---
title: CSOC Tier 3 Analyst III at Risadirect
description: Risadirect is hiring for the CSOC Tier 3 Analyst III role in Springfield, VA.
  Pays $87K–$95K per year. See the full description and apply.
type: job
url: https://www.foundrole.com/jobs/csoc-tier-3-analyst-iii-at-risadirect-01a0ea0f-9f58-705e-8d34-419ca5403cde
date: 2026-09-28T22:15:20Z
og_description: Join Risadirect as CSOC Tier 3 Analyst III in Springfield, VA. Pays $87K–$95K
  per year. Full-time, on-site role.
og_image: https://www.foundrole.com/og/hei3f5.png
breadcrumbs:
  - label: Home
    url: https://www.foundrole.com/
  - label: Search
    url: https://www.foundrole.com/jobs
---

| | |
|---|---|
| **Company** | risadirect.com |
| **Location** | Springfield, VA |
| **Salary** | $87K/yr - $95K/yr |
| **Type** | Full Time |
| **Posted** | Sep 28, 2026 |
## Description

**Incident Responder / Malware Analyst (CSOC Tier 3)**

**Cyber Security Operations Specialist III - CSOC Tier 3**

**Location:** Springfield, VA - on site

**Time Type:** Full time, Exempt

**Clearance Required to Start:** Active TS/SCI (U.S. citizenship required)

**Additional Requirement:** Must be able to obtain and maintain a Government polygraph (post-hire requirement)

**Schedule:** Supports a 24x7x365 incident response operation

**Travel:** None

**Salary Range:** $87,000 – $95,000

**When an incident happens, you are the one who contains it.**

RISA is hiring a CSOC Tier 3 analyst for the incident response team defending an Intelligence Community customer's enterprise. This is the top of the escalation chain: containment, eradication, and recovery, plus malware and implant analysis and forensic artifact work. When a Cyber Incident Response Team stands up, you work under the Government CIRT Commander; between incidents, you run the exercises that make the next response better. You will talk to the owner here, not a recruiting queue.

**What You Will Do**

- Implement containment measures during incidents - IP and domain blocks, account disablement - at Government direction.
- Perform digital media analysis on host, server, and network data, including volatile and non-volatile memory.
- Perform malware analysis and reverse engineering, and develop signatures and indicators of compromise.
- Categorize incidents, build timelines, and brief stakeholders on adversary activity and response actions.
- Coordinate with counterintelligence, insider threat, and law enforcement partners on advanced investigation and triage.
- Develop and, when authorized, run custom scripts and tools to collect and analyze data.
- Write incident investigation reports covering the full lifecycle of each incident, with corrective and TTP recommendations.
- Contribute to daily and weekly CSOC reporting, and quality-check a share of closed Tier 2 tickets each week.

**What You'll Bring**

- S. citizenship and an active TS/SCI.
- Ability to successfully obtain and maintain a Government polygraph after hire.
- Education and experience, per the contract labor category criteria: Bachelor's degree in a field applicable to the position plus 6 years of relevant experience. Equivalents accepted - Master's plus 4, Associate's plus 8, or High School diploma/GED plus 10.
- DoD 8140.01 / 8570.01-M IAT Level II and CSSP Incident Responder; IAT Level III and CSSP Incident Responder must be held or obtained within six months of start.
- Hands-on incident response: containment, eradication, and recovery.
- Host, network, and memory forensics, and malware analysis.
- Documentation disciplined enough that every action and analysis can be reconstructed from the ticket.

**Nice to Have**

- Master's degree.
- IAT Level III already in hand.

**About RISA**

Rolston Information Systems Assurance (RISA) is a Service-Disabled Veteran-Owned Small Business that has supported federal defense and intelligence cybersecurity missions for more than seventeen years. We are small on purpose: direct access to leadership, a real say in how the work gets done, and none of the layers that slow large primes down.

**Benefits**

Medical, dental, and vision insurance; 401(k) and Roth; Paid Time Off; and 11 paid Federal Holidays.

*RISA is an Equal Opportunity Employer.*

- Upon receiving an offer of employment, all applicants will be required to do a background check, including a criminal record check and employment/education verification.
## Skills

- Counterintelligence
- Incident Investigation
- Triage
- Investigation
- Insightful S-plus
- DoD IAT Level II Certification
- Malware Analysis
- DoD 8140 (Cyberspace Workforce)
- Reverse Engineering
- Incident Response
- Insider Threat Detection
- Quality Assurance Procedures
- Digital Media
- Polygraphy
- Tibco S-plus
- Equities
- Top Secret-Sensitive Compartmented Information (Ts/sci Clearance)
## Benefits

- Health Insurance
- Dental Insurance
- Vision Insurance
- Paid Time Off (Pto)
- 401(k) Plans

## How to Apply

[Apply for this position](https://www.foundrole.com/jobs/csoc-tier-3-analyst-iii-at-risadirect-01a0ea0f-9f58-705e-8d34-419ca5403cde?utm_source=ai_markdown)

## Related

- [Browse all companies](https://www.foundrole.com/companies?utm_source=ai_markdown)