Security Operations Center (SOC) Tier 3 Analyst Incident Responder
Baltimore, MD - USA
Job Summary
- Lead advanced investigations involving ransomware APTs zero-day exploits insider threats credential theft lateral movement cloud compromise on-premises systems VDI SaaS API abuse business email compromise certificate abuse and data exfiltration.
- Perform full lifecycle incident response including detection triage investigation containment eradication recovery validation root cause analysis and post-incident review.
- Investigate attacks spanning on-premises infrastructure Windows and Linux servers Active Directory Active Directory Certificate Services (AD CS) Microsoft Entra ID Microsoft 365 Azure AWS VDI SaaS platforms APIs containers Kubernetes databases enterprise applications and hybrid cloud environments.
- Perform forensic analysis of on-premises systems endpoints servers virtual machines VDI cloud workloads identity systems SaaS applications APIs databases and network devices.
- Analyze telemetry from EDR/XDR NDR SIEM firewalls IDS/IPS WAF VPN DNS DHCP proxy email security cloud audit logs API gateways identity providers application logs and operating system logs.
- Develop detections and SIEM correlation rules using Elastic Security KQL ESQL/EQL SQL PowerShell and Python.
- Conduct proactive threat hunting using MITRE ATT&CK behavioral analytics and threat intelligence.
- Provide technical leadership and mentoring to Tier 1 and Tier 2 analysts.
- Support management with reporting including producing technical reports documenting attack timelines root cause IOCs IOAs TTPs and recommendations.
- Expert knowledge of SIEM SOAR EDR/XDR NDR IDS/IPS WAF firewalls email security web proxies CASB DLP IAM PAM API security and cloud-native security technologies.
- Expert experience with Elastic Security (ELK) CrowdStrike Falcon Microsoft Defender XDR Defender for Endpoint Defender for Identity Defender for Office 365 Defender for Cloud and Defender for Cloud Apps.
- Deep understanding of on-premises infrastructure including Windows Server Linux Active Directory Active Directory Certificate Services (AD CS) VMware Hyper-V storage virtualization networking Microsoft Entra ID Microsoft 365 Azure AWS VDI SaaS APIs containers Kubernetes databases and hybrid cloud architectures.
- Expert knowledge of TCP/IP DNS DHCP VPN routing switching PKI Kerberos NTLM OAuth OIDC SAML JWT and certificate-based authentication.
- Advanced proficiency investigating on-premises systems cloud environments endpoints servers identity platforms VDI SaaS applications APIs databases enterprise applications and AD CS/PKI-related attacks.
- Expert proficiency with KQL ESQL/EQL SQL PowerShell Python and Bash.
- Deep knowledge of MITRE ATT&CK MITRE D3FEND Cyber Kill Chain NIST CSF NIST 800-61 OWASP Top 10 malware analysis digital forensics and attacker methodologies.
- Minimum two certifications such as GCFA GCFE GCIH GCIA GREM CISSP SC-200 SC-100 AWS Certified Security Specialty or equivalent.
- Bachelors degree in Cybersecurity Computer Science Information Technology or equivalent experience.
- Experience in financial services or another highly regulated industry.
- Experience investigating enterprise incidents across Microsoft 365 Azure AWS Elastic CrowdStrike and hybrid environments.
- Experience supporting DFIR engagements involving ransomware nation-state threats insider threats enterprise-scale incidents and Active Directory Certificate Services (AD CS) abuse.
- Minimum 8 years of progressive cybersecurity experience.
- Minimum 6 years of hands-on Security Operations Center experience.
- Minimum 4 years leading complex enterprise incident investigations.
- Minimum 2 years performing advanced digital forensics threat hunting and detection engineering.
- Proven experience independently investigating incidents from initial alert through full remediation across on-premises infrastructure enterprise networks endpoints identity platforms Microsoft 365 Azure AWS VDI SaaS applications APIs Elastic Security hybrid cloud environments and PKI/AD CS.
OneMain Holdings Inc. is an Equal Employment Opportunity (EEO) employer. Qualified applicants will receive consideration for employment without regard to age ancestry citizenship status color creed culture disability ethnicity gender gender identity or expression genetic information or history marital status military status national origin nationality pregnancy race religion sex sexual orientation socioeconomic status transgender or on any other basis protected by law.
Required Experience:
IC
About Company
Sometimes unexpected costs occur, so trust OneMain to provide personal loans for home improvement, debt consolidation, car purchases, & more.