SOC Tier 3 Analyst

Reposted 6 Days Ago
Be an Early Applicant
Portland, OR, USA
In-Office
Senior level
Artificial Intelligence • Cloud • Information Technology • Security • Software
The Role
The SOC Tier 3 Analyst leads complex incident analysis, validates investigative findings, coordinates technical responses, and mentors lower-tier SOC analysts.
Summary Generated by Built In
Job Summary & Responsibilities

Everforth ECS is seeking a SOC Tier 3 Analyst to work in our Portland, OR office. 

 

The SOC Analyst 3 supports the organization's security operations by leading complex incident analysis, validating advanced investigative findings, coordinating technical response actions, improving detection effectiveness, and mentoring lower-tier analysts. This role is the senior technical analysis and escalation tier within the SOC Analyst role family. 

The ideal candidate has advanced SOC, incident response, and detection-analysis experience; understands adversary tradecraft and enterprise security architecture; and can coordinate complex technical investigations while partnering with SOC leadership, threat hunting, threat intelligence, forensics, Splunk engineering, security engineering, and program stakeholders. 

 

This role involves shift work schedule to support our 24/7 operation, including weekends and holidays. Candidates must be flexible in their availability. While we make every effort to accommodate individual preferences, it's essential to understand that specific shift requests are not guaranteed and are assigned based on operational needs.

 

Key Responsibilities 

Advanced Incident Analysis & Escalation Leadership 

  • Lead analysis of complex, high-impact, multi-stage, or ambiguous security incidents across enterprise systems, cloud environments, identity platforms, endpoints, networks, and applications. 
  • Validate incident severity, scope, attack path, affected assets, affected accounts, likely root cause, and potential operational or business impact. 
  • Review and resolve escalated findings from SOC Analyst 1 and SOC Analyst 2, including disputed severity, inconclusive evidence, or multi-source correlation challenges. 
  • Provide technical facts, risk context, and recommended response priorities to SOC leadership for major incident handling and stakeholder communication. 

Technical Response Coordination 

  • Coordinate complex containment, eradication, and recovery support with Security Engineer, Senior Engineer, system owners, incident responders, and other technical teams. 
  • Define evidence collection requirements and coordinate handoff to Forensics Lead or Forensics Mid when formal acquisition, preservation, chain of custody, or deep forensic analysis is required. 
  • Guide investigation strategy, timeline development, technical response sequencing, and escalation decisions for complex incidents. 
  • Maintain alignment with approved incident response plans, playbooks, evidence-handling expectations, and leadership direction. 

Detection Effectiveness & Analytic Improvement 

  • Analyze adversary behaviors, attack patterns, vulnerabilities, threat intelligence, control gaps, and recurring incident trends to improve detection and response effectiveness. 
  • Define analytic requirements and validate correlation rules, alert logic, dashboards, use cases, and response playbooks for operational effectiveness. 
  • Map complex observed behaviors to MITRE ATT&CK and other applicable threat models to support analytic improvement and stakeholder reporting. 
  • Coordinate with SOC Threat Hunter to convert hunt findings into operational detections and with Senior Splunk Engineer or Splunk Architect/Lead for technical implementation. 

Reporting, Briefings & Knowledge Transfer 

  • Prepare or review complex incident summaries, technical timelines, investigation narratives, after-action inputs, and lessons-learned content. 
  • Communicate complex technical findings in clear operational, business, and risk language for SOC leadership, program stakeholders, and technical teams. 
  • Provide technical input to SOC Technical Writer for SOPs, playbooks, knowledge articles, and formal documentation products. 
  • Mentor SOC Analyst 1 and SOC Analyst 2 personnel through escalation review, coaching, analytic guidance, and quality feedback. 

Governance, Quality & Continuous Improvement 

  • Lead or support detection reviews, tabletop exercises, incident retrospectives, process assessments, and quality improvement activities. 
  • Identify recurring gaps in telemetry, tools, controls, workflows, documentation, or analyst training and coordinate corrective action requirements with the appropriate owner. 
  • Stay current with evolving cyber threats, vulnerabilities, adversary tradecraft, detection techniques, and security operations best practices. 
  • Translate lessons learned and threat developments into improved detections, procedures, escalation criteria, and analyst enablement materials. 
Preferred Qualifications
  • U.S. Citizenship with ability to obtain and maintain a DOE “L” clearance after start.
  • 5+ years of experience in SOC operations, incident response, detection engineering support, threat analysis, or advanced cybersecurity operations. 
  • Advanced experience using SIEM, EDR, log analysis, case management, and cross-tool correlation to investigate complex security incidents. 
  • Strong understanding of adversary tradecraft, MITRE ATT&CK, incident response lifecycle activities, evidence handling, detection logic, and enterprise security architecture. 
  • Experience leading complex investigations, validating technical findings, defining response priorities, and coordinating technical response across multiple teams. 
  • Experience developing or validating detection requirements, alert logic, analytic coverage, investigation workflows, or response playbooks. 
  • Strong written and verbal communication skills, including the ability to brief technical findings and mentor lower-tier analysts. 

Skills Required

  • 5+ years of experience in SOC operations or advanced cybersecurity operations.
  • Advanced experience using SIEM, EDR, log analysis, cross-tool correlation.
  • Strong understanding of adversary tradecraft and incident response lifecycle.
  • Experience leading complex investigations and technical response coordination.
  • Strong written and verbal communication skills.

ECS Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about ECS and has not been reviewed or approved by ECS.

  • Healthcare Strength ECS advertises multiple national-network medical plan options with HSA eligibility alongside dental and vision coverage. Coverage generally begins quickly and is paired with company-paid short- and long-term disability, adding stability to the health package.
  • Retirement Support A 401(k) with Safe Harbor and immediate vesting on employer contributions is emphasized, with an employer match available. Access to an employee stock purchase plan via the parent company provides an additional savings avenue.
  • Parental & Family Support Paid parental leave up to 30 days, adoption assistance, and other family-oriented leaves are highlighted. Feedback suggests these offerings add meaningful value beyond base pay for many roles.

ECS Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Fairfax, VA
2,129 Employees
Year Founded: 1993

What We Do

ECS, a segment of ASGN (NYSE: ASGN), delivers advanced solutions and services in cloud, cybersecurity, artificial intelligence (AI), machine learning (ML), application and IT modernization, and science and engineering. The company solves critical, complex challenges for customers across the U.S. public sector, defense, intelligence and commercial industries. ECS maintains partnerships with leading cloud, cybersecurity, and AI/ML providers and holds specialized certifications in their technologies. Headquartered in Fairfax, Virginia, ECS has more than 3,400 employees throughout the U.S. and has been recognized as a Top Workplace by The Washington Post for the last five years.

Similar Jobs

Optum Logo Optum

Primary Care Nurse Practitioner or Physician Associate - Albany, OR

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Corvallis, OR, USA
160000 Employees
105K-156K Annually

Optum Logo Optum

Medical Assistant - Corvallis, Albany, Philomath, OR

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Corvallis, OR, USA
160000 Employees
16-29 Hourly

CertifID Logo CertifID

Principal Product Manager

Legal Tech • Real Estate • Security • Software • Cybersecurity • PropTech
Easy Apply
Remote or Hybrid
3 Locations
130 Employees

Cox Enterprises Logo Cox Enterprises

Fraud Prevention Agent ( Autotrader/KBB)

Artificial Intelligence • Automotive • Greentech • Information Technology • Machine Learning • Software • Cybersecurity
Remote or Hybrid
United States
50000 Employees
22-33 Hourly

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account