Level 2 Cyber Security Analyst

Netrio

McKinney (TX)

On-site

USD 80,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Netrio is seeking a mid-level SOC Analyst II to investigate escalated alerts, perform root-cause analysis, and mentor Tier 1 analysts. You will lead containment and remediation actions for incidents across multi-tenant government client environments, coordinating with client contacts under defined protocols.

Responsibilities include threat hunting, detection engineering, evidence handling per CMMC/NIST frameworks, and participation in IR tabletop exercises. U.S.

Qualifications

  • 2–5 years of experience in a SOC/IR/threat hunting role
  • Experience with at least one SIEM/XDR platform and one EDR platform in production
  • Solid understanding of the cyber kill chain, MITRE ATT&CK framework, and common adversary TTPs
  • U.S. Citizenship and ability to pass a background check
  • Ability to pass a background investigation as required by client contracts

Responsibilities

  • Perform in-depth investigation of escalated alerts and incidents using SIEM/XDR and EDR platforms
  • Conduct root-cause analysis, threat correlation, and impact assessment across multi-tenant government client environments
  • Lead containment, eradication, and recovery actions for confirmed incidents per incident response playbooks
  • Own DFARS 252.204-7012 incident reporting workflow, including 72-hour DIBNet reporting coordination and 90-day data preservation requirements
  • Perform threat hunting across EDR, SIEM, and identity telemetry
  • Mentor and validate escalations from Tier 1 analysts; provide on-shift coaching and quality review of Tier 1 triage decisions
  • Refine and author detection use cases, correlation rules, and playbooks from findings
  • Coordinate with client POCs during active incidents per protocols
  • Support endpoint management (RMM) and email security investigations as they intersect with incidents
  • Maintain and validate chain-of-custody and evidence-handling procedures for CUI investigations under CMMC Level 2 / NIST SP 800-171
  • Participate in tabletop exercises, IR plan reviews, and audit/assessment support (C3PAO readiness)

Skills

SOC experience
Threat hunting
Incident response
Mentoring

Education

DoD 8140 certifications (CySA+/GCIH/GCFA)

Tools

SIEM/XDR
EDR

Job description

The SOC Analyst II is a mid-level, hands-on investigative role responsible for deep-dive analysis, incident response, and mentorship of Tier 1 analysts within Netrio's Government SOC. This role aligns to the DoD 8140/DCWF Cyber Defense Analyst (511) work role at an intermediate proficiency level and serves as the primary escalation point for confirmed or suspected security incidents across federal and Defense Industrial Base (DIB) client environments hosted in government-authorized cloud platforms.

Key Responsibilities
  • Perform in-depth investigation of escalated alerts and incidents using SIEM/XDR and EDR platforms
  • Conduct root-cause analysis, threat correlation, and impact assessment across multi-tenant government client environments
  • Lead containment, eradication, and recovery actions for confirmed incidents per incident response playbooks
  • Own DFARS 252.204-7012 incident reporting workflow, including 72-hour DIBNet reporting coordination and 90-day data preservation requirements
  • Perform threat hunting activities across EDR, SIEM, and identity telemetry (conditional access alerts, sign-in logs)
  • Mentor and validate escalations from Tier 1 analysts; provide on-shift coaching and quality review of Tier 1 triage decisions
  • Refine and author detection use cases, correlation rules, and playbooks based on investigation findings
  • Coordinate with client points of contact during active incidents, within defined communication protocols
  • Support endpoint management (RMM) and email security investigations as they intersect with broader incidents
  • Maintain and validate chain-of-custody and evidence-handling procedures for CUI-related investigations under CMMC Level 2 / NIST SP 800-171
  • Participate in tabletop exercises, incident response plan reviews, and audit/assessment support (C3PAO readiness activities)
Required Qualifications
  • 2–5 years of experience in a SOC analyst, incident response, or threat hunting role
  • Demonstrated experience with at least one SIEM/XDR platform and one EDR platform in a production capacity
  • Solid understanding of the cyber kill chain, MITRE ATT&CK framework, and common adversary TTPs
  • Experience with log analysis, network traffic analysis, and basic malware/artifact triageStrong incident documentation and client communication skills, including under time pressure
  • U.S. Citizenship (required for access to government client environments)
  • Ability to pass a background investigation as required by client contracts
Required Certifications (DoD 8140/DCWF Alignment)

CompTIA CySA+ and/or GIAC GCIH (Certified Incident Handler). GIAC GCFA (Certified Forensic Analyst) preferred, especially for candidates focused on investigation/forensics depth.

If not held at hire, required certification(s) must be obtained within the first 6 months of employment as a condition of continued assignment to government client accounts (DoD 8140 intermediate-level certification requirement).

Preferred Qualifications
  • Prior experience supporting CMMC, FedRAMP, or NIST 800-171/800-53 controlled environments
  • Experience in a multi-tenant MSSP or managed detection and response (MDR) setting
  • Scripting/automation experience (PowerShell, Python) for detection engineering or response automation
  • Familiarity with government cloud administrative constructs (e.g., GCC High, Azure Government, or equivalent)
  • Experience mentoring or leading junior analysts
Work Environment & Physical Requirements
  • Extended periods at a workstation monitoring multiple screens/dashboards and investigation tooling
  • Ability to work rotating shifts, including nights, weekends, and holidays
  • Ability to respond to off-hours pages/alerts during on-call rotation, including leading response for active incidents outside normal working hours
  • This is a 24/7 operational function — reliable attendance and shift punctuality are essential job functions

This job requisition is intended to describe the general nature of the work performed. It is not an exhaustive list of all duties, responsibilities, and qualification

Netrio is a leading MSP in North America, specializing in IT solutions for small- to mid-market enterprises. We serve over 1,000 clients across industries with services including managed IT, cybersecurity, cloud, connectivity, voice, and custom application development.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Level 1 Cyber Security Analyst
Level 1 Cyber Security Analyst

Netrio • McKinney (TX)

On-site
USD 65,000 - 90,000
SOC Analyst I — Entry-Level Cyber Defense (DoD/Govt)
SOC Analyst I — Entry-Level Cyber Defense (DoD/Govt)

Netrio • McKinney (TX)

On-site
USD 65,000 - 90,000
Cyber Network Defense Analyst
Cyber Network Defense Analyst

Base One Technologies • Washington

Hybrid
USD 65,000 - 85,000
Cyber Threat Analyst II
Cyber Threat Analyst II

NewGen Technologies • Arlington (VA)

On-site
USD 90,000 - 120,000
Senior Cyber Manager
Senior Cyber Manager

Peraton • Washington

On-site
USD 120,000 - 170,000
Cybersecurity Analyst, Security Operations Center (SOC) Analyst
Cybersecurity Analyst, Security Operations Center (SOC) Analyst

Digital-Global-Connectors • McLean (VA)

Hybrid
USD 90,000 - 130,000
Cybersecurity Analyst, Security Operations Center (SOC) Analyst
Cybersecurity Analyst, Security Operations Center (SOC) Analyst

Digital Global Connectors • McLean (VA)

Hybrid
USD 70,000 - 110,000
SOC Analyst
SOC Analyst

NTG • Alexandria (VA)

On-site
USD 85,000 - 125,000
Senior Security Analyst – Security Operations Center
Senior Security Analyst – Security Operations Center

Jobtailor • Town of Florida (NY)

On-site
USD 120,000 - 180,000
SOC Analyst
SOC Analyst

Tactibit • Suitland (MD)

On-site
USD 85,000 - 110,000