Jobs Companies OneMain Financial Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

Über diese Security Operations Center (SOC) Tier 3 Analyst / Incident Responder Stelle bei OneMain Financial

OneMain Financial · Vor Ort · Baltimore, MD

Key Responsibilities

  • Lead advanced investigations involving ransomware, APTs, zero-day exploits, insider threats, credential theft, lateral movement, cloud compromise, on-premises systems, VDI, SaaS, API abuse, business email compromise, certificate abuse, and data exfiltration.
  • Perform full lifecycle incident response including detection, triage, investigation, containment, eradication, recovery, validation, root cause analysis, and post-incident review.
  • Investigate attacks spanning on-premises infrastructure, Windows and Linux servers, Active Directory, Active Directory Certificate Services (AD CS), Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS platforms, APIs, containers, Kubernetes, databases, enterprise applications, and hybrid cloud environments.
  • Perform forensic analysis of on-premises systems, endpoints, servers, virtual machines, VDI, cloud workloads, identity systems, SaaS applications, APIs, databases, and network devices.
  • Analyze telemetry from EDR/XDR, NDR, SIEM, firewalls, IDS/IPS, WAF, VPN, DNS, DHCP, proxy, email security, cloud audit logs, API gateways, identity providers, application logs, and operating system logs.
  • Develop detections and SIEM correlation rules using Elastic Security, KQL, ES|QL/EQL, SQL, PowerShell, and Python.
  • Conduct proactive threat hunting using MITRE ATT&CK, behavioral analytics, and threat intelligence.
  • Provide technical leadership and mentoring to Tier 1 and Tier 2 analysts.
  • Support management with reporting, including producing technical reports documenting attack timelines, root cause, IOCs, IOAs, TTPs, and recommendations.

Required Qualifications

  • Expert knowledge of SIEM, SOAR, EDR/XDR, NDR, IDS/IPS, WAF, firewalls, email security, web proxies, CASB, DLP, IAM, PAM, API security, and cloud-native security technologies.
  • Expert experience with Elastic Security (ELK), CrowdStrike Falcon, Microsoft Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud, and Defender for Cloud Apps.
  • Deep understanding of on-premises infrastructure including Windows Server, Linux, Active Directory, Active Directory Certificate Services (AD CS), VMware, Hyper-V, storage, virtualization, networking, Microsoft Entra ID, Microsoft 365, Azure, AWS, VDI, SaaS, APIs, containers, Kubernetes, databases, and hybrid cloud architectures.
  • Expert knowledge of TCP/IP, DNS, DHCP, VPN, routing, switching, PKI, Kerberos, NTLM, OAuth, OIDC, SAML, JWT, and certificate-based authentication.
  • Advanced proficiency investigating on-premises systems, cloud environments, endpoints, servers, identity platforms, VDI, SaaS applications, APIs, databases, enterprise applications, and AD CS/PKI-related attacks.
  • Expert proficiency with KQL, ES|QL/EQL, SQL, PowerShell, Python, and Bash.
  • Deep knowledge of MITRE ATT&CK, MITRE D3FEND, Cyber Kill Chain, NIST CSF, NIST 800-61, OWASP Top 10, malware analysis, digital forensics, and attacker methodologies.
  • Minimum two certifications such as GCFA, GCFE, GCIH, GCIA, GREM, CISSP, SC-200, SC-100, AWS Certified Security – Specialty, or equivalent.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent experience.

Preferred Qualifications

  • Experience in financial services or another highly regulated industry.
  • Experience investigating enterprise incidents across Microsoft 365, Azure, AWS, Elastic, CrowdStrike, and hybrid environments.
  • Experience supporting DFIR engagements involving ransomware, nation-state threats, insider threats, enterprise-scale incidents, and Active Directory Certificate Services (AD CS) abuse.

Experience Requirements

  • Minimum 8 years of progressive cybersecurity experience.
  • Minimum 6 years of hands-on Security Operations Center experience.
  • Minimum 4 years leading complex enterprise incident investigations.
  • Minimum 2 years performing advanced digital forensics, threat hunting, and detection engineering.
  • Proven experience independently investigating incidents from initial alert through full remediation across on-premises infrastructure, enterprise networks, endpoints, identity platforms, Microsoft 365, Azure, AWS, VDI, SaaS applications, APIs, Elastic Security, hybrid cloud environments, and PKI/AD CS.

OneMain Holdings, Inc. is an Equal Employment Opportunity (EEO) employer. Qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship status, color, creed, culture, disability, ethnicity, gender, gender identity or expression, genetic information or history, marital status, military status, national origin, nationality, pregnancy, race, religion, sex, sexual orientation, socioeconomic status, transgender or on any other basis protected by law.

Bereit, sich bei OneMain Financial zu bewerben?
Bei OneMain Financial bewerben

Über OneMain Financial

OneMain Financial (NYSE: OMF) is the leader in offering nonprime customers responsible access to credit and is dedicated to improving the financial well-being of hardworking Americans. Since 1912, we've looked beyond credit scores to help people get the money they need today and reach their goals for tomorrow. Our growing suite of personal loans, credit cards and other products help people borrow better and work toward a brighter future. In our more than 1300 community branches and across the U.S., team members help millions of customers solve critical financial needs, including debt consolidation, home and auto repairs, medical procedures and extending household budgets. We meet customers w

Alle Jobs bei OneMain Financial ansehen →

Ähnliche Jobs

OneMain Financial
Accountant Lead - Close and Consolidation
OneMain Financial
⚡ Früh bewerben Irving, TX Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
OneMain Financial
Loan Sales Specialist
OneMain Financial
⚡ Früh bewerben Danville, VA Vor Ort $35,360–$40,560
● Neu 👁 Gesehen ✓ Beworben vor 2 Tg.
OneMain Financial
Bilingual Loan Sales Specialist
OneMain Financial
⚡ Früh bewerben Orlando, FL Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 2 Tg.
OneMain Financial
Loan Sales Specialist
OneMain Financial
⚡ Früh bewerben Sparks, NV Vor Ort $39,520–$46,800
● Neu 👁 Gesehen ✓ Beworben vor 2 Tg.
OneMain Financial
Loan Sales Specialist
OneMain Financial
⚡ Früh bewerben Yakima, WA Vor Ort $35,360–$41,600
● Neu 👁 Gesehen ✓ Beworben vor 2 Tg.
OneMain Financial
VP/Director, Product – Document Management Platform
OneMain Financial
⚡ Früh bewerben New York, NY Hybrid $170,000–$210,000
● Neu 👁 Gesehen ✓ Beworben vor 2 Tg.
OneMain Financial
Senior Platform Engineer (Observability)
OneMain Financial
⚡ Früh bewerben Evansville, IN Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 2 Tg.
OneMain Financial
Loan Sales Specialist
OneMain Financial
⚡ Früh bewerben Puyallup, WA Vor Ort $37,440–$45,760
● Neu 👁 Gesehen ✓ Beworben vor 2 Tg.
OneMain Financial
Bilingual Loan Sales Specialist
OneMain Financial
⚡ Früh bewerben Wichita, KS Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 2 Tg.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei OneMain Financial

Alle Jobs bei OneMain Financial ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos