CSOC CIR Tier II Analyst

PingWind

Hines (IL)

On-site

USD 79,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Eleven Federal Holidays
Paid Time Off accrued each pay period
Parental Leave
Medical, Dental and Vision Insurance

Job summary

PingWind, Inc. is seeking a Cyber Incident Response Tier II Analyst to support our VA customer located at Hines, IL; Martinsburg, WV; or Austin, TX.

This on-site role requires 3+ years in enterprise SOC incident response and the ability to obtain Tier 4 / High Risk clearance. You will monitor security alerts with SIEM/EDR, triage incidents, document actions, and collaborate with forensics, threat intel, IT, and network teams.

Qualifications

  • Bachelor's degree in computer science, cybersecurity, information technology, or related field (or equivalent work experience).
  • 3+ years of experience supporting incident response in an enterprise-level SOC.
  • Ability to obtain Tier 4 / High Risk Background Investigation.

Responsibilities

  • Perform real-time monitoring and triage of security alerts in cybersecurity toolsets including SIEM, and EDR.
  • Make accurate determination of what alerts are false positives or require further investigation and prioritization.
  • Lead and actively participate in the investigation, analysis, and resolution of cybersecurity incidents; analyze attack patterns, determine the root cause, and recommend appropriate remediation measures to prevent future occurrences.
  • Ensure accurate and detailed documentation of incident response activities, including analysis, actions taken, and lessons learned; collaborate with knowledge management teams to maintain up-to-date incident response playbooks.
  • Collaborate effectively with cross-functional teams, including forensics, threat intelligence, IT, and network administrators; clearly communicate technical information and incident-related updates to management and stakeholders.
  • Identify and action opportunities for tuning alerts to make the incident response team more efficient.
  • Monitor the performance of security analytics and automation processes regularly, identifying areas for improvement and taking proactive measures to enhance their efficacy.
  • Leverage Security Orchestration, Automation, and Response (SOAR) platforms to streamline and automate incident response processes, including enrichment, containment, and remediation actions.
  • Support the mentoring and training of more junior IR staff.
  • Stay informed about the latest cybersecurity threats, trends, and best practices; actively participate in cybersecurity exercises, drills, and simulations to improve incident response capabilities.

Skills

Incident response
SOC operations
Cybersecurity monitoring
Threat analysis

Education

Bachelor's degree or equivalent (CS/ cybersecurity/ IT)

Tools

SIEM
EDR
IDS/IPS
Network monitoring
ServiceNow

Job description

Location: On-site in Hines, IL; Martinsburg, WV; or Austin, TX.

Required Clearance: Ability to obtain Tier 4 / High Risk Background Investigation.

Required Education: Bachelor's degree in computer science, Cybersecurity, Information Technology, or a related field (or equivalent work experience).

Required Experience: 3+ years of experience supporting incident response in an enterprise-level Security Operations Center (SOC).

Description

PingWind is seeking a Cyber Incident Response Tier II Analyst to support our VA customer at Hines, IL; Martinsburg, WV; or Austin, TX.

Certifications

Must currently have or be willing to obtain one of the following certifications (or equivalent):

  • GIAC Certified Incident Handler
  • EC-Council’s Certified Incident Handler (ECIH)
  • GIAC Certified Incident Handler (GCIH)
  • Incident Handling & Response Professional (IHRP)
  • Certified Computer Security Incident Handler (CSIH)
  • Certified Incident Handling Engineer (CIHE)
  • EC-Council’s Certified Ethical Hacker
Responsibilities
  • Perform real-time monitoring and triage of security alerts in cybersecurity toolsets including SIEM, and EDR.
  • Make accurate determination of what alerts are false positives or require further investigation and prioritization.
  • Lead and actively participate in the investigation, analysis, and resolution of cybersecurity incidents; analyze attack patterns, determine the root cause, and recommend appropriate remediation measures to prevent future occurrences.
  • Ensure accurate and detailed documentation of incident response activities, including analysis, actions taken, and lessons learned; collaborate with knowledge management teams to maintain up-to-date incident response playbooks.
  • Collaborate effectively with cross-functional teams, including forensics, threat intelligence, IT, and network administrators; clearly communicate technical information and incident-related updates to management and stakeholders.
  • Identify and action opportunities for tuning alerts to make the incident response team more efficient.
  • Monitor the performance of security analytics and automation processes regularly, identifying areas for improvement and taking proactive measures to enhance their efficacy.
  • Leverage Security Orchestration, Automation, and Response (SOAR) platforms to streamline and automate incident response processes, including enrichment, containment, and remediation actions.
  • Support the mentoring and training of more junior IR staff.
  • Stay informed about the latest cybersecurity threats, trends, and best practices; actively participate in cybersecurity exercises, drills, and simulations to improve incident response capabilities.
Requirements
  • Work 100% on-site Monday – Friday from 11:00 PM to 7:00 AM.
  • A deep understanding of cybersecurity principles, incident response methodologies, and a proactive mindset to ensure our SOC operates effectively in a high‑pressure environment.
  • Strong experience with security technologies, including SIEM, IDS/IPS, EDR, and network monitoring tools.
  • Experience with enterprise ticketing systems like ServiceNow.
  • Excellent analytical and problem‑solving skills.
  • Ability to work independently and in a team environment to identify errors, pinpoint root causes, and devise solutions with minimal oversight.
  • Ability to learn and function in multiple capacities and learn quickly.
  • Strong verbal and written communication skills.
Preferred Qualifications
  • Ability to investigate Indicators of Compromise (IOCs) using Splunk by correlating logs from multiple sources to detect, trace, and assess threat activity across the enterprise.
  • Experience leveraging Microsoft Defender for Endpoint (MDE) to perform endpoint investigations, analyze process trees, and validate IOCs during active threat scenarios.
  • Ability to remediate phishing incidents, including analysis of email headers, links, and attachments, identifying impacted users, and executing containment actions such as user lockouts, email quarantine, and domain blacklisting.
  • Experience performing root cause analysis of malware leveraging PowerShell, using tools such as MDE advanced hunting (KQL) and Splunk to identify infection paths, attacker behavior, and persistence mechanisms.
Benefits
  • Eleven Federal Holidays
  • Paid Time Off accrued each pay period
  • Parental Leave
  • Three medical plan choices with generous employer contribution
  • Dental and Vision Insurance
  • Company paid Short-Term and Long-Term Disability
  • Company paid Life and AD&D Insurance
  • 401k with competitive matching and vesting schedule
  • Continuing education assistance
  • Short Term / Long Term Disability & Life Insurance
  • Medical, Dependent Care and Commuter Flexible Spending Accounts
  • Employee Assistance Program
  • Wellness benefits include Calm Health app and WellHub gym subsidy (formerly GymPass)
  • 529 College Savings Plan
  • Legal Insurance
  • Pet Insurance
Salary Range

$79k-$110k

The pay range for this job is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) job responsibilities, education, certifications, experience, as well as internal equity mapping and alignment with market data, or other applicable laws.

Veterans are encouraged to apply.

PingWind, Inc. does not discriminate in employment opportunities, terms, and conditions of employment, or practices on the basis of race, age, gender, religious or political beliefs, national origin or heritage, disability, sexual orientation, or any characteristic protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

CSOC CIR Tier II Analyst
CSOC CIR Tier II Analyst

PingWind • Hines (OR)

On-site
USD 79,000 - 110,000
Paid Time Off
Parental Leave
Dental and Vision Insurance
+1
Cyber Incident Response Tier II Analyst - On-Site
Cyber Incident Response Tier II Analyst - On-Site

PingWind • Hines (OR)

On-site
USD 79,000 - 110,000
Paid Time Off
Parental Leave
Dental and Vision Insurance
+1
SOC Analyst Tier 3
SOC Analyst Tier 3

JFL CONSULTING, LLC • Springfield (VA)

On-site
USD 140,000 - 180,000
Salary: $140k- $180k
100% employer-paid medical, dental, &
CSOC Analyst T1
CSOC Analyst T1

Nightwing • Falls Church (VA)

Remote
USD 64,000 - 128,000
401(k) plan
PTO
Holidays
+1
SOC Analyst
SOC Analyst

Gridiron IT • Huntsville (AL)

On-site
USD 100,000 - 115,000
Cyber IR Tier II Analyst – Night Shift On-site
Cyber IR Tier II Analyst – Night Shift On-site

Medium • Hines (IL)

On-site
USD 79,000 - 110,000
Eleven Federal Holidays
Paid Time Off accrued each pay period
Parental Leave
+1
Security Operation Center (SOC) Analyst II
Security Operation Center (SOC) Analyst II

General Dynamics Information Technology • Colorado Springs (CO)

On-site
USD 112,000 - 138,000
Medical plan options
Dental and Vision plan options
401(k) plan with company match
Cybersecurity Lead
Cybersecurity Lead

PingWind, Inc. • Huntsville (AL)

On-site
USD 106,000 - 148,000
Eleven Federal Holidays
Paid Time Off
Parental Leave
+12
Cybersecurity Lead
Cybersecurity Lead

PingWind • Huntsville (AL)

On-site
USD 106,000 - 148,000
Eleven Federal Holidays
Paid Time Off
Parental Leave
+3
Mid Level SOC Operations Analyst with Security Clearance
Mid Level SOC Operations Analyst with Security Clearance

Cintel, Inc. • Huntsville (AL)

On-site
USD 75,000 - 95,000