SOC Analyst

Posted 3 days ago

This is a fully remote position, open to applicants in District of Columbia, +1 more state.

📋 Description

• Deliver Tier III support for SIEM alert triage, perform comprehensive forensic analyses, and manage escalations.

• Conduct malware reverse engineering, memory forensics, and correlate campaigns across SOC and partner SOC environments.

• Act as the escalation point during shifts for complex or high-severity incidents raised by Tier I and Tier II analysts.

• Review escalated incidents within 4 hours in accordance with contractual SLAs.

• Maintain awareness of SIEM, SOAR, EDR, NDR, and CDM tools as well as telemetry data flows.

• Notify the SOC Manager of any tool health or coverage issues that may jeopardize detection capabilities.

• Lead shift transitions with written and verbal summaries detailing open incidents, active hunts, tuning adjustments, and follow-up tasks.

• Assist in updating SOC standard operating procedures and playbooks.

• Support Red Team and Purple Team exercises by confirming detection coverage and converting adversary tactics into detection rules.

• Aid in the creation and testing of custom detection rules.

• Collaborate with customer OCIO, OIG, and partner SOCs to enhance strategic threat awareness.

• Contribute to the development of monthly threat actor profiles and update detection signatures accordingly.

• Prepare initial incident reports within an hour of confirmation.

• Assist in final incident reports within 72 hours, including details on impact, timeline, and remediation actions.

• Engage in post-incident lessons-learned discussions.

• Transform findings into playbooks, runbooks, and enhancements in detection.

• Mentor Tier I and Tier II analysts in triage techniques, log analysis, and escalation quality.


⛳️ Requirements

• U.S. Citizenship is required due to obligations related to federal contracts.

• Must successfully pass a federal background investigation.

• Minimum of six years of experience in a Security Operations Center, with proven time in a Tier II or Tier III analyst capacity.

• Possess at least one of the following certifications: GCIH, GCIA, CEH, or Security+.

• Hands-on experience with SIEM platforms and endpoint telemetry, including alert tuning, correlation rule assessments, and the use of EDR agents for investigations.

• Proficient understanding of Windows and Linux internals, event and audit logs, as well as process and memory artifacts.

• Solid knowledge of networking, including TCP/IP, DNS, HTTP/S, common protocols, and packet capture analysis.

• Experience with AWS native capabilities and telemetry, including CloudTrail, GuardDuty, VPC Flow Logs, and CloudWatch, within a monitoring or investigative context.

• Capability to lead a shift and ensure proper handover discipline across analyst tiers.

• Excellent written and verbal communication skills, with the ability to produce clear incident write-ups and shift handover documentation.

• Required to obtain and maintain a Non-Sensitive / High Risk (Public Trust) security clearance, Tier 4/6c.

• Additional certifications such as GCFA, GCFE, GNFA, or GREM are considered advantageous.

• Preferred experience in malware reverse engineering, memory forensics, and network forensics.

• Familiarity with MITRE ATT&CK is advantageous.

• Working knowledge of NIST SP 800-61 Rev. 2, NIST SP 800-86, and NIST SP 800-137 is preferable.

• Experience with SOAR platforms and playbook automation is a plus.

• Familiarity with AWS GovCloud and hybrid cloud detection patterns is preferred.

• A quiet, distraction-free workspace with reliable internet access for telework is necessary.

• Must maintain full attention and availability during working hours.

• Schedule should align with the core business hours of colleagues and clients.

• Must disclose any current or future outside employment and obtain written approval.


🏝️ Benefits

• Valiant covers 99% of Medical, Dental, and Vision Insurance for full-time employees.

• Valiant contributes 25% towards Health Coverage for family members and dependents.

• Full-time employees receive 100% paid Short-Term Disability and Life Insurance coverage.

• 100% of certification costs are covered.

• 401K matching up to 4% is available.

• Paid Time Off is offered.

• Paid Federal Holidays are included.

• Wellness & Fitness Programs are available.

• Access to Valiant University – an Online Education and Training Portal.

• Flexible Spending Account (FSA) programs for medical costs, dependent care, transit, and parking are offered.

• Referral Bonuses are available.

• 100% remote work is supported.

• Opportunities for career development are provided.

• A focus on work-life balance is emphasized.

People also viewed

Talan1 day ago

Security Operations Analyst – SIEM Operations, Threat Detection

CZ flagCzechia OnlyFull-timeSecurity Operations
ApplyView job
Pragmatike1 day ago

Security Operations Analyst – SIEM, Threat Detection

ES flagSpain OnlyFreelanceSecurity Operations
ApplyView job
Supply Chimp1 day ago

SOC Analyst Level 2

PH flagPhilippines OnlyFull-timeSecurity OperationsPHP 65k – PHP 80k/month
ApplyView job
Pragmatike1 day ago

Security Operations Analyst – Cyber Defense Operations

ES flagSpain, +5 more countriesFull-timeSecurity Operations
ApplyView job
Pragmatike1 day ago

Security Operations Analyst – Cyber Defense

IN flagIndia, +4 more countriesFull-timeSecurity Operations
ApplyView job
Talan1 day ago

Security Operations Analyst – SIEM Operations, Threat Detection

PL flagPoland OnlyFull-timeSecurity Operations
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers