Security Operations Center (SOC) Analyst II
ASM ResearchAbout the role
The Security Operations Center (SOC) Analyst II serves as a mid‑level cyber defender responsible for continuous monitoring, investigation, and response to security events across enterprise networks, endpoints, and cloud environments in a highly regulated government setting. This Tier 2 role handles alerts escalated from Tier 1, performing deeper analysis, driving containment and mitigation recommendations, and supporting coordinated remediation for mission‑critical systems. The analyst helps operate and tune SOC technologies such as SIEM, EDR/XDR, IDS/IPS, and threat intelligence platforms while improving playbooks, use cases, and procedures to enhance detection fidelity and reduce false positives.
Key Responsibilities
-
Conduct in‑depth analysis of security alerts escalated from Tier 1, correlating logs, network traffic, endpoint telemetry, and threat intelligence to determine incident scope, impact, and root cause.
-
Operate and tune SIEM, EDR/XDR, IDS/IPS, and related SOC tooling to improve detection fidelity, reduce false positives, and enhance visibility across on‑premises and cloud environments.
-
Execute Tier 2 incident response activities, including containment and mitigation recommendations, coordination with infrastructure and application teams, and support for digital evidence collection and documentation.
-
Review and apply emerging cyber threat intelligence, including indicators of compromise and adversary TTPs, to update rules, playbooks, and monitoring use cases aligned to frameworks such as MITRE ATT&CK.
-
Maintain accurate and detailed case records in ticketing and case‑management systems, supporting 24x7 operations with clear handoffs, status reporting, and after‑action inputs.
-
Support compliance‑driven operations in a highly regulated government environment by following established SOPs, incident handling processes, and security control requirements for mission‑critical systems.
-
Collaborate with and mentor Tier 1 analysts by providing guidance on triage techniques, escalation criteria, and best practices for investigating suspicious activity.
Required Qualifications
-
Bachelor’s Degree in Computer Science, Information Assurance, Cybersecurity, or a closely related field, or equivalent relevant experience (aligned to Operations Security Planner II standard).Standard-Job-Titles-SharePoint-2-11.xlsx
-
Typically 3–5 years of prior experience in a SOC, cyber incident response, or closely related security operations role handling Tier 1/Tier 2 investigations.
-
Demonstrated hands‑on experience operating and tuning SIEM, endpoint security (EDR/XDR), IDS/IPS, and related SOC tools in enterprise environments.
-
Strong analytical skills in log analysis, network traffic review, and endpoint telemetry, with the ability to determine incident scope, impact, and probable root cause.
-
Familiarity with cyber threat intelligence concepts, indicators of compromise, and adversary TTPs, and experience applying these within monitoring and detection use cases.
-
U.S. Citizenship required, wi
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s