SOC Tier 3 Analyst & Engineer

Posted One Month Ago
Be an Early Applicant
Santiago, Metropolitana de Santiago, CHL
In-Office
Mid level
Information Technology
The Role
Lead advanced analysis of escalated security events, perform proactive threat hunting and IOC ingestion, produce technical advisories and runbooks, coordinate incident response and remediation across teams, analyze logs/PCAP/NetFlow, and support OT/ICS security using SIEM, threat intelligence, and endpoint/network defenses.
Summary Generated by Built In

Job Description:

At DXC, we harness the power of technology to deliver mission-critical IT services that our clients need to modernize operations and drive innovation across their entire IT estate. We provide services through the Enterprise Technology Stack for business process outsourcing, analytics and engineering, applications, security, cloud, IT Outsourcing, and Modern Workplace.

About the role

Responsibilities:

  • Utilize advanced technical background and experience to scrutinize and provide corrective analysis to escalated cyber security events from Tier 1 & 2 analysts distinguishing these events from benign activities and escalating confirmed incidents to the Incident Response Lead.
  • Provide in-depth cyber security analysis, and trending/correlation of large datasets such as logs, event data, and alerts from diverse network devices and applications within the enterprise to identify and troubleshoot specific cyber security incidents and make informed technical recommendations that enable remediation efficiently.
  • Proactively search through log, network, and system data to find and identify undetected threats.
  • Identify and ingest indicators of compromise (IOC’s) (e.g., malicious IPs/URLs, etc.) into network security tools/applications to protect the clients network.
  • Quality-proof technical advisories and assessments prior to release from SOC.
  • Coordinate with and provide expert technical support to enterprise-wide technicians and staff to resolve confirmed incidents.
  • Report common and repeat problems, observed via trend analysis, to SOC management and propose process and technical improvements to improve the effectiveness and efficiency of alert notification and incident handling.
  • Formulate technical best-practice SOPs and Runbooks for SOC Analysts.
  • Respond to inbound requests via phone and other electronic means for technical assistance and resolve problems independently. Coordinate escalations with Service Delivery Lead and collaborate with internal technology teams to ensure timely resolution of issues.
  • Identifies, reports, and resolves security violations.
  • The role oversees a modern security ecosystem leveraging AI Agentic SIEM, OT environment with Nozomi, and Threat Intelligence platforms to deliver real-time visibility, rapid threat detection, and resilient cyber operations.

Skills and Qualifications:

  • Proficiency in English and Spanish, enabling effective communication with global stakeholders, vendors, and executive leadership teams.
  • At least 3-5 years of demonstrated operational experience as a cyber security analyst/engineer handling cyber security incidents and response in critical environments, and/or equivalent knowledge in areas such as: technical incident handling and analysis, intrusion detection, log analysis, penetration testing, vulnerability management.
  • In-depth understanding of: current cyber security threats, attacks and countermeasures for adversarial activities such as network probing and scanning, distributed denial of service (DDoS), phishing, ransomware, botnets, command and control (C2) activity, etc.
  • In-depth hands-on experience analyzing and responding to security events and incidents with most of the following technologies and/or techniques: security information and event management, (SIEM) technologies, intrusion detection/prevention systems (IDS/IPS), network and host-based firewalls, network access control (NAC), data leak protection (DLP), database activity monitoring (DAM), web and email content filtering, vulnerability scanning tools, endpoint protection, secure coding, etc.
  • Strong communication, interpersonal, organizational, oral, and customer service skills.
  • Strong knowledge of TCP/IP protocols, services, and networking.
  • Knowledge of forensic analysis techniques for common operating systems.
  • Adept at proactive search, solicitation, and detailed analysis of threat intelligence (e.g., exploits, IOCs, hacking tools, vulnerabilities, threat actor TTPs) derived from open-source resources and external entities, to identify cyber security threats and derive countermeasures, not previously ingested into network security tools/applications (external & internal threat hunting)
  • Excellent ability to multi-task, prioritize, and manage time and tasks effectively.
  • Ability to work effectively in stressful situations.
  • Strong attention to detail.
  • Strong understanding of command line scripting and implementation (i.e., Python, PowerShell, Bash Shell)
  • Ability to write new content/searches/scripts (e.g., CrowdStrike Falcon Next-Gen + AI & ONUM, Palo Alto Cortex XSIAM + AI, Microsoft Azure Sentinel, Splunk Enterprise Security, IBM QRadar, ManageEngine Log360, etc.)
  • Strong knowledge of Operational Technology (OT) environments, including SCADA systems, Industrial Control Systems (ICS), industrial network security, asset visibility, threat detection, and OT security solutions such as Nozomi Networks.
  • Experience with tools such as Active Directory, Cisco IOS, MS Server, AMP, CrowdStrike, Splunk ES, SNORT, Yara, IronPort, and Firepower.
  • Strong understanding of networking (TCP Flags, TCP Handshake, IP addressing, Firewalls, Proxy, IDS, IPS)
  • Ability to perform NetFlow / packet capture (PCAP) analysis
  • Information Technology security related certifications but not limited to: CompTIA A+, Network+, Security+, Linux, Cisco CCNA, MS (SC-*/AZ-*), AWS, CEH, CrowdStrike, Palo Alto Cortex XSIAM, CISSP, etc.

Preferred Skills: 

  • Certification desired - SANS GCIA, GCED, GPEN, GCIH or similar industry
  • Experience working with or in any of the following:
  • Computer Incident Response Team CIRT/CSIRT.
  • Computer Emergency Response Team CERT.
  • Computer Security Incident Response Center CSIRC.
  • Degree in Computer Science, Information Security or similar discipline.

Joining DXC connects you with brilliant people who embrace change and seize opportunities to advance their careers and amplify client success. At DXC, we support each other and work as a team, globally and locally. Our achievements demonstrate how we deliver excellence to our clients and colleagues. You will join a team committed to creating a culture of learning, diversity, and inclusion, dedicated to strong ethics and corporate citizenship.

At DXC Technology, we believe strong connections and community are key to our success. Our work model prioritizes in-person collaboration while offering flexibility to support wellbeing, productivity, individual work styles, and life circumstances. We’re committed to fostering an inclusive environment where everyone can thrive.

Recruitment fraud is a scheme in which fictitious job opportunities are offered to job seekers typically through online services, such as false websites, or through unsolicited emails claiming to be from the company. These emails may request recipients to provide personal information or to make payments as part of their illegitimate recruiting process. DXC does not make offers of employment via social media networks and DXC never asks for any money or payments from applicants at any point in the recruitment process, nor ask a job seeker to purchase IT or other equipment on our behalf. More information on employment scams is available here.

Skills Required

  • Bilingual: English and Spanish
  • Minimum 3-5 years operational experience as a cybersecurity analyst/engineer (incident handling and response)
  • Operational incident handling, intrusion detection, log analysis, penetration testing, vulnerability management
  • In-depth understanding of cyber threats and countermeasures (DDoS, phishing, ransomware, botnets, C2, scanning, etc.)
  • Hands-on experience with SIEM, IDS/IPS, network and host firewalls, NAC, DLP, DAM, web/email content filtering, vulnerability scanners, endpoint protection
  • Strong knowledge of TCP/IP protocols, networking concepts (TCP flags, handshake, IP addressing, firewalls, proxy, IDS/IPS)
  • Forensic analysis techniques for common operating systems
  • Proactive threat hunting, IOC identification and ingestion, threat intelligence analysis
  • Command-line scripting skills: Python, PowerShell, Bash
  • Ability to write searches/scripts and new content for platforms (CrowdStrike Falcon, Palo Alto Cortex XSIAM, Azure Sentinel, Splunk ES, IBM QRadar, ManageEngine Log360)
  • Operational Technology (OT) / SCADA / ICS security knowledge and familiarity with Nozomi Networks
  • Experience with Active Directory, Cisco IOS, Windows Server, AMP, CrowdStrike, Splunk ES, SNORT, Yara, IronPort, Firepower
  • NetFlow and packet capture (PCAP) analysis
  • Strong communication, interpersonal, organizational skills; ability to work under stress and multitask
  • Information security certifications (examples: CompTIA A+, Network+, Security+, Linux, Cisco CCNA, MS SC-/AZ-*, AWS, CEH, CrowdStrike, Palo Alto, CISSP)
  • SANS certifications (GCIA, GCED, GPEN, GCIH) or similar
  • Experience with CIRT/CSIRT/CERT/CSIRC teams
  • Degree in Computer Science, Information Security or similar discipline

DXC Technology Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about DXC Technology and has not been reviewed or approved by DXC Technology.

  • Healthcare Strength Health coverage includes multiple national carrier options and plan types, with HSA eligibility where applicable. Feedback suggests the medical, dental, and vision lineup is broad and comparable to large-firm offerings.
  • Retirement Support A 401(k) program with employer matching and an annual true-up is available, with standard vesting provisions. This structure can help employees capture matching contributions over the year if contribution rates vary.
  • Leave & Time Off Breadth Flexible or “unlimited” vacation is offered for many U.S. roles instead of accrual-based PTO. Feedback suggests the approach can support work-life balance when team norms allow adequate time away.

DXC Technology Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Ashburn, VA
86,261 Employees
Year Founded: 2017

What We Do

DXC Technology is a Fortune 500 global IT services leader. Our more than 130,000 people in 70-plus countries are entrusted by our customers to deliver what matters most. We use the power of technology to deliver mission critical IT services across the Enterprise Technology Stack to drive business impact. DXC is an employer of choice with strong values, and fosters a culture of inclusion, belonging and corporate citizenship. We are DXC.

Similar Jobs

Mastercard Logo Mastercard

Manager, Insights and Analytics Products LAC

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Santiago, Metropolitana de Santiago, CHL
38800 Employees

Mastercard Logo Mastercard

Consultant

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Santiago, Metropolitana de Santiago, CHL
38800 Employees

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Sr. Sales Associate III

eCommerce • Fashion • Retail • Sales • Wearables • Design
Remote or Hybrid
14 Locations
16000 Employees
15-20 Hourly

Domino Data Lab Logo Domino Data Lab

Support Engineer

Artificial Intelligence • Machine Learning
Remote or Hybrid
10 Locations
200 Employees

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account