> Markdown version of [/jobs/ext/1437474-soc-analyst-tier-3](https://www.wearedevelopers.com/jobs/ext/1437474-soc-analyst-tier-3). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SOC Analyst Tier 3 - **Company:** Jfl Consulting, Llc - **Location:** Springfield, VA, United States - **Experience:** Expert - **Salary:** $140,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Query Languages, Event Logging, Pcap, Log Analysis, Network Forensics, Kusto Query Language, Reverse Engineering, Security Information and Event Management, Wireshark, Mitre Att&ck, Malware, SC Clearance, Information Technology, IDA Pro, Cybercrime, 3-tier Architectures - **Published:** July 25, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9056858/soc-analyst-tier-3 ## About the Role * 5+ years of SOC, threat hunting or incident response type experience * Bachelor's degree in Cyber Security, Information Technology, Computer Science, Information Security, or related field. In lieu of degree, four additional years of experience in a NOC, SOC, IT security, or network engineering role * Two of the following certifications, equivalent or better: Sec+, CYSA+, GCIH, SecX, CEH, GCIA, GSOC, CISSP * Demonstrated hands-on incident response experience including containment, eradication, and recovery * Proficiency with SIEM platforms and log analysis * Proficiency with SIEM query languages - SPL, KQL, or equivalent * Proficiency with PCAP analysis tools (Wireshark, NetworkMiner, or equivalent) * Experience with EDR, endpoint forensics, memory analysis, and network forensics tools * Deep understanding of attacker TTPs, kill chain methodology, and MITRE ATT&CK * Ability to work shifts including nights, weekends, and holidays on rotating shift schedule, * GCFA or GCFE certification or other forensic certifications * Active Secret clearance preferred but not required * Experience with threat hunting frameworks and platforms * Reverse engineering experience (IDA Pro, Ghidra) * Prior experience on a DFIR team or incident response retainer * Experience with malware analysis (static and dynamic) ## Description We're looking for a SOC Analyst Tier 3 and Incident Responder, a senior analyst role in the SOC. This role leads the response to confirmed security incidents, conducts threat hunting operations, and provides deep technical analysis capability in the operations center. Tier 3/IR analysts are activated for severe incidents and are the primary interface to the Tier 4 SME and external response resources when needed., * Provide Tier 3 escalation and resolution for the most complex incidents and outages escalating to the Tier 4 SME as needed with appropriate documentation * Lead the response to Priority 1 and complex Priority 2 security incidents from detection through remediation * Conduct proactive threat hunting operations to identify threats that have bypassed automated detection * Perform advanced PCAP analysis, log analysis, memory forensics, and malware triage * Contain and eradicate threats while coordinating with engineers for isolation and remediation * Produce formal incident response reports for Priority 1 and Priority 2 incidents * Develop and maintain threat hunting TTPs and playbooks * Build new detection use cases from threat hunting findings and submit to SIEM engineer * Serve as on-call incident responder * Brief senior leadership during active high priority incidents * Mentor Tier 1 and 2 analysts in investigation techniques and escalation decision-making * Manage and own the SOC Event log for all events during the shifts * Maintain situational awareness of the threat landscape and active campaigns * Participate briefings and training sessions ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [WeAreDevelopers LIVE - Yes, CSS Can Do That!](https://www.wearedevelopers.com/videos/1819-wearedevelopers-live-yes-css-can-do-that) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)