SOC Analyst II
Posted 3hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
SOC Analyst II protecting small and medium-sized businesses with enterprise-class cybersecurity. Leading threat investigations, incident response, threat hunting, and vulnerability management.
Responsibilities:
- Serve as the primary escalation point for Tier I analysts
- Take ownership of critical/high-severity alerts and escalated security incidents
- Analyze endpoints, network traffic, and log data to validate incidents and perform root cause analysis
- Lead containment, eradication, and recovery during active security incidents
- Follow and document Standard Operating Procedures and Incident Response Plans
- Reconstruct attack chains using the MITRE ATT&CK Framework and Cyber Kill Chain
- Conduct intelligence- and hypothesis-driven threat hunts
- Write executive reports with clear narratives, detailed analysis, and actionable recommendations
- Manage the vulnerability management lifecycle, including scan analysis, risk-based prioritization, and remediation coordination
- Develop and maintain incident response playbooks and SOPs
- Provide technical guidance, training, and feedback to Tier 1 analysts
- Participate in an on-call rotation for critical incidents outside standard business hours
- Collaborate with and mentor junior staff
- Help advance capabilities in digital forensics and incident response, threat hunting, vulnerability management, and threat intelligence
Requirements:
- U.S. citizenship
- Must be eligible for a Secret clearance
- Minimum of 2–5 years of experience in a Security Operations Center and/or cyber-adjacent or IT administration roles
- Intermediate to advanced understanding of Windows OS internals, including Event Tracing for Windows, Win32 API, Registry, Memory, and Process operations
- Intermediate to advanced understanding of TCP/IP, DNS, HTTP, SSL/TLS, and other common network protocols
- Intermediate to advanced ability to write and interpret Python or PowerShell scripts
- Ability to manage Windows devices via command line using PowerShell or Batch
- Ability to detect and reverse engineer malicious scripts or other high-level languages
- Understanding of code injection and attack/evasion techniques related to Windows
- Prior experience with SIEM platforms such as Microsoft Sentinel, ELK/Elastic Stack, or Splunk
- Hands-on experience with Sysinternals Suite, Volatility, SIFT Workstation, CyberChef, Forensic Browser for SQLite, Velociraptor, Explorer Suite, Wireshark, and malware analysis sandboxes, or equivalent tools
- Familiarity with malware development, social engineering, phishing, exploitation, persistence, evasion, credential theft, C2, exfiltration, and lateral movement
- Intermediate to advanced certification such as GCIH/GCIA/GCFA, OSCP, BTL2, or equivalent is highly desired
- Previous team lead or supervisory leadership experience is desired
- Experience with Azure, Microsoft Sentinel/Defender XDR, Entra ID, and Kusto Query Language (KQL) is desired
- Active participation in Capture-the-Flag events and homelabbing is a plus
- Understanding of x64 assembly, Windows data structures, and undocumented parts of Windows OS is desired
- Familiarity with low-level reverse engineering and debugging tools such as Ghidra, x64dbg, and IDA is desired
- Must participate in an on-call rotation
Benefits:
- Fully paid individual healthcare, vision and dental insurance for the employee
- Paid certification and training opportunities
- Three weeks of paid vacation
- 11 paid holidays
- Supportive environment with a focus on keeping healthy work-life balance
- Retirement benefit (401k) with company match
- Potential transition into a team leadership role
- Exposure to new and emerging technologies
- Fun, dynamic environment working on interesting problems















