ECS

SOC Analyst (SR.)

ECS  •  Virginia (Remote)  •  1 day ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Everforth ECS is seeking a Senior SOC Analystto work remotely

At Everforth ECS Federal, we're driven by a commitment to excellence and innovation in solving complex challenges. As a premier provider of advanced technology solutions and services, our mission is to secure and optimize the most critical commercial, government, defense, and intelligence projects across the country. Our team is composed of dynamic professionals who thrive in a collaborative and empowering environment, where our team members leverage the latest technologies and insights to make a real-world impact. Join us and be part of a forward-thinking organization that values your expertise and supports your professional growth.

The Senior SOC Analyst is responsible for advanced security monitoring, investigation, and incident response activities within the Everforth Security Operations Center (SOC). This role serves as a senior technical resource within the analyst team, responsible for leading complex investigations, mentoring junior analysts, and ensuring high-quality incident analysis across enterprise environments. The Senior SOC Analyst plays a critical role in identifying sophisticated threats, escalating security incidents, and improving SOC investigative capabilities.

This role reports to the SOC Manager and works closely with the Security Engineering team, enterprise IT operations teams, and the Everforth Commercial MSSP to ensure effective monitoring, investigation, and response across the enterprise.

Responsibilities

  • Advanced Threat Investigation Conduct in-depth analysis of complex security alerts, anomalies, and potential threat activity across enterprise environments.
  • Incident Response Support Lead investigation and response activities for confirmed or suspected cybersecurity incidents affecting enterprise systems.
  • Alert Triage and Escalation Perform detailed triage of security alerts and escalate validated incidents according to established procedures.
  • Investigation Leadership Serve as the lead analyst during significant investigations, coordinating investigative efforts and guiding response activities.
  • Threat Analysis Analyze indicators of compromise, attacker behavior, and malicious artifacts to determine the scope and impact of security incidents.
  • Detection Engineering Develop and refine detection logic, analytics, and monitoring use cases based on investigative findings and threat intelligence.
  • Threat Hunting Conduct proactive threat hunting activities to identify adversary behavior not detected through automated alerts.
  • MSSP Escalation Handling Review and validate alerts and escalations originating from the MSSP after-hours monitoring team.
  • Investigation Documentation Ensure thorough documentation of investigations, findings, and response actions within the SOC case management platform.
  • Operational Quality Assurance Support the SOC Manager in maintaininginvestigation quality and adherence to SOC playbooks and procedures.
  • Operational Effectiveness: Leads the design and implementation of SOC process improvements through automation, AI-driven solutions, workflow optimization, and continuous enhancement of detection and response capabilities.
  • Operational Collaboration Work closely with IT operations, infrastructure teams, and security engineering to support investigation and remediation activities.
  • Knowledge Sharing Mentor junior SOC analysts and provide guidance on investigative techniques, threat analysis, and incident handling procedures.
  • Situational AwarenessMaintain awareness of emerging threats, attacker tactics, techniques, and procedures relevant to enterprise environments.
  • Playbook Execution Execute established SOC investigation playbooks and contribute to the refinement of operational procedures.
  • On-Call Support: Participates in on-call support to assist with security incident response, operational issues, and investigation activities to maintain continuous SOC coverage and response capability.

Qualifications

Required Skills

  • Experience Minimum of 5 years of cybersecurity experience, with at least 3 years in a Security Operations Center or incident response role.
  • Security Investigation Expertise Strong experience investigating security alerts, analyzing suspicious activity, and determining the scope and impact of security incidents.
  • Incident Response Experience Hands-on experience supporting incident response investigations including containment, eradication, and recovery coordination.
  • Security Technology Experience Experience working with enterprise security tools such as SIEM platforms, EDR platforms, and log analysis systems.
  • Threat Analysis Skills Ability to analyze indicators of compromise, attacker behaviors, and adversary techniques during investigations.
  • Log Analysis Expertise Strong experience reviewing and interpreting system logs, endpoint telemetry, network events, and authentication activity.
  • Detection Engineering Experience Experience developing or tuning detection rules, analytics, or monitoring logic used to identify malicious activity.
  • Security Framework KnowledgeFamiliarity with cybersecurityframeworks such as NIST Cybersecurity Framework or CIS Critical Security Controls.
  • Investigation Documentation Experience documenting investigations, incidents, and response actions within case management platforms.

Other Requirements of the position include:

  • Able and willing to obtain a USSecurity Clearance
  • This role may require occasional on-call support during off-hours to respond to security incidents.
ECS

About ECS

ECS is a fast-growing 4,000-person, $1.2B provider of advanced technology solutions for federal civilian, defense, intelligence, and commercial customers. We tackle complex client challenges with smart, scalable solutions in data and AI, cybersecurity, and digital transformation. Our collective work empowers customers’ missions, strengthens our partners, inspires our employees, and grows our company.

To achieve our purpose — to tackle the missions that matter most and create a lasting impact on our customers, employees, and community — we are committed to excellence in growth, customer delivery, technology innovation, and employee engagement.  

We believe in:

• Attracting, developing, and retaining top talent

• Building high-performing teams

• Creating an engaging employee environment

• Acting with social responsibility

• Having a positive impact on our community

Our core values: Excellence, Drive, Grit, and Community. We keep these values at the heart of all we do. We’re looking for driven individuals who want to solve meaningful challenges and help shape the future of national security and public service. If you’re ready to make a difference, you’ll find your team here.

Industry
IT & Software
Company Size
1,001-5,000 employees
Headquarters
Fairfax, VA
Year Founded
1993
Social Media