SOC Analyst II

Posted 3hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

SOC Analyst II protecting small and medium-sized businesses with enterprise-class cybersecurity. Leading threat investigations, incident response, threat hunting, and vulnerability management.

Responsibilities:

  • Serve as the primary escalation point for Tier I analysts
  • Take ownership of critical/high-severity alerts and escalated security incidents
  • Analyze endpoints, network traffic, and log data to validate incidents and perform root cause analysis
  • Lead containment, eradication, and recovery during active security incidents
  • Follow and document Standard Operating Procedures and Incident Response Plans
  • Reconstruct attack chains using the MITRE ATT&CK Framework and Cyber Kill Chain
  • Conduct intelligence- and hypothesis-driven threat hunts
  • Write executive reports with clear narratives, detailed analysis, and actionable recommendations
  • Manage the vulnerability management lifecycle, including scan analysis, risk-based prioritization, and remediation coordination
  • Develop and maintain incident response playbooks and SOPs
  • Provide technical guidance, training, and feedback to Tier 1 analysts
  • Participate in an on-call rotation for critical incidents outside standard business hours
  • Collaborate with and mentor junior staff
  • Help advance capabilities in digital forensics and incident response, threat hunting, vulnerability management, and threat intelligence

Requirements:

  • U.S. citizenship
  • Must be eligible for a Secret clearance
  • Minimum of 2–5 years of experience in a Security Operations Center and/or cyber-adjacent or IT administration roles
  • Intermediate to advanced understanding of Windows OS internals, including Event Tracing for Windows, Win32 API, Registry, Memory, and Process operations
  • Intermediate to advanced understanding of TCP/IP, DNS, HTTP, SSL/TLS, and other common network protocols
  • Intermediate to advanced ability to write and interpret Python or PowerShell scripts
  • Ability to manage Windows devices via command line using PowerShell or Batch
  • Ability to detect and reverse engineer malicious scripts or other high-level languages
  • Understanding of code injection and attack/evasion techniques related to Windows
  • Prior experience with SIEM platforms such as Microsoft Sentinel, ELK/Elastic Stack, or Splunk
  • Hands-on experience with Sysinternals Suite, Volatility, SIFT Workstation, CyberChef, Forensic Browser for SQLite, Velociraptor, Explorer Suite, Wireshark, and malware analysis sandboxes, or equivalent tools
  • Familiarity with malware development, social engineering, phishing, exploitation, persistence, evasion, credential theft, C2, exfiltration, and lateral movement
  • Intermediate to advanced certification such as GCIH/GCIA/GCFA, OSCP, BTL2, or equivalent is highly desired
  • Previous team lead or supervisory leadership experience is desired
  • Experience with Azure, Microsoft Sentinel/Defender XDR, Entra ID, and Kusto Query Language (KQL) is desired
  • Active participation in Capture-the-Flag events and homelabbing is a plus
  • Understanding of x64 assembly, Windows data structures, and undocumented parts of Windows OS is desired
  • Familiarity with low-level reverse engineering and debugging tools such as Ghidra, x64dbg, and IDA is desired
  • Must participate in an on-call rotation

Benefits:

  • Fully paid individual healthcare, vision and dental insurance for the employee
  • Paid certification and training opportunities
  • Three weeks of paid vacation
  • 11 paid holidays
  • Supportive environment with a focus on keeping healthy work-life balance
  • Retirement benefit (401k) with company match
  • Potential transition into a team leadership role
  • Exposure to new and emerging technologies
  • Fun, dynamic environment working on interesting problems