About This Role
The DC Office of the Chief Technology Officer (OCTO) is seeking a Tier 3 SOC Analyst to provide advanced technical and analytical oversight of a Security Operations Center team that monitors, detects, analyzes, remediates, and reports on cybersecurity events and incidents across the District’s technology infrastructure. This is the advanced escalation point above Tier 2, responsible for deep analysis, threat hunting, detection tuning, and incident response. This is a 100% onsite role in Washington, DC.
Responsibilities
Serve as the advanced (Tier 3) escalation point: scrutinize and provide corrective analysis to cybersecurity events escalated from Tier 2 and escalate confirmed incidents to the Incident Response Lead
Provide in-depth analysis and trending/correlation of large data sets (logs, events, alerts) across network devices and applications to troubleshoot incidents and recommend remediation
Proactively threat-hunt through log, network, and system data to find undetected threats
Tune security tools: develop and adjust detection rules, build response procedures, and reduce false positives
Identify, verify, and ingest indicators of compromise and attack (IOCs, IOAs) into network security tools
Quality-proof technical advisories and assessments; provide expert support to resolve confirmed incidents
Formulate and coordinate SOC SOPs and runbooks; report trends and propose process and technical improvements
| Location | Washington, DC |
| Job Type | Contractor, Full-time |
| Salary | $59–$77 Per Hour |
Qualifications
Bachelor’s degree in Cyber Security or related area (or equivalent experience)
Minimum 5 years of operational experience as a cybersecurity analyst/engineer handling and coordinating incidents in critical environments
In-depth understanding of current threats, attacks, and countermeasures (scanning, DDoS, phishing, ransomware, botnets, C2)
In-depth hands-on experience analyzing and responding to incidents with SIEM, IDS/IPS, firewalls, NAC, DLP, DAM, content filtering, vulnerability scanning, and endpoint protection
Strong knowledge of TCP/IP protocols, services, and networking; forensic analysis techniques for common operating systems
11 to 15 years implementing and operating IS technologies (firewalls, IDS/IPS, SIEM, antivirus, traffic analyzers, malware analysis), scripting/automation (Perl, PowerShell, Regex), and leading incident-response plans
Preferred: SANS GCIA, GCED, GPEN, or GCIH (or similar) certification
Required Skills
Advanced SOC analysis and incident response (Tier 3 escalation, correlation, containment, eradication)
SIEM-based detection and analysis, and SOC detection-rule tuning and false-positive reduction
Proactive threat hunting and threat-intelligence analysis (IOCs, IOAs, threat-actor TTPs)
Enterprise security technologies: IDS/IPS, firewalls, NAC, DLP, DAM, content filtering, endpoint protection, vulnerability scanning
Network and protocol expertise (TCP/IP) and digital-forensics techniques
Scripting and automation for security operations (PowerShell, Perl, Regex); SOP and runbook development
*Software / tools:* leading SIEM platforms, IDS/IPS, firewalls, EDR/endpoint protection, vulnerability scanners, malware-analysis and network-traffic-analysis tools
About Tecknomic
Tecknomic is a technical staffing firm partnering with government and Fortune 500 clients across manufacturing, engineering, and technology. We are an Equal Opportunity Employer and consider all qualified applicants without regard to race, color, religion, sex, national origin, disability, protected-veteran status, or any other protected characteristic.
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.
Free resume templatesImprove your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.
Free resume builder