
SOC Analyst
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in District of Columbia, +1 more state.
• Deliver Tier III support for SIEM alert triage, perform comprehensive forensic analyses, and manage escalations.
• Conduct malware reverse engineering, memory forensics, and correlate campaigns across SOC and partner SOC environments.
• Act as the escalation point during shifts for complex or high-severity incidents raised by Tier I and Tier II analysts.
• Review escalated incidents within 4 hours in accordance with contractual SLAs.
• Maintain awareness of SIEM, SOAR, EDR, NDR, and CDM tools as well as telemetry data flows.
• Notify the SOC Manager of any tool health or coverage issues that may jeopardize detection capabilities.
• Lead shift transitions with written and verbal summaries detailing open incidents, active hunts, tuning adjustments, and follow-up tasks.
• Assist in updating SOC standard operating procedures and playbooks.
• Support Red Team and Purple Team exercises by confirming detection coverage and converting adversary tactics into detection rules.
• Aid in the creation and testing of custom detection rules.
• Collaborate with customer OCIO, OIG, and partner SOCs to enhance strategic threat awareness.
• Contribute to the development of monthly threat actor profiles and update detection signatures accordingly.
• Prepare initial incident reports within an hour of confirmation.
• Assist in final incident reports within 72 hours, including details on impact, timeline, and remediation actions.
• Engage in post-incident lessons-learned discussions.
• Transform findings into playbooks, runbooks, and enhancements in detection.
• Mentor Tier I and Tier II analysts in triage techniques, log analysis, and escalation quality.
• U.S. Citizenship is required due to obligations related to federal contracts.
• Must successfully pass a federal background investigation.
• Minimum of six years of experience in a Security Operations Center, with proven time in a Tier II or Tier III analyst capacity.
• Possess at least one of the following certifications: GCIH, GCIA, CEH, or Security+.
• Hands-on experience with SIEM platforms and endpoint telemetry, including alert tuning, correlation rule assessments, and the use of EDR agents for investigations.
• Proficient understanding of Windows and Linux internals, event and audit logs, as well as process and memory artifacts.
• Solid knowledge of networking, including TCP/IP, DNS, HTTP/S, common protocols, and packet capture analysis.
• Experience with AWS native capabilities and telemetry, including CloudTrail, GuardDuty, VPC Flow Logs, and CloudWatch, within a monitoring or investigative context.
• Capability to lead a shift and ensure proper handover discipline across analyst tiers.
• Excellent written and verbal communication skills, with the ability to produce clear incident write-ups and shift handover documentation.
• Required to obtain and maintain a Non-Sensitive / High Risk (Public Trust) security clearance, Tier 4/6c.
• Additional certifications such as GCFA, GCFE, GNFA, or GREM are considered advantageous.
• Preferred experience in malware reverse engineering, memory forensics, and network forensics.
• Familiarity with MITRE ATT&CK is advantageous.
• Working knowledge of NIST SP 800-61 Rev. 2, NIST SP 800-86, and NIST SP 800-137 is preferable.
• Experience with SOAR platforms and playbook automation is a plus.
• Familiarity with AWS GovCloud and hybrid cloud detection patterns is preferred.
• A quiet, distraction-free workspace with reliable internet access for telework is necessary.
• Must maintain full attention and availability during working hours.
• Schedule should align with the core business hours of colleagues and clients.
• Must disclose any current or future outside employment and obtain written approval.
• Valiant covers 99% of Medical, Dental, and Vision Insurance for full-time employees.
• Valiant contributes 25% towards Health Coverage for family members and dependents.
• Full-time employees receive 100% paid Short-Term Disability and Life Insurance coverage.
• 100% of certification costs are covered.
• 401K matching up to 4% is available.
• Paid Time Off is offered.
• Paid Federal Holidays are included.
• Wellness & Fitness Programs are available.
• Access to Valiant University – an Online Education and Training Portal.
• Flexible Spending Account (FSA) programs for medical costs, dependent care, transit, and parking are offered.
• Referral Bonuses are available.
• 100% remote work is supported.
• Opportunities for career development are provided.
• A focus on work-life balance is emphasized.
Talan
Pragmatike
Supply Chimp
Pragmatike
Get handpicked remote jobs straight to your inbox weekly.