SOC Analyst (SR.)

ECS Tech IncWork from home, Virginia
Remote

About The Position

Everforth ECS is seeking a Senior SOC Analyst to work remotely. At Everforth ECS Federal, we're driven by a commitment to excellence and innovation in solving complex challenges. As a premier provider of advanced technology solutions and services, our mission is to secure and optimize the most critical commercial, government, defense, and intelligence projects across the country. Our team is composed of dynamic professionals who thrive in a collaborative and empowering environment, where our team members leverage the latest technologies and insights to make a real-world impact. Join us and be part of a forward-thinking organization that values your expertise and supports your professional growth. The Senior SOC Analyst is responsible for advanced security monitoring, investigation, and incident response activities within the Everforth Security Operations Center (SOC). This role serves as a senior technical resource within the analyst team, responsible for leading complex investigations, mentoring junior analysts, and ensuring high-quality incident analysis across enterprise environments. The Senior SOC Analyst plays a critical role in identifying sophisticated threats, escalating security incidents, and improving SOC investigative capabilities. This role reports to the SOC Manager and works closely with the Security Engineering team, enterprise IT operations teams, and the Everforth Commercial MSSP to ensure effective monitoring, investigation, and response across the enterprise.

Requirements

  • Minimum of 5 years of cybersecurity experience, with at least 3 years in a Security Operations Center or incident response role.
  • Strong experience investigating security alerts, analyzing suspicious activity, and determining the scope and impact of security incidents.
  • Hands-on experience supporting incident response investigations including containment, eradication, and recovery coordination.
  • Experience working with enterprise security tools such as SIEM platforms, EDR platforms, and log analysis systems.
  • Ability to analyze indicators of compromise, attacker behaviors, and adversary techniques during investigations.
  • Strong experience reviewing and interpreting system logs, endpoint telemetry, network events, and authentication activity.
  • Experience developing or tuning detection rules, analytics, or monitoring logic used to identify malicious activity.
  • Familiarity with cybersecurity frameworks such as NIST Cybersecurity Framework or CIS Critical Security Controls.
  • Experience documenting investigations, incidents, and response actions within case management platforms.
  • Able and willing to obtain a US Security Clearance.
  • This role may require occasional on-call support during off-hours to respond to security incidents.

Responsibilities

  • Conduct in-depth analysis of complex security alerts, anomalies, and potential threat activity across enterprise environments.
  • Lead investigation and response activities for confirmed or suspected cybersecurity incidents affecting enterprise systems.
  • Perform detailed triage of security alerts and escalate validated incidents according to established procedures.
  • Serve as the lead analyst during significant investigations, coordinating investigative efforts and guiding response activities.
  • Analyze indicators of compromise, attacker behavior, and malicious artifacts to determine the scope and impact of security incidents.
  • Develop and refine detection logic, analytics, and monitoring use cases based on investigative findings and threat intelligence.
  • Conduct proactive threat hunting activities to identify adversary behavior not detected through automated alerts.
  • Review and validate alerts and escalations originating from the MSSP after-hours monitoring team.
  • Ensure thorough documentation of investigations, findings, and response actions within the SOC case management platform.
  • Support the SOC Manager in maintaining investigation quality and adherence to SOC playbooks and procedures.
  • Leads the design and implementation of SOC process improvements through automation, AI-driven solutions, workflow optimization, and continuous enhancement of detection and response capabilities.
  • Work closely with IT operations, infrastructure teams, and security engineering to support investigation and remediation activities.
  • Mentor junior SOC analysts and provide guidance on investigative techniques, threat analysis, and incident handling procedures.
  • Maintain awareness of emerging threats, attacker tactics, techniques, and procedures relevant to enterprise environments.
  • Execute established SOC investigation playbooks and contribute to the refinement of operational procedures.
  • Participates in on-call support to assist with security incident response, operational issues, and investigation activities to maintain continuous SOC coverage and response capability.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service