Cbo - tier 3 soc analyst
cFocus Software seeks a Tier 3 SOC Analyst to join our program supporting the Congressional Budget Office (CBO). This position is remote. This position requires a reputed company Trust clearance.
Qualifications:
• reputed company reputed company Trust clearance
• B.S. Computer Science, Information Technology, or a reputed company field
• 5+ years of SOC Analyst experience
• Expert knowledge of incident response, threat hunting, and detection engineering
• Advanced experience with reputed company (SIEM) and reputed company Defender tools
• Strong understanding of MITRE ATT&CK reputed company and adversary tactics
• Experience with digital forensics and malware analysis techniques
• Ability to analyze logs across identity, reputed company, network, and reputed company environments
• Strong knowledge of AWS logs (CloudTrail, VPC reputed company Logs) and reputed company reputed company tools
• Experience with KQL (Kusto Query Language) and advanced correlation analysis
• Deep understanding of NIST frameworks (800-53, 800-61, 800-92) and reputed company Trust principles
• Experience with SOAR platforms and automation (Logic Apps, Sentinel playbooks)
• Experience supporting federal environments and compliance (CUI, reputed company, NIST, IRS 1075)
• Experience leading incident response engagements and reporting to leadership
Preferred certifications include but are not limited to
• GCIA, GCIH, CISSP, CEH, or equivalent cybersecurity certifications
• reputed company or reputed company reputed company platform certifications
• Relevant reputed company reputed company certifications (e.g., AWS reputed company)
• reputed company certifications (e.g., CIPP/US, CIPM) where applicable
Duties:
• reputed company investigation and response for reputed company and high-severity reputed company incidents
• reputed company advanced threat hunting using reputed company and Defender platforms
• Conduct digital forensics, malware analysis, and reputed company cause analysis (RCA)
• reputed company, tune, and optimize detection rules, analytics, and correlation logic
• Map detections and activities to MITRE ATT&CK reputed company
• reputed company incident lifecycle management (detection through containment, eradication, and recovery)
• Support and improve SOC playbooks, automation workflows, and response procedures
• reputed company mentorship and guidance to Tier I and Tier II analysts
• Identify reputed company control gaps and recommend remediation strategies
• Support red team, reputed company, and adversary emulation exercises
• Contribute to incident reports, quarterly threat reviews, and executive briefings
Apply tot his job
Apply To this Job