ECS · 3 weeks ago
SOC Analyst IV
ECS is seeking a SOC Analyst IV to join a premier cybersecurity program supporting a major federal civilian agency. This role involves providing advanced technical support, leading complex investigations, and mentoring junior analysts while ensuring the agency's cybersecurity posture is robust and effective.
E-Commerce
Responsibilities
Provide Tier III support for SIEM alert triage, forensic analysis, and escalation, handling the most complex and high-priority security events within the SOC environment
Maintain situational awareness across all SOC tools and telemetry sources, ensuring continuous visibility into the agency's security posture
Lead shift handovers with clear, thorough documentation, ensuring seamless operational continuity across all SOC shifts
Contribute to the development, review, and ongoing improvement of standard operating procedures (SOPs) and incident response playbooks to ensure they remain current, accurate, and operationally effective
Support Red Team and Purple Team exercises to validate detection coverage, improve response procedures, and identify gaps in the SOC's defensive capabilities
Apply the MITRE ATT&CK framework to map adversary tactics, techniques, and procedures (TTPs) during investigations, turning fragmented alerts into clear and actionable threat narratives
Conduct in-depth forensic analysis of endpoint, network, and cloud telemetry to support incident investigations and root cause analysis activities
Support and contribute to the four phases of the NIST SP 800-61 incident response lifecycle, Preparation, Detection and Analysis, Containment/Eradication/Recovery, and Post-Incident Activity, ensuring thorough documentation and stakeholder communication at each stage
Mentor and provide technical guidance to Tier I and Tier II SOC analysts, supporting their professional development and improving overall team capability
Collaborate with threat hunting, CTI, and security engineering teams to operationalize new detection logic and ensure the SOC benefits from the latest intelligence
Produce high-quality incident reports, shift logs, and technical documentation for both technical teams and senior government officials
Contribute to detection engineering and automation initiatives to reduce manual workload and improve analyst efficiency across the SOC
Qualification
Required
Experience providing Tier III support for SIEM alert triage, forensic analysis, and escalation
Ability to handle complex and high-priority security events within the SOC environment
Experience maintaining situational awareness across SOC tools and telemetry sources
Ability to lead shift handovers with clear, thorough documentation
Experience contributing to the development, review, and ongoing improvement of standard operating procedures (SOPs) and incident response playbooks
Experience supporting Red Team and Purple Team exercises
Ability to apply the MITRE ATT&CK framework to map adversary tactics, techniques, and procedures (TTPs)
Experience conducting in-depth forensic analysis of endpoint, network, and cloud telemetry
Experience supporting the four phases of the NIST SP 800-61 incident response lifecycle
Ability to mentor and provide technical guidance to Tier I and Tier II SOC analysts
Experience collaborating with threat hunting, CTI, and security engineering teams
Ability to produce high-quality incident reports, shift logs, and technical documentation
Experience contributing to detection engineering and automation initiatives
Company
ECS
ECS's history is an inalienable part of the history of the city of Lahore and history of Pakistani enterprise.
Funding
Current Stage
Late StageCompany data provided by crunchbase