Security Operations Center (SOC) Analyst II

ASM ResearchRemote,
Onsite

About The Position

The Security Operations Center (SOC) Analyst II serves as a mid-level cyber defender responsible for continuous monitoring, investigation, and response to security events across enterprise networks, endpoints, and cloud environments in a highly regulated government setting. This Tier 2 role handles alerts escalated from Tier 1, performing deeper analysis, driving containment and mitigation recommendations, and supporting coordinated remediation for mission-critical systems. The analyst helps operate and tune SOC technologies such as SIEM, EDR/XDR, IDS/IPS, and threat intelligence platforms while improving playbooks, use cases, and procedures to enhance detection fidelity and reduce false positives.

Requirements

  • Bachelor’s Degree in Computer Science, Information Assurance, Cybersecurity, or a closely related field, or equivalent relevant experience (aligned to Operations Security Planner II standard).
  • Typically 3–5 years of prior experience in a SOC, cyber incident response, or closely related security operations role handling Tier 1/Tier 2 investigations.
  • Demonstrated hands-on experience operating and tuning SIEM, endpoint security (EDR/XDR), IDS/IPS, and related SOC tools in enterprise environments.
  • Strong analytical skills in log analysis, network traffic review, and endpoint telemetry, with the ability to determine incident scope, impact, and probable root cause.
  • Familiarity with cyber threat intelligence concepts, indicators of compromise, and adversary TTPs, and experience applying these within monitoring and detection use cases.
  • U.S. Citizenship required, with ability to satisfy background investigation requirements appropriate to a federal IT environment.
  • Ability to work effectively as part of a 24x7 SOC operation, including clear written and verbal communication for case documentation and handoffs.

Nice To Haves

  • Experience with leading SIEM and endpoint security platforms such as Splunk, Microsoft Sentinel, Microsoft Defender, or similar tools.
  • Industry certifications such as Security+, CySA+, GCIH, or equivalent SOC/incident response credentials.
  • Prior experience supporting federal or other highly regulated environments requiring U.S. citizenship and eligibility for a clearance or public trust.
  • Familiarity with frameworks such as MITRE ATT&CK and NIST 800-series as they relate to SOC use cases, detection engineering, and incident handling.

Responsibilities

  • Conduct in-depth analysis of security alerts escalated from Tier 1, correlating logs, network traffic, endpoint telemetry, and threat intelligence to determine incident scope, impact, and root cause.
  • Operate and tune SIEM, EDR/XDR, IDS/IPS, and related SOC tooling to improve detection fidelity, reduce false positives, and enhance visibility across on-premises and cloud environments.
  • Execute Tier 2 incident response activities, including containment and mitigation recommendations, coordination with infrastructure and application teams, and support for digital evidence collection and documentation.
  • Review and apply emerging cyber threat intelligence, including indicators of compromise and adversary TTPs, to update rules, playbooks, and monitoring use cases aligned to frameworks such as MITRE ATT&CK.
  • Maintain accurate and detailed case records in ticketing and case-management systems, supporting 24x7 operations with clear handoffs, status reporting, and after-action inputs.
  • Support compliance-driven operations in a highly regulated government environment by following established SOPs, incident handling processes, and security control requirements for mission-critical systems.
  • Collaborate with and mentor Tier 1 analysts by providing guidance on triage techniques, escalation criteria, and best practices for investigating suspicious activity.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service