More jobs:
SOC Mid-Level Analyst
Job in
Fairfax, Fairfax County, Virginia, 22032, USA
Listed on 2026-06-24
Listing for:
Electronic Consulting Services, Inc (ECS Federal)
Full Time
position Listed on 2026-06-24
Job specializations:
-
IT/Tech
Cybersecurity, Security Manager, IT Support
Job Description & How to Apply Below
ECS is seeking a SOC Mid-Level Analyst to work remotely . Please Note:
This position is contingent upon additional funding.
Position Summary
ECS is seeking a Mid-Level SOC Analyst with demonstrated experience supporting the development of processes, procedures, and automations to rapidly ingest, aggregate, correlate, normalize, and analyze event messages to rapidly and assuredly identify and respond to Indicators of Compromise (IoC). The ideal candidate is a critical thinker and perpetual learner who is excited to solve some of our clients' toughest challenges.
To be successful the candidate must have experience working in a mature 24x7x365 Security Operation Center.
Shift schedule: Sunday-Wednesday, 7:00AM - 5:00PM ET (subject to change)
This role involves shift work schedule to support our 24/7 operation, including weekends and holidays. Candidates must be flexible in their availability. While we make every effort to accommodate individual preferences, it's essential to understand that specific shift requests are not guaranteed and are assigned based on operational needs.
Responsibilities include:
Escalated Alert Investigation & Correlation
- Review and investigate alerts escalated by SOC Analyst 1 or automated SOC workflows to validate severity, scope, potential impact, and required response actions.
- Analyze suspicious activity, indicators of compromise, anomalous behavior, and policy violations using logs, endpoint telemetry, network data, identity data, cloud events, and other evidence.
- Correlate evidence across security platforms to identify affected assets, affected accounts, attack paths, timeline of activity, and potential business or mission impact.
- Map observed behaviors to applicable frameworks and threat models such as MITRE ATT&CK when useful for investigation, reporting, or detection improvement.
- Support containment, eradication, and recovery activities for standard or moderate incidents in alignment with incident response plans and approved playbooks.
- Coordinate with system owners, security engineers, senior analysts, and other technical teams to gather evidence, validate impact, and support response actions.
- Escalate complex, high-impact, evidence-sensitive, or ambiguous incidents to SOC Analyst 3, SOC leadership, Forensics, Threat Hunter, Threat Intelligence Analyst, or other specialized roles as appropriate.
- Maintain accurate incident status, action tracking, and communications during investigation and response activities.
- Analyze recurring alerts, false positives, attack patterns, threat intelligence, vulnerabilities, and emerging tactics to identify opportunities to improve detection and response.
- Recommend updates to correlation rules, alert logic, dashboards, use cases, response playbooks, and triage procedures based on investigation outcomes.
- Operationalize threat intelligence in triage and investigation workflows by applying relevant indicators, adversary behaviors, vulnerabilities, and contextual reporting.
- Document investigation activities, evidence, decisions, response actions, and outcomes clearly and accurately.
- Prepare incident summaries, ticket updates, timelines, shift handoff notes, and supporting information for after-action documentation.
- Communicate technical findings in clear operational, business, and risk language for SOC leadership and affected stakeholders.
- Provide evidence summaries and analysis notes that can be used by Forensics or specialized teams when deeper analysis is required.
- Provide escalation guidance, quality feedback, and informal mentoring to SOC junior analysts personnel.
- Participate in lessons-learned activities, tabletop exercises, detection reviews, and SOC process improvement efforts.
- Stay current with evolving cyber threats, vulnerabilities, detection techniques, and security operations best practices.
- Contribute to continuous improvement of SOC workflows, investigation checklists, documentation practices, and escalation procedures.
General Description of Benefits
Re…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×