CareerPlanSign in

Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

Baltimore, MD💼 Full-time🗓 2026-07-27 → 2026-09-30

Core

Lead advanced investigations and full lifecycle incident response for ransomware, APTs, zero-day exploits, insider threats, and credential theft across hybrid cloud and on-premises environments.

Role type

Senior IC Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

Builds

Incident response playbooks, forensic artifacts, detection rules, and technical reports for management

Domain

Cybersecurity, Incident Response, Digital Forensics, Threat Hunting

Required skills

Advanced incident response, forensic analysis, threat hunting, detection engineering, technical leadership, root cause analysis, attack timeline reconstruction, IOCs/IOAs/TTPs documentation

Preferred skills

Financial services industry experience, enterprise-scale incident investigation, DFIR engagement support, Active Directory Certificate Services (AD CS) abuse investigation

Technologies

Elastic Security, KQL, ES|QL/EQL, SQL, PowerShell, Python, CrowdStrike Falcon, Microsoft Defender XDR, Microsoft Entra ID, Microsoft 365, Azure, AWS, Kubernetes, MITRE ATT&CK, NIST CSF, NIST 800-61

Responsibilities

Lead advanced investigations involving ransomware, APTs, zero-day exploits, insider threats, credential theft, lateral movement, cloud compromise, and data exfiltration; Perform full lifecycle incident response including detection, triage, investigation, containment, eradication, recovery, validation, root cause analysis, and post-incident review; Investigate attacks spanning on-premises infrastructure, Windows and Linux servers, Active Directory, Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS platforms, APIs, containers, and Kubernetes; Perform forensic analysis of on-premises systems, endpoints, servers, virtual machines, cloud workloads, identity systems, SaaS applications, APIs, databases, and network devices; Analyze telemetry from EDR/XDR, NDR, SIEM, firewalls, IDS/IPS, WAF, VPN, DNS, DHCP, proxy, email security, cloud audit logs, API gateways, identity providers, application logs, and operating system logs; Develop detections and SIEM correlation rules using Elastic Security, KQL, ES|QL/EQL, SQL, PowerShell, and Python; Conduct proactive threat hunting using MITRE ATT&CK, behavioral analytics, and threat intelligence; Provide technical leadership and mentoring to Tier 1 and Tier 2 analysts; Support management with reporting, including producing technical reports documenting attack timelines, root cause, IOCs, IOAs, TTPs, and recommendations

Seniority

Senior, hands-on IC with leadership responsibilities

Sourced via workday · Listed on CareerPlan, which tracks 877,000+ jobs from 20+ sources.