Demo

Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

OneMain Financial
Baltimore, MD Full Time
POSTED ON 9/23/2026
AVAILABLE BEFORE 11/22/2026

Key Responsibilities

  • Lead advanced investigations involving ransomware, APTs, zero-day exploits, insider threats, credential theft, lateral movement, cloud compromise, on-premises systems, VDI, SaaS, API abuse, business email compromise, certificate abuse, and data exfiltration.
  • Perform full lifecycle incident response including detection, triage, investigation, containment, eradication, recovery, validation, root cause analysis, and post-incident review.
  • Investigate attacks spanning on-premises infrastructure, Windows and Linux servers, Active Directory, Active Directory Certificate Services (AD CS), Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS platforms, APIs, containers, Kubernetes, databases, enterprise applications, and hybrid cloud environments.
  • Perform forensic analysis of on-premises systems, endpoints, servers, virtual machines, VDI, cloud workloads, identity systems, SaaS applications, APIs, databases, and network devices.
  • Analyze telemetry from EDR/XDR, NDR, SIEM, firewalls, IDS/IPS, WAF, VPN, DNS, DHCP, proxy, email security, cloud audit logs, API gateways, identity providers, application logs, and operating system logs.
  • Develop detections and SIEM correlation rules using Elastic Security, KQL, ES|QL/EQL, SQL, PowerShell, and Python.
  • Conduct proactive threat hunting using MITRE ATT&CK, behavioral analytics, and threat intelligence.
  • Provide technical leadership and mentoring to Tier 1 and Tier 2 analysts.
  • Support management with reporting, including producing technical reports documenting attack timelines, root cause, IOCs, IOAs, TTPs, and recommendations.

Required Qualifications

  • Expert knowledge of SIEM, SOAR, EDR/XDR, NDR, IDS/IPS, WAF, firewalls, email security, web proxies, CASB, DLP, IAM, PAM, API security, and cloud-native security technologies.
  • Expert experience with Elastic Security (ELK), CrowdStrike Falcon, Microsoft Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud, and Defender for Cloud Apps.
  • Deep understanding of on-premises infrastructure including Windows Server, Linux, Active Directory, Active Directory Certificate Services (AD CS), VMware, Hyper-V, storage, virtualization, networking, Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS, APIs, containers, Kubernetes, databases, and hybrid cloud architectures.
  • Expert knowledge of TCP/IP, DNS, DHCP, VPN, routing, switching, PKI, Kerberos, NTLM, OAuth, OIDC, SAML, JWT, and certificate-based authentication.
  • Advanced proficiency investigating on-premises systems, cloud environments, endpoints, servers, identity platforms, VDI, SaaS applications, APIs, databases, enterprise applications, and AD CS/PKI-related attacks.
  • Expert proficiency with KQL, ES|QL/EQL, SQL, PowerShell, Python, and Bash.
  • Deep knowledge of MITRE ATT&CK, MITRE D3FEND, Cyber Kill Chain, NIST CSF, NIST 800-61, OWASP Top 10, malware analysis, digital forensics, and attacker methodologies.
  • Minimum two certifications such as GCFA, GCFE, GCIH, GCIA, GREM, CISSP, SC-200, SC-100, AWS Certified Security – Specialty, or equivalent.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent experience.

Preferred Qualifications

  • Experience in financial services or another highly regulated industry.
  • Experience investigating enterprise incidents across Microsoft 365, Azure, AWS, Elastic, CrowdStrike, and hybrid environments.
  • Experience supporting DFIR engagements involving ransomware, nation-state threats, insider threats, enterprise-scale incidents, and Active Directory Certificate Services (AD CS) abuse.

Experience Requirements

  • Minimum 8 years of progressive cybersecurity experience.
  • Minimum 6 years of hands-on Security Operations Center experience.
  • Minimum 4 years leading complex enterprise incident investigations.
  • Minimum 2 years performing advanced digital forensics, threat hunting, and detection engineering.
  • Proven experience independently investigating incidents from initial alert through full remediation across on-premises infrastructure, enterprise networks, endpoints, identity platforms, Microsoft 365, Azure, AWS, VDI, SaaS applications, APIs, Elastic Security, hybrid cloud environments, and PKI/AD CS.

Salary.com Estimation for Security Operations Center (SOC) Tier 3 Analyst / Incident Responder in Baltimore, MD
$97,240 to $123,829
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Security Operations Center (SOC) Tier 3 Analyst / Incident Responder?

Sign up to receive alerts about other jobs on the Security Operations Center (SOC) Tier 3 Analyst / Incident Responder career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$87,466 - $114,731
Income Estimation: 
$114,790 - $146,930
Income Estimation: 
$115,647 - $153,495
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$220,784 - $286,649
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at OneMain Financial

  • OneMain Financial Wilmington, DE
  • Campaign Execution Manager, Direct Marketing Apply Now Full Job Title: Campaign Execution Manager, Direct Marketing Job Number: R2409-42871 Location: Wilmi... more
  • Just Posted

  • OneMain Financial Wilmington, DE
  • VP/Director, Credit and Pricing Analytics Apply Now Full Job Title: VP/Director, Credit and Pricing Analytics Job Number: R2409-42956 Location: Wilmington,... more
  • Just Posted

  • OneMain Financial Wilmington, DE
  • VP/Managing Director of Operations (Collections) Apply Now Full Job Title: VP/Managing Director of Operations (Collections) Job Number: R2411-43955 Locatio... more
  • Just Posted

  • OneMain Financial Wilmington, DE
  • VP/MD Collections Strategy Apply Now Full Job Title: VP/MD Collections Strategy Job Number: R2502-44809 Location: Wilmington, Delaware Date Posted: 02/03/2... more
  • Just Posted


Not the job you're looking for? Here are some other Security Operations Center (SOC) Tier 3 Analyst / Incident Responder jobs in the Baltimore, MD area that may be a better fit.

  • Deloitte US Baltimore, MD
  • Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions t... more
  • 1 Month Ago

  • Lockheed Martin - US Harmans, MD
  • hackajob is collaborating with Lockheed Martin - US to connect them with exceptional professionals for this role. WHO WE ARE Lockheed Martin, Rotary Missio... more
  • 1 Month Ago

AI Assistant is available now!

Feel free to start your new journey!