SOC Tier 1 Analyst

ECS Federal LLC

DC

JOB DETAILS
SKILLS
Analysis Skills, Best Practices, Case Management, Cloud Computing, Communication Skills, Computer Security, Customer/Consumer Behavior, Data Quality, Documentation, Identity Data Management, Incident Response, Information Technology & Information Systems, Internet Security, Intrusion Detection Systems, Intrusion Prevention Systems, Leadership, Malware, Operations Security (OPSEC), Performance Analysis, Phishing, Procedure Development, Process Improvement, Reporting Dashboards, Risk, Security Attacks, Security Information and Event Management (SIEM), Security Infrastructure, Security Monitoring, Splunk, Standard Operating Procedures (SOP), Telemetry, Validation Documentation
LOCATION
DC
POSTED
30+ days ago

Everforth ECS is seeking a SOC Tier 1 Analyst to work in our Portland, OR office. Please Note: This position is contingent upon contract award.

The SOC Analyst 1 supports the organization's security operations by monitoring security events, performing first-level alert triage, validating suspicious activity, documenting tickets, and escalating confirmed or higher-risk events using approved runbooks and procedures. This role is the initial monitoring and triage tier within the SOC Analyst role family.

The ideal candidate has foundational cybersecurity or IT operations experience, understands basic security concepts and defensive technologies, and can follow established procedures while communicating clearly with SOC Analyst 2, SOC Analyst 3, incident response, engineering, and other program stakeholders.

Key Responsibilities

Security Monitoring & Initial Alert Triage

  • Monitor security events and alerts across SIEM, EDR, IDS/IPS, cloud, network, identity, case management, and other approved security platforms.
  • Perform first-level alert validation to determine whether activity is benign, suspicious, policy-related, or requires escalation.
  • Assign initial severity, scope, affected assets, affected accounts, and potential impact using approved triage criteria and runbooks.
  • Escalate confirmed, ambiguous, high-risk, or complex alerts to SOC Analyst 2, SOC Analyst 3, or SOC leadership according to established procedures.

Ticketing, Documentation & Shift Handoff

  • Create and update incident tickets with clear descriptions, timestamps, evidence references, preliminary findings, and actions taken.
  • Document investigation steps, alert context, decisions, and escalation rationale clearly and accurately.
  • Prepare shift handoff notes and status updates to ensure continuity of monitoring and incident follow-up.
  • Maintain case management hygiene, including accurate categorization, status tracking, and closure documentation for routine alerts.

Incident Response Support

  • Support standard incident response activities under direction of SOC Analyst 2, SOC Analyst 3, incident responders, or SOC leadership.
  • Collect readily available logs, alert details, endpoint information, user information, and other operational evidence needed for escalation.
  • Coordinate basic information requests with system owners, security engineers, and other technical teams as directed.
  • Track escalations and provide status updates until ownership is accepted by the appropriate SOC or specialized role.

Tool Use & Procedure Adherence

  • Use SOC tools such as SIEM, SOAR, EDR, threat intelligence portals, case management systems, and vulnerability platforms in accordance with approved procedures.
  • Follow playbooks, standard operating procedures, evidence-handling expectations, and escalation thresholds consistently.
  • Report suspected data quality issues, missing telemetry, dashboard problems, or tool availability concerns to SOC Analyst 2/3, Splunk engineering, or security engineering teams.
  • Participate in training, drills, tabletop exercises, and lessons-learned activities to improve monitoring and triage performance.

Continuous Learning

  • Stay current with common cyber threats, phishing techniques, malware trends, vulnerabilities, user behavior risks, and security operations best practices.
  • Apply feedback from senior analysts to improve alert validation, documentation quality, and escalation accuracy.
  • Contribute operational observations and recurring alert patterns to process improvement discussions.

About the Company

E

ECS Federal LLC

ECS was founded in 2001 by experienced IT professionals with a commitment to quality processes, people and performance. Led by our Chairman, Roy Kapani, and an experienced executive leadership team, ECS provides our customers with solutions and services that support their critical needs and further mission objectives. This commitment has paved the way for expansive growth, year over year.

ECS gained market share in 2011 in the Department of Defense and Federal spaces through both organic and acquisition growth. In May, ECS completed its first strategic acquisition with the purchase of OAK Management, Inc., a leading provider of marine environmental services, ship systems engineering, maritime consulting and platform acquisition management. The OAK acquisition kicked off ECS’ intention to add tactical acquisitions as a part of its long term strategy to supplement and expand upon organic growth and to build enterprise value. ECS closed out 2011 with the acquisition of Paradigm Technologies, Inc. The Paradigm transaction added approximately 200 employees to ECS’ existing 900+ employees. Paradigm also added new Defense clients for ECS, including the Missile Defense Agency, the Navy’s Program Executive Officer for Integrated Warfare Systems, the United States Marine Corps, and the U.S. Marshals Service.

In 2012, ECS completed the acquisition of iLuMinA Solutions, Inc. iLuMinA brings large-scale Enterprise Resource Planning (ERP) software implementation and infrastructure design and development to ECS’ expanding capabilities.

ECS will continue to invest in corporate infrastructure and quality processes as we grow and enhance our ability to offer professional excellence to both our customers and our employees.

COMPANY SIZE
50 to 99 employees
INDUSTRY
Staffing/Employment Agencies
FOUNDED
2000
WEBSITE
http://www.ecs-federal.com/