See all roles

Cbo - tier 3 soc analyst

Work from home Full-time role Hiring

cFocus Software seeks a Tier 3 SOC Analyst to join our program supporting the Congressional Budget Office (CBO). This position is remote. This position requires a Public Trust clearance. Qualifications:

  • Active Public Trust clearance
  • B.S. Computer Science, Information Technology, or a related field
  • 5+ years of SOC Analyst experience
  • Expert knowledge of incident response, threat hunting, and detection engineering
  • Advanced experience with Microsoft Sentinel (SIEM) and Microsoft Defender tools
  • Strong understanding of MITRE ATT&CK framework and adversary tactics
  • Experience with digital forensics and malware analysis techniques
  • Ability to analyze logs across identity, endpoint, network, and cloud environments
  • Strong knowledge of AWS logs (CloudTrail, VPC Flow Logs) and enterprise security tools
  • Experience with KQL (Kusto Query Language) and advanced correlation analysis
  • Deep understanding of NIST frameworks (800-53, 800-61, 800-92) and Zero Trust principles
  • Experience with SOAR platforms and automation (Logic Apps, Sentinel playbooks)
  • Experience supporting federal environments and compliance (CUI, FTI, NIST, IRS 1075)
  • Experience leading incident response engagements and reporting to leadership

Preferred certifications include but are not limited to

  • GCIA, GCIH, CISSP, CEH, or equivalent cybersecurity certifications
  • Microsoft Sentinel or Microsoft security platform certifications
  • Relevant cloud security certifications (e.g., AWS security)
  • Privacy certifications (e.g., CIPP/US, CIPM) where applicable

Duties:

  • Lead investigation and response for complex and high-severity security incidents
  • Perform advanced threat hunting using Microsoft Sentinel and Defender platforms
  • Conduct digital forensics, malware analysis, and root cause analysis (RCA)
  • Develop, tune, and optimize detection rules, analytics, and correlation logic
  • Map detections and activities to MITRE ATT&CK framework
  • Oversee incident lifecycle management (detection through containment, eradication, and recovery)
  • Support and improve SOC playbooks, automation workflows, and response procedures
  • Provide mentorship and guidance to Tier I and Tier II analysts
  • Identify security control gaps and recommend remediation strategies
  • Support red team, purple team, and adversary emulation exercises
  • Contribute to incident reports, quarterly threat reviews, and executive briefings

Apply tot his job Apply To this Job

You might like

SOC Tier III Analyst / Threat Hunter | WINTrio LLC

Work from home Full-time role

[Remote] Security Operations Center Analyst II - Remote

Work from home Full-time role

SOC Analyst - Contract - Candidate is local to Columbia, SC

Work from home Full-time role

Jr. SOC Analyst

Work from home Full-time role

XTN-2584703 | L3 SOC ANALYST

Work from home Full-time role

Sr. SOC Analyst

Work from home Full-time role

Senior SOC OT Security Consultant Engineer

Work from home Full-time role

SOC Analyst; L2

Work from home Full-time role

Tier 1 Analyst

Work from home Full-time role

Junior Cyber Defender (SOC Analyst)

Work from home Full-time role

Litigation Administrative Assistant

Work from home Full-time role

Web Development Intern

Work from home Full-time role

Experienced Customer Success Expert – Delivering Exceptional Service and Building Meaningful Relationships at arenaflex

Work from home Full-time role

CAP Petite Enfance (AEPE) en Alternance (H/F)

Work from home Full-time role

Technical Solutions Consultant - SQL (Remote - Mexico Only)

Work from home Full-time role

Experienced Virtual Customer Care Representative – Community Management and Customer Relations

Work from home Full-time role

Machine Tool Service Engineer

Work from home Full-time role

Experienced Customer Service Representative - Remote Opportunity with arenaflex

Work from home Full-time role

Experienced Data Entry Specialist – Supporting Operational Excellence at arenaflex

Work from home Full-time role

Experienced Remote Customer Interaction Specialist – Thriving in a Dynamic arenaflex Environment

Work from home Full-time role