About this role
Job title: SOC Analyst IV
About the Role Everforth ECS, on behalf of HelloRache, is seeking a SOC Analyst IV to join a premier, enterprise-scale cybersecurity program supporting a major federal civilian agency. This senior technical contributor will drive protection of highly sensitive data, modernize the agency's cyber posture, and help scale automation across a large federal IT environment. Location: Remote with proximity to the National Capital Region (NCR); salary range $120k-$140k.
What You'll Do
- Provide Tier III support for SIEM alert triage, forensic analysis, and escalation for the most complex security events.
- Maintain situational awareness across SOC tools and telemetry sources; lead shift handovers and maintain thorough documentation.
- Develop, review, and continuously improve SOPs and incident response playbooks; contribute to detection logic and automation initiatives.
- Support Red Team and Purple Team exercises to validate coverage and identify gaps; map adversary TTPs using MITRE ATT&CK.
- Conduct in-depth forensic analysis of endpoint, network, and cloud telemetry to support investigations and root cause analysis.
- Mentor Tier I and II analysts; collaborate with threat hunting, CTI, and security engineering teams.
- Produce high-quality incident reports, shift logs, and technical documentation for technical and executive audiences.
What We're Looking For
- U.S. citizenship; 6+ years of SOC experience with Tier III incident response, forensic analysis, and SIEM operations.
- Remote but within close proximity to the NCR; active Public Trust 6c clearance, or ability to obtain one.
- At least one certification: GCIA, CEH, or CompTIA Security+.
- Hands-on experience with SIEM platforms and endpoint telemetry in a federal or enterprise environment.
- Strong OS and networking fundamentals; experience with AWS native security capabilities.
- Deep understanding of NIST SP 800-61 and its practical application in a tiered SOC.
- Demonstrated ability to apply the MITRE ATT&CK framework to real-world investigations and improvements.
- Experience contributing to or developing incident response playbooks, SOPs, and lessons-learned documentation.
- Ability to lead shift handovers and maintain clear, accurate operational documentation; strong written and verbal communication.
Nice to Have
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent professional experience.
Compensation & Benefits
- Salary range: $120,000 - $140,000 per year USD.