Principal Associate, CSOC Analyst

4 weeks ago


Richmond, United States Capital One Full time
Center 3 (19075), United States of America, McLean, Virginia

Principal Associate, CSOC Analyst (Incident Response)

Capital One is looking for talented Cyber Security Analysts with traditional network security and cloud infrastructure monitoring experience to join our Cyber Security Operations Center (CSOC) in McLean, VA. The Principal Associate level CSOC Analyst position will require a deep knowledge of network protocols and infrastructure, log investigation techniques, knowledge/understanding of cloud infrastructures, and incident handling experience. Not only will you need to know about the threats to networks, applications, cloud infrastructure, and theory regarding network protocols, but also the ability to proactively identify signs of misuse and abuse using various log sources.

It is your responsibility to find the threat actors attempting to attack the Capital One infrastructure, and identify and stop any malicious actors who make it past our defenses. In addition to the technical skills, you will need to be a leader, someone who enjoys training and mentoring teammates, and a person who can encourage and elevate the team.

What You'll Do:
  • Support day-to-day cybersecurity threat detection and incident response operations through indicator pivoting, campaign analysis, and tactical intelligence
  • Identify and enhance processes where automation has the potential to improve efficiencies, provide actionable data, and facilitate collaboration across CSOC
  • Leverage Security Orchestration, Automation, and Response (SOAR) or Security Information and Event Management (SIEM) tools to identify threat patterns, enrich investigations, and build automation-supported workflows
  • Deconstruct multi-source reporting into actionable intelligence including Tactics, Techniques, and Procedures TTPs data objects, campaign analysis, and threat patterns.
  • Regularly analyze malware reports to track adversary behaviors and support the construction of a TTP repository
  • Develop expertise on the Capital One threat landscape using internal data, threat trends, and operational metrics to clearly communicate the Capital One threat landscape to senior executives, to include the Chief Information Security Officer and Chief Information Officer.
  • Proactively build and maintain relationships with partner teams, including but not limited to Cyber Intelligence, Red Team, Insider Threat, and Hunt teams.
  • Conduct time-sensitive analysis during cyber investigations, including active threat hunting, malware analysis, and campaign enrichment
  • Routinely identify gaps in detection and collaborate with teams across the Cyber organization to mitigate risk, including blocking of malicious indicators, tuning vendor signatures, and instrumenting custom detection rules
  • Support the tactical intelligence-to-detection pipeline, to include malware reverse engineering, TTP analysis, and association mapping in a TIP (threat intelligence platform) for future pivoting
  • Attend conferences and briefings to stay current on threats against both COF and the Financial Services sector
  • Mentor other CSOC analysts in project execution and tactical upskilling; conduct brown bag lunches to teach specialized skill sets


Basic Qualifications
  • High School Diploma, GED or Equivalent Certification
  • At least 4 years of experience conducting Cyber Security investigation and documentation
  • At least 4 years of experience working with a SIEM
  • At least 4 years of experience with system, cloud, application and network logs
  • At least 4 years of experience analyzing and identifying network traffic
  • At least 4 years of experience with PCAP analysis
  • At least 4 years of experience analyzing endpoints (server and workstation)


Preferred Qualifications
  • Bachelor's Degree in Information Technology, Cyber Security or Computer Science
  • 5+ years of experience conducting Cyber Security investigations into network and application activity
  • 5+ years of experience working in a Security Operations Center (SOC)
  • 5+ years of experience working with SIEMs and evaluating SIEM alerts
  • 5+ years of experience administering or investigating Mac OS, Linux OS
  • 5+ years of experience leveraging core security, cloud, and infrastructure technologies during investigations
  • One or more of the following certifications (CISSP, CISM, CCSP, SANS GIAC 503 or 504, AWS Security)


At this time, Capital One will not sponsor a new applicant for employment authorization for this position.

Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the . Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.

This role is expected to accept applications for a minimum of 5 business days.

No agencies please. Capital One is an equal opportunity employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to sex (including pregnancy, childbirth or related medical conditions), race, color, age, national origin, religion, disability, genetic information, marital status, sexual orientation, gender identity, gender reassignment, citizenship, immigration status, protected veteran status, or any other basis prohibited under applicable federal, state or local law. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.

If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1- or via email at . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.

For technical support or questions about Capital One's recruiting process, please send an email to

Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.

Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).

  • Richmond, United States Capital One Full time

    Center 3 (19075), United States of America, McLean, VirginiaPrincipal Associate, Cyber Security Operations Center (CSOC) Countermeasures AnalystCapital One is looking for talented Cyber Security Analysts with experience performing endpoint, network, and cloud security monitoring to join our Cyber Security Operations Center (CSOC). The Principal Associate...


  • Richmond, United States Capital One Full time

    Center 3 (19075), United States of America, McLean, VirginiaPrincipal Associate, Cyber Security Operations Center (CSOC) - (Fusion) AnalystThe Cyber Security Operation Center Fusion team synthesizes multi-source security alerting, intrusion investigations, cyber intelligence, and business information into actionable analysis. The Fusion team provides this...


  • Richmond, Virginia, United States City of Richmond VA Full time

    Position OverviewThe City of Richmond Department of Justice Services is in search of a dedicated and skilled professional to assume the role of Management Analyst, Principal. This position is crucial for the effective administration and operational oversight within the department.Key ResponsibilitiesConduct comprehensive analyses to support decision-making...


  • Richmond, United States Capital One Full time

    West Creek 4 (12074), United States of America, Richmond, VirginiaPrincipal Analyst, Financial Planning and Analysis We are seeking a strategically minded analyst and forward leaning problem solver to support the Tech & Digital organization. As a Principal Analyst, Financial Planning & Analysis (FP&A), you will be responsible for ad hoc financial analysis,...


  • Richmond, United States Richmond Symphony Full time

    The position is for Associate Principal 2nd Violin. Essential duties include performing in our 69 member orchestra and may include performing in public schools, community engagement, and donor events. Other responsibilities are outlined in our Collective Bargaining Agreement (CBA). This position is expected to begin as soon as possible following an offer of...


  • Richmond, Virginia, United States Richmond Symphony Full time

    The position is for Associate Principal 2nd Violin. Essential duties include performing in our 69 member orchestra and may include performing in public schools, community engagement, and donor events. Other responsibilities are outlined in our Collective Bargaining Agreement (CBA). This position is expected to begin as soon as possible following an offer of...


  • Richmond, United States Thermo Fisher Scientific Full time

    A day in the Life:Scheduling Coordination and Oversight. Oversee task assignments. Lead internal external Scheduling Meetings. Track and coordinate use of shared/limited resources. Ordering/ Inventory Management. Oversee consumable inventory nee Research Scientist, Operations, Associate, Investigator, Principal, Equipment Maintenance, Manufacturing,...

  • Principal Analyst

    1 week ago


    Richmond, Virginia, United States LTM Full time

    About LTM INC. LTM INC. started its journey in 1994 as a modest enterprise with a single contract and a team of four in Havelock, NC, providing support to the DoD and the Marines. Today, LTM has expanded its reach across the United States, with a diverse workforce in multiple states. We take pride in having you as part of our growing family. Employment Type...


  • Richmond, United States City of Richmond VA Full time

    The City of Richmond, Department of Public Utilities is seeking highly qualified candidates for the position of Management Analyst, Associate in the Gas & Light Division. The incumbents will be responsible for certifying contractor invoices for the p Gas, Analyst, Associate, Management, Mechanical, Project Management, Business Services


  • Richmond, United States Capital One Full time

    Center 1 (19052), United States of America, McLean, VirginiaOntology & Data Modeling- Principal Associate, BC&PThe role of the Principal Associate of Ontology and Data Modeling is to develop, implement, and maintain enterprise ontologies in support of Capital One's Data Strategy. The Principal Associate of Ontology and Data Modeling, as part of BC&P...


  • Richmond, United States Capital One Full time

    Plano 1 (31061), United States of America, Plano, TexasPrincipal Associate, Cyber TechnicalWe are seeking a Principal Associate, Cyber Technical who enjoys solving complex business problems in a fast-paced, collaborative, inclusive, and iterative delivery environment. At Capital One, you'll be part of a big group of builders, breakers, doers and disruptors,...


  • Richmond, United States Capital One Full time

    Center 3 (19075), United States of America, McLean, VirginiaPrincipal Associate, Cyber Controls MonitoringAs a Principal Associate (PA) in Capital One's Cyber Governance & Risk organization, you will have the chance to oversee control development, enhancement, execution, testing and reporting, and ensuring controls meet quality standards. You will work on a...


  • Richmond, Virginia, United States Dominion Energy Full time

    Job SummaryThe Corporate Intelligence & Security group is looking to hire an Associate Physical Security Analyst or Physical Security Analyst to join their team in Richmond, Virginia. There is one position available and it will be filled at the level commensurate with the successful candidate's knowledge, skills, and experience. Responsibilities include:...


  • Richmond, United States Dominion Energy Full time

    Job Summary The Corporate Intelligence & Security group is looking to hire an Associate Physical Security Analyst or Physical Security Analyst to join their team in Richmond, Virginia. There is one position available and it will be filled at the level commensurate with the successful candidate's knowledge, skills, and experience.  Responsibilities...


  • Richmond, United States Capital One Full time

    West Creek 1 (12071), United States of America, Richmond, VirginiaPrincipal Risk Associate, Customer Resiliency Risk Events and Remediation As a Principal Risk Specialist within the Customer Resiliency Risk Events and Remediation team, you will engage with a team of risk managers, product and process owners in delivering flawlessly executed processes that...


  • Richmond, United States Metis Search Full time

    Metis Search are currently partnered with a strong, growing Middle Market Investment Bank who are adding Analysts, Associates and VPs to their M&A groups across Boston and Virginia. We are keen to connect with Investment Banking Analysts, Associates and VPs with a proven track record in sell side M&A advisory. Applicants should have the following...


  • Richmond, Virginia, United States Dominion Energy Full time

    Job SummaryResponsible for analyzing and making recommendations for changes to internal processes and/or standards/specifications in order to create more efficient and economical operations for Dominion Energy and Dominion Delivery business areas. Assist on multiple concurrent projects to identify and document the major business processes associated with the...


  • Richmond, United States Dominion Energy Full time

    Job Summary Responsible for analyzing and making recommendations for changes to internal processes and/or standards/specifications in order to create more efficient and economical operations for Dominion Energy and Dominion Delivery business areas. Assist on multiple concurrent projects to identify and document the major business processes associated with...

  • Financial Analyst

    1 week ago


    Richmond, Virginia, United States Commonwealth of Virginia Full time

    Join the Commonwealth of Virginia's Grants & Contracts Department as a Financial Analyst As a full-time employee, you will have access to a comprehensive benefits package that includes: extensive health coverage, upfront paid annual and holiday leave, retirement planning options, tax-deferred annuity and cash match programs, generous tuition assistance,...


  • Richmond, United States Metis Search Full time

    Metis Search are currently partnered with a strong, growing Middle Market Investment Bank who are adding Analysts, Associates and VPs to their M&A groups across Boston and Virginia.We are keen to connect with Investment Banking Analysts, Associates and VPs with a proven track record in sell side M&A advisory.Applicants should have the following...