Skip to main content

Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

Location: Baltimore, Maryland

Apply

What makes a Security Operations Center (SOC) Tier 3 Analyst / Incident Responder successful at OneMain? Check out the top traits we’re looking for and see if you qualify.

  • Adaptable
  • Analytical
  • Curious
  • Entrepreneurial
  • Inventive
  • Problem Solver

Culture

  • We foster an entrepreneurial spirit that's powered by a national brand – our teams are empowered to make a difference
  • We encourage teams to take ownership of initiatives in this fast-paced, innovative culture so they can drive solutions that stay ahead of customer needs
  • We prioritize teamwork and building in-person connections with each other, understanding that fostering a collaborative environment is the best way to support each other.
  • We promote avenues to allow team members to expand their professional capabilities and continuously develop skills, facilitating upward mobility and career progression
Headshot of Andy W.

I like working at OneMain because of the opportunity it provides. You get to work with a lot of talented people, a lot of motivation to better the lives of our customers and a lot of fun technology that you get to interact with on a daily basis. I feel like I have many different options that I can take on yearly.

Andy W., Software Developer

Benefits

  • Blue circular icon with 4 people illustrations

    We promote social and family well-being by offering paid time off for volunteer hours and providing family back-up care.

  • Blue circular icon with open hands holding heart

    We offer extensive, comprehensive coverage to support team members’ needs physically and mentally, such as access to Talkspace and Hinge for on-demand physical therapy via an app.

  • Blue circular icon with piggy bank

    We offer financial wellness that includes 401(k) with match, ESPP, tuition reimbursement and tools like subscription cancelation that help you stay on top of your financial goals.

Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

Location: Baltimore, MD
Apply
Job Number R2607-51809 Date posted 07/27/2026

Key Responsibilities

  • Lead advanced investigations involving ransomware, APTs, zero-day exploits, insider threats, credential theft, lateral movement, cloud compromise, on-premises systems, VDI, SaaS, API abuse, business email compromise, certificate abuse, and data exfiltration.
  • Perform full lifecycle incident response including detection, triage, investigation, containment, eradication, recovery, validation, root cause analysis, and post-incident review.
  • Investigate attacks spanning on-premises infrastructure, Windows and Linux servers, Active Directory, Active Directory Certificate Services (AD CS), Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS platforms, APIs, containers, Kubernetes, databases, enterprise applications, and hybrid cloud environments.
  • Perform forensic analysis of on-premises systems, endpoints, servers, virtual machines, VDI, cloud workloads, identity systems, SaaS applications, APIs, databases, and network devices.
  • Analyze telemetry from EDR/XDR, NDR, SIEM, firewalls, IDS/IPS, WAF, VPN, DNS, DHCP, proxy, email security, cloud audit logs, API gateways, identity providers, application logs, and operating system logs.
  • Develop detections and SIEM correlation rules using Elastic Security, KQL, ES|QL/EQL, SQL, PowerShell, and Python.
  • Conduct proactive threat hunting using MITRE ATT&CK, behavioral analytics, and threat intelligence.
  • Provide technical leadership and mentoring to Tier 1 and Tier 2 analysts.
  • Support management with reporting, including producing technical reports documenting attack timelines, root cause, IOCs, IOAs, TTPs, and recommendations.

Required Qualifications

  • Expert knowledge of SIEM, SOAR, EDR/XDR, NDR, IDS/IPS, WAF, firewalls, email security, web proxies, CASB, DLP, IAM, PAM, API security, and cloud-native security technologies.
  • Expert experience with Elastic Security (ELK), CrowdStrike Falcon, Microsoft Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud, and Defender for Cloud Apps.
  • Deep understanding of on-premises infrastructure including Windows Server, Linux, Active Directory, Active Directory Certificate Services (AD CS), VMware, Hyper-V, storage, virtualization, networking, Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS, APIs, containers, Kubernetes, databases, and hybrid cloud architectures.
  • Expert knowledge of TCP/IP, DNS, DHCP, VPN, routing, switching, PKI, Kerberos, NTLM, OAuth, OIDC, SAML, JWT, and certificate-based authentication.
  • Advanced proficiency investigating on-premises systems, cloud environments, endpoints, servers, identity platforms, VDI, SaaS applications, APIs, databases, enterprise applications, and AD CS/PKI-related attacks.
  • Expert proficiency with KQL, ES|QL/EQL, SQL, PowerShell, Python, and Bash.
  • Deep knowledge of MITRE ATT&CK, MITRE D3FEND, Cyber Kill Chain, NIST CSF, NIST 800-61, OWASP Top 10, malware analysis, digital forensics, and attacker methodologies.
  • Minimum two certifications such as GCFA, GCFE, GCIH, GCIA, GREM, CISSP, SC-200, SC-100, AWS Certified Security – Specialty, or equivalent.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent experience.

Preferred Qualifications

  • Experience in financial services or another highly regulated industry.
  • Experience investigating enterprise incidents across Microsoft 365, Azure, AWS, Elastic, CrowdStrike, and hybrid environments.
  • Experience supporting DFIR engagements involving ransomware, nation-state threats, insider threats, enterprise-scale incidents, and Active Directory Certificate Services (AD CS) abuse.

Experience Requirements

  • Minimum 8 years of progressive cybersecurity experience.
  • Minimum 6 years of hands-on Security Operations Center experience.
  • Minimum 4 years leading complex enterprise incident investigations.
  • Minimum 2 years performing advanced digital forensics, threat hunting, and detection engineering.
  • Proven experience independently investigating incidents from initial alert through full remediation across on-premises infrastructure, enterprise networks, endpoints, identity platforms, Microsoft 365, Azure, AWS, VDI, SaaS applications, APIs, Elastic Security, hybrid cloud environments, and PKI/AD CS.

Apply

You have not saved any jobs.

You have not recently viewed any jobs.

Join our Talent Community

Sign up here for job alert emails and SMS messages from OneMain Financial Recruiting.

Already signed up?

Interested InPlease select a category or location option. Click “Add” to create your job alert.