Soc Tier 3 Analyst

Global Alliant•Crownsville, MD
•Hybrid

About The Position

This is a full-time, hybrid position for a SOC Tier 3 Analyst located in Crownsville, MD. The role requires US citizenship due to federal regulations and the sensitive nature of the work. The analyst will be responsible for planning, initiating, and conducting forensic investigations, analyzing attacker tools and techniques, developing and tuning detection rules, and conducting threat hunting. The position also involves providing technical leadership, training SOC analysts, and assisting with the development of SOC tiered monitoring and escalation processes. The analyst will support Tier 1 & 2 SOC personnel and provide technical expertise in areas such as End Point Protection and Response, Vulnerability Management, and Security Operations Expansion. Responsibilities include engineering and implementing cybersecurity monitoring and analysis tools, reviewing and triaging security alerts in Sentinel, and using various tools to investigate cyber incidents. Additional duties may include security program development, documentation, threat hunting, vulnerability management, technical and risk assessment, and security engineering.

Requirements

  • US citizenship because of federal regulations and the sensitive nature of the work involved.
  • Bachelor’s degree in Computer Science, Information Systems, Engineering, or a related technical/scientific discipline.
  • 10+ years of relevant experience in cybersecurity, digital forensics, or incident response.
  • Proficiency with forensic tools.
  • SIEM platforms (Sentinel).
  • Malware analysis.
  • Network traffic analysis.
  • Threat intelligence gathering.
  • Hybrid position – Must be able to work at the Crownsville office 2–3 times a week or rotation schedule with other Tier 3 Analysts.
  • Strong leadership and communication skills.

Nice To Haves

  • GREM, CEH, CHFI, GCFE, GIAC, or similar cybersecurity/forensics credentials are preferred.

Responsibilities

  • Plan, initiate, and conduct forensic investigations on compromised systems.
  • Perform root cause and scope-of-impact analysis.
  • Create detailed forensic reports.
  • Support malware analysis of attacker tools and techniques.
  • Identify and analyze malicious payloads.
  • Train SOC analysts on SIEM tools (e.g., Sentinel).
  • Develop and tune detection rules.
  • Assist in creating new SOC monitoring processes.
  • Correlate actionable security events.
  • Review threat data.
  • Develop custom detection signatures.
  • Conduct threat hunting to identify advanced threats.
  • Contribute to technical briefings.
  • Develop incident response procedures.
  • Ensure adherence to operational and technical standards.
  • May require availability outside regular hours or on weekends to respond to critical incidents.
  • Assists with the development of Security Operation Center (SOC) tiered monitoring and escalation processes.
  • Provides support for SOC Analyst Tier 1 & 2 personnel.
  • Provides technical expertise in the development of existing Cybersecurity projects and initiatives to include but not limited to: End Point Protection and Response, Vulnerability Management, Security Operations Expansion.
  • Provides technical expertise & support in Cybersecurity monitoring and analysis tool engineering and implementation.
  • Reviews, evaluates, and triages security alerts in Sentinel using dashboards, reports, and custom queries.
  • Uses tools, such as captured network traffic, intrusion detection software and Sentinel instrumentation to investigate possible cyber incidents.
  • Other security program development, documentation, security monitoring, threat hunting, vulnerability management, technical and risk assessment, and security engineering duties assigned by OSM SOC and senior management.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service