databases, and hybrid cloud architectures.
  • Expert knowledge of TCP/IP, DNS, DHCP, VPN, routing, switching, PKI, Kerberos, NTLM, OAuth, OIDC, SAML, JWT, and certificate-based authentication.
  • Advanced proficiency investigating on-premises systems, cloud environments, endpoints, servers, identity platforms, VDI, SaaS applications, APIs, databases, enterprise applications, and AD CS/PKI-related attacks.
  • Expert proficiency with KQL, ES|QL/EQL, SQL, PowerShell, Python, and Bash.
  • Deep knowledge of MITRE ATT&CK, MITRE D3FEND, Cyber Kill Chain, NIST CSF, NIST 800-61, OWASP Top 10, malware analysis, digital forensics, and attacker methodologies.
  • Minimum two certifications such as GCFA, GCFE, GCIH, GCIA, GREM, CISSP, SC-200, SC-100, AWS Certified Security – Specialty, or equivalent.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent experience.

Preferred Qualifications

  • Experience in financial services or another highly regulated industry.
  • Experience investigating enterprise incidents across Microsoft 365, Azure, AWS, Elastic, CrowdStrike, and hybrid environments.
  • Experience supporting DFIR engagements involving ransomware, nation-state threats, insider threats, enterprise-scale incidents, and Active Directory Certificate Services (AD CS) abuse.

Experience Requirements

  • Minimum 8 years of progressive cybersecurity experience.
  • Minimum 6 years of hands-on Security Operations Center experience.
  • Minimum 4 years leading complex enterprise incident investigations.
  • Minimum 2 years performing advanced digital forensics, threat hunting, and detection engineering.
  • Proven experience independently investigating incidents from initial alert through full remediation across on-premises infrastructure, enterprise networks, endpoints, identity platforms, Microsoft 365, Azure, AWS, VDI, SaaS applications, APIs, Elastic Security, hybrid cloud environments, and PKI/AD CS.

OneMain Holdings, Inc. is an Equal Employment Opportunity (EEO) employer. Qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship status, color, creed, culture, disability, ethnicity, gender, gender identity or expression, genetic information or history, marital status, military status, national origin, nationality, pregnancy, race, religion, sex, sexual orientation, socioeconomic status, transgender or on any other basis protected by law.

Skills

PythonAWSAzureKubernetesLinuxVMwareSQLCybersecuritySIEMOAuthTCP/IPAWS CertifiedCISSP

Similar Jobs

30

Manager Security Operations Center

KPN · Hilversum, NH, Netherlands · Hybrid

Today

Security Operations Center Operator

security Aus · Kahului, HI, US

Yesterday

Security Operations Center Operator

Security Aus · Kahului, HI, US

Yesterday

Supervisor, Security Operations Center- Swing Shift

Comcast · PA - West Chester, 1354 Boot Rd, United States of America · Remote, Onsite

Yesterday

Manager-Security Operations Center

Sound Transit · Seattle, WA

3 days ago

Security Operations Center Coordinator - Abilene, TX

Convergint Technologies · Abilene, TX

3 days ago

Physical Security Operations Center Operator- Charlotte, NC

Walden Security · Charlotte · Onsite

3 days ago

Security Operations Center Operator - 2nd and 3rd Shift- Chicago, IL

Titan Security Group · Chicago, IL

4 days ago

Security Operations Center Officer - 12 Hour Rotational Shifts - Webster, NY

Securitas · Webster, NY, United States, US

4 days ago

Global Security Operations Center Manager

Aus · Anaheim, CA, US

5 days ago

Global Security Operations Center Supervisor

Crane Worldwide Logistics · Houston, TX

5 days ago

Bancorp Security Operations Center Agent II 3pm-11:30pm

Fifththird · Fifth Third Center Cincinnati, United States of America

6 days ago

Bancorp Security Operations Center Team Lead First Shift

Fifththird · Fifth Third Center Cincinnati, United States of America

6 days ago

Security Operations Center Dispatcher

Allina Health have · Abbott Northwestern Hospital, United States of America

6 days ago

Security Operations Center Officer - On-Call

security Aus · Gardena, CA, US

6 days ago

Bancorp Security Operations Center Agent II 7am-3:30pm

Fifththird · Fifth Third Center Cincinnati, United States of America

6 days ago

Security Operations Center Technology Associate Manager

Accenture · Dublin, 1 Grand Canal Square, Ireland

6 days ago

Security Operations Center Officer

General Security Services Corporation · Maple Grove, MN

6 days ago

Security Operations Center Analist

Securitas · Winschoten, GR, Netherlands

6 days ago

Security Operations Center Analyst II

Global Resource Solutions · Colorado Springs, CO

1 week ago

Security Operations Center Analyst II

Global Resource Solutions · Colorado Springs, CO

1 week ago

Security Operations Center Analyst II

Global Resource Solutions · Colorado Springs, CO

1 week ago

Global Security Operations Center (GSOC) Operator - Swing Shift

Smithweb · Hou - Holl, United States of America

1 week ago

Global Security Operations Center (GSOC) Operator - Night Shift

Smithweb · Hou - Holl, United States of America

1 week ago

Security Operations Center Analyst - Low

Koniag Government Services · Washington, DC, USA

1 week ago

Security Operations Center Officer

Startup Aus · Boston, MA, US

1 week ago

Security Operations Center Operator

Startup Aus · Boston, MA, US

1 week ago

Global Security Operations Center (GSOC) Operator - Day Shift

Smithweb · Hou - Holl, United States of America

1 week ago

Security Operations Center Analyst - High

Koniag Government Services · Washington, DC, USA

1 week ago

Security Operations Center Analyst - Mid

Koniag Government Services · Washington, DC, USA

1 week ago
Remote Security Operations Center (SOC) Tier 3 Analyst / Incident Responder at Myhrhome | Hiring.Camp