More jobs:
Incident Responder SOC Analysts
Job in
Richmond, Henrico County, Virginia, 23214, USA
Listed on 2026-02-16
Listing for:
Triumph Services
Full Time
position Listed on 2026-02-16
Job specializations:
-
IT/Tech
Cybersecurity, Security Manager
Job Description & How to Apply Below
Incident Responder / SOC Analyst
Richmond, VA (ONSITE 3-4 days / week)
ONGOING, Long Term Contract (Auto renew every 6 months)
An organization is seeking a skilled Incident Responder / SOC Analyst to support and enhance its cybersecurity operations. This role plays a critical part in protecting the confidentiality, integrity, and availability of sensitive systems and data.
The analyst will investigate cybersecurity threats, respond to incidents, and strengthen ongoing detection and response capabilities. Responsibilities align with Tier 1 and Tier 2 SOC functions under the NICE framework.
Key ResponsibilitiesMonitoring & Detection
- Monitor and triage alerts from SIEM, EDR, and NDR tools to identify and validate true security events.
- Conduct incident investigations, assessing severity, scope, and impact
. - Analyze attack telemetry and convert raw data into actionable threat intelligence.
- Coordinate with senior cybersecurity staff or advanced analysts on complex investigations requiring deeper forensic analysis or malware reverse engineering.
- Utilize threat intelligence sources—IOCs, updated detections, frameworks like MITRE ATT&CK
, and relevant advisories—to strengthen detection capabilities. - Assist in designing and implementing containment strategies, including device isolation, account lockdown, and segmentation.
- Support recovery activities to restore systems securely and prevent recurrence.
- Update and refine incident response playbooks, procedures, and documentation based on lessons learned.
- Assist with SIEM tuning
, detection rule optimization, and reduction of false positives. - Prepare detailed incident reports for stakeholders, ensuring clarity and completeness.
- Thoroughly document investigation steps, evidence, timestamps, and actions taken in case management systems.
- Collect and preserve digital evidence according to standard operating procedures.
- Manage ticketing workflows, ensuring SLA compliance and effective handoff between shifts.
- Collaborate with leadership and engineering teams to improve alert quality and operational efficiency.
Candidates must meet the following essential requirements:
- 2–5 years of experience in cybersecurity operations, incident response, or a SOC environment.
- Strong understanding of:
- Incident Response Lifecycle (e.g.,
NIST 800-61
) - Threat intelligence & IOC correlation
- Network protocols (TCP/IP, DNS, HTTP) and log analysis
- Incident Response Lifecycle (e.g.,
- Proficiency with:
- SIEM platforms (Splunk, QRadar, Microsoft Sentinel, etc.)
- EDR tools (Crowd Strike, Microsoft Defender, Cisco Secure Endpoint, etc.)
- Threat intelligence platforms and IOC feeds
- Familiarity with incident handling concepts and identity management (Active Directory, Azure AD).
- Scripting experience using Power Shell or Python for automation and data parsing.
- Ability to contain and remediate incidents using established playbooks.
- Strong communication and documentation skills for technical and non-technical audiences.
These skills and credentials are not required but are highly desirable:
Education- Bachelor’s degree in Cybersecurity, IT, Computer Science, or a related field.
- CompTIA Security+,
CySA+ - GIAC certifications (e.g.,
GCIA, GCIH, GCFA
) - CISSP (in progress acceptable)
- Microsoft security certifications (
SC-900, SC-200
) - Splunk Core User or equivalent
- SOAR automation for incident response workflows
- Packet capture and analysis (e.g.,
Wireshark
) - Cloud security concepts and tooling (Azure, AWS)
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×