1

Incident Response Soc Analyst Jobs (NOW HIRING)

SOC Analyst Expression is seeking a SOC Analyst to join our team in support of the National ... In this role, you will provide cyber threat monitoring, analysis, and incident response support ...

New

SOC Analyst

Washington, DC · On-site

$100K - $120K/yr

SOC Analyst Expression is seeking a SOC Analyst to join our team in support of the National ... In this role, you will provide cyber threat monitoring, analysis, and incident response support ...

New

SOC Analyst

Washington, DC · On-site

$100K - $120K/yr

SOC Analyst Expression is seeking a SOC Analyst to join our team in support of the National ... In this role, you will provide cyber threat monitoring, analysis, and incident response support ...

New

The SOC Analyst 2 supports the organization's security operations by conducting deeper ... Incident Response & Coordination Support * Support containment, eradication, and recovery ...

The SOC Analyst will play a critical role in monitoring, analyzing, and responding to security ... This position involves collaboration with Incident Response teams, conducting research, managing ...

SOC Analyst I

Monterey, CA · On-site

$38.72 - $40/hr

May assist with the design of incident response for cloud service models. * As a requirement of ... The SOC Analyst I will provide support Monday - Thursday, 6:45am - 5:15pm PST. AMERICAN SYSTEMS is ...

Incident Response Analyst

Alexandria, VA · On-site

$94K - $127K/yr

Description Incident Response Analyst Xcelerate Solutions is seeking an Incident Response Analyst ... Coordinate with SOC analysts, Cybersecurity Service Providers, system owners, technical teams, and ...

SOC Analyst II (L2) Location: Bellaire, Texas (Hybrid - 1 day onsite per week) About Us STAFFXPERT ... Document incident findings, response actions, and recommendations for improvement. * Support ...

next page

Showing results 1-20

Incident Response Soc Analyst information

See salary details

$22

$46

$62

How much do incident response soc analyst jobs pay per hour?

As of Aug 21, 2026, the average hourly pay for incident response soc analyst in the United States is $46.45, according to ZipRecruiter salary data. Most workers in this role earn between $40.62 and $52.64 per hour, depending on experience, location, and employer.

What is an incident response SOC analyst?

An Incident Response SOC Analyst is a cybersecurity professional responsible for monitoring, detecting, analyzing, and responding to security incidents within an organization. Working in a Security Operations Center (SOC), they investigate alerts, contain threats, and coordinate with other teams to mitigate potential damage. They also help develop and refine security procedures, ensure compliance with policies, and create detailed reports on incidents. Their work is crucial in protecting an organization's digital assets and reducing the impact of cyberattacks.

What are some common challenges incident response SOC analysts face when handling real-time security incidents?

Incident Response SOC Analysts often face the challenge of quickly distinguishing between genuine threats and false positives, as alerts can be numerous and sometimes ambiguous. They must remain calm and methodical under pressure, especially during active incidents where rapid decisions are critical to minimize potential damage. Effective collaboration with IT, network teams, and sometimes external partners is vital for gathering information and executing containment or remediation steps. Additionally, staying updated with evolving cyber threats and maintaining detailed incident documentation are ongoing demands that can shape daily responsibilities.

What are the key skills and qualifications needed to thrive as an incident response SOC analyst, and why are they important?

To thrive as an Incident Response SOC Analyst, you need a solid understanding of cybersecurity principles, threat analysis, and incident response methodologies, often supported by a degree in computer science or cybersecurity and relevant certifications like CompTIA Security+ or GIAC. Familiarity with Security Information and Event Management (SIEM) tools, intrusion detection systems (IDS), and forensic analysis software is typically required. Attention to detail, analytical thinking, and effective communication are essential soft skills for identifying, investigating, and resolving security incidents. These skills and qualifications are crucial to quickly detect threats, minimize damage, and enhance an organization’s overall security posture.

What is the difference between Incident Response Soc Analyst vs Security Operations Center (SOC) Analyst?

AspectIncident Response Soc AnalystSecurity Operations Center (SOC) Analyst
CertificationsCompTIA Security+, GIAC certifications, CISSP (preferred)CompTIA Security+, GIAC certifications, CISSP (preferred)
Work EnvironmentResponds to security incidents, investigates breaches, often in a reactive roleMonitors security alerts, analyzes threats, maintains security tools
Employer & Industry UsageUsed in cybersecurity teams across various industries, focusing on incident handlingCommon in security operations centers across industries, focusing on threat detection

Both roles require similar certifications and work in cybersecurity environments, but Incident Response Soc Analysts focus on investigating and responding to security incidents, while SOC Analysts primarily monitor and analyze security alerts to prevent incidents.

Do incident response SOC analysts get paid well?

Incident response SOC analysts typically earn competitive salaries that vary by experience, location, and industry. Entry-level analysts may start with lower pay, but with certifications like CISSP or GIAC and experience, salaries can increase significantly, often reflecting the specialized skills required for cybersecurity incident handling.

Is incident response SOC analyst still in demand?

Incident Response SOC analysts are in high demand due to increasing cybersecurity threats and the need for organizations to detect and respond to security incidents quickly. The role often requires knowledge of security tools, threat intelligence, and certifications like CISSP or GIAC, and job growth is expected to remain strong in the coming years.
More about Incident Response Soc Analyst jobs

What cities are hiring for Incident Response Soc Analyst jobs?

Cities with the most Incident Response Soc Analyst job openings:

What job categories do people searching Incident Response Soc Analyst jobs look for?

The top searched job categories for Incident Response Soc Analyst jobs are:

Infographic showing various Incident Response Soc Analyst job openings in the United States as of August 2026, with employment types broken down into 2% As Needed, 81% Full Time, 13% Part Time, 3% Contract, and 1% Nights. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $96,618 per year, or $46.5 per hour.

$100K - $120K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 3 days ago

New


Job description

SOC Analyst

Expression is seeking a SOC Analyst to join our team in support of the National Telecommunications and Information Administration (NTIA) ISCOM Division. In this role, you will provide cyber threat monitoring, analysis, and incident response support that strengthens program situational awareness and ensures resilience of critical federal networks. You will support Tier 1 and Tier 2 SOC operations, contribute to SOC playbook development, and help mature cyber defense strategies in a mission-focused environment.

Location and Clearance

  • Washington, DC - Onsite
  • Active Secret or Top Secret clearance required (U.S. Citizenship required)

Responsibilities

  • Monitor, detect, and analyze security threats, risks, and alerts using SOC tools, and initiate escalation as required.
  • Conduct cyber threat analysis and contribute to reports for program situational awareness.
  • Provide Tier 1 response to security incidents and support escalation to Tier 2 during high-volume or critical events.
  • Conduct functional incident response teams during shifts, ensuring accountability and effective resolution.
  • Conduct malware analysis (static and dynamic) and assess Indicators of Compromise (IOCs).
  • Perform network forensics and deep packet inspection to investigate intrusions.
  • Implement remediation strategies and support recovery activities after incidents.
  • Recommend process improvements and create new detection content to strengthen SOC operations.
  • Conduct proactive monthly threat hunts and provide reports to stakeholders.
  • Collaborate with cyber teams for incident escalation, coordinated responses, and SOC policy/procedure development.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or related field; OR equivalent certifications (CompTIA Security+, CISSP, GCIH, GCIA).
  • Minimum of 4 years of experience in security operations, incident response, or cyber threat analysis.
  • Strong knowledge of SOC operations, incident detection, and response workflows.
  • Familiarity with malware analysis, network forensics, and packet-level inspection.
  • Excellent analytical, problem-solving, and communication skills.

Preferred Experience

  • Advanced certifications such as CISSP, GCFA, GCIH, GCIA, or equivalent.
  • Prior experience supporting NTIA, Department of Commerce, or other federal civilian agencies.
  • Hands-on experience with SIEM platforms, IDS/IPS, and endpoint monitoring tools.
  • Familiarity with the NIST Cybersecurity Framework and Risk Management Framework (RMF).
  • Experience developing and maturing SOC playbooks, processes, and detection capabilities.

Benefits

Expression offers highly competitive salaries, performance-based incentives, and additional benefits, such as:

  • 401k matching
  • PPO and HDHP medical/dental/vision insurance
  • Education reimbursement up to $10,000/yr
  • Complimentary life insurance
  • Generous PTO and 11 days of holiday leave
  • Onsite gym facility at our HQ office in Washington DC
  • Commuter Benefits Plan

About Expression

Founded in 1997 and headquartered in Washington, DC, Expression provides data fusion, data analytics, AI/ML, software engineering, information technology, and electromagnetic spectrum management solutions to the U.S. Department of Defense, Department of State, and national security community.

Our culture emphasizes creating immediate and sustainable value for our clients through agile delivery of tailored solutions and constant engagement. We were ranked #1 on the Washington Technology Fast 50 list of fastest-growing small business Government contractors and recognized as a Top 20 Big Data Solutions Provider by CIO Review.

At Expression, we ensure every team member has the tools and opportunities to grow while working with the newest technologies in the industry. We celebrate milestones, accomplishments, promotions, and collaborative achievements that make our workplace engaging and rewarding.

Equal Opportunity Employer/Veterans/Disabled
Expression is an Equal Opportunity Employer. If you require a reasonable accommodation during the application or interview process, please submit your request to our Human Resources department through the application portal.

Employment Type: FULL_TIME