SOC Analyst Tier 3
Job Title: SOC Analyst Tier 3
Place of Performance: Springfield, VA
Experience Level: 5-8 years of experience
About JFL Consulting:
With more than 20 years of securing some of the U.S. Department of Defense and the Intelligence Community’s most critical networks, JFL Consulting, LLC provides advanced network security solutions to a range of US Government and US commercial clients.
Our cybersecurity operators are experts at assessing and defending mission-critical data and the networks that facilitate their operation. We are focused on delivering advanced products and industry best practices that meet each customer’s unique requirements. Visit
What We Offer:
- Salary: $140k- $180k
- 100% employer-paid medical, dental, and vision premiums for employees and dependents
- Flexible Spending Accounts (healthcare, dependent care, and commuter)
- Life insurance, short-term disability and long-term disability
- 401(k) with immediate vesting of company contribution
- Generous PTO policy (15 vacation, 5 sick, 2 personal days, 11 holidays)
- We support your growth through certification reimbursement, dedicated professional development funding, and company-provided access to online learning platforms
Job Overview:
We're looking for a SOC Analyst Tier 3 and Incident Responder, a senior analyst role in the SOC. This role leads the response to confirmed security incidents, conducts threat hunting operations, and provides deep technical analysis capability in the operations center. Tier 3/IR analysts are activated for severe incidents and are the primary interface to the Tier 4 SME and external response resources when needed.
Key Responsibilities:
- Provide Tier 3 escalation and resolution for the most complex incidents and outages escalating to the Tier 4 SME as needed with appropriate documentation
- Lead the response to Priority 1 and complex Priority 2 security incidents from detection through remediation
- Conduct proactive threat hunting operations to identify threats that have bypassed automated detection
- Perform advanced PCAP analysis, log analysis, memory forensics, and malware triage
- Contain and eradicate threats while coordinating with engineers for isolation and remediation
- Produce formal incident response reports for Priority 1 and Priority 2 incidents
- Develop and maintain threat hunting TTPs and playbooks
- Build new detection use cases from threat hunting findings and submit to SIEM engineer
- Serve as on-call incident responder
- Brief senior leadership during active high priority incidents
- Mentor Tier 1 and 2 analysts in investigation techniques and escalation decision-making
- Manage and own the SOC Event log for all events during the shifts
- Maintain situational awareness of the threat landscape and active campaigns
- Participate briefings and training sessions