SOC Analyst II

Sentinel Blue

United States

Remote

USD 90,000 - 130,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Healthcare coverage
Paid certification and training
Vacation and holidays
401k with company match

Job summary

Sentinel Blue is seeking a Security Operations Center (SOC) Analyst II to join our Overwatch Team. The role leads analysis, containment, and remediation of complex threats beyond initial triage, across a multi-tenant client base.

You will drive improvements to workflows, playbooks, and DFIR capabilities, while mentoring junior staff. This is a full-time, fully remote position requiring US citizenship with eligibility for a Secret clearance.

Qualifications

  • Experience leading analysis, containment, and remediation of complex threats.
  • Proven ability to investigate incidents from detection through resolution.
  • Familiarity with MITRE ATT&CK and Cyber Kill Chain.
  • Experience in DFIR, threat hunting, vulnerability management, and threat intel.

Responsibilities

  • Serve as primary escalation point for Tier I analysts and own high-severity alerts.
  • Analyze endpoints and network data to validate incidents and perform root-cause analysis.
  • Lead containment, eradication, and recovery during active incidents with SOPs and IR plans.
  • Reconstruct attack chains using MITRE ATT&CK and Cyber Kill Chain frameworks.
  • Conduct intelligence-driven threat hunts across environments for advanced threats.
  • Write executive reports with clear narrative, actionable recommendations.
  • Manage vulnerability lifecycle and coordinate remediation with IT/Engineering.
  • Develop and maintain IR playbooks and SOPs for consistent event handling.
  • Mentor Tier 1 analysts to improve triage capabilities and knowledge.
  • Participate in on-call rotation for off-hours coverage.

Skills

IR lifecycle
Windows internals
MITRE ATT&CK
Threat hunting
DFIR
Python/PowerShell
Networking protocols
Mentoring junior staff
On-call experience

Tools

Microsoft Sentinel
Elastic Stack
Splunk
Sysinternals Suite
Volatility
SIFT Workstation
CyberChef
Velociraptor
Wireshark

Job description

Sentinel Blue is seeking a Security Operations Center (SOC) Analyst II to join our Overwatch Team. In this role, the SOC Analyst II will lead the analysis, containment, and remediation of complex threats that extend beyond initial triage.

The ideal candidate can manage concurrent investigations across a multi-tenant client base, determine scope of impact, and investigate incidents from detection through resolution. They can think like an attacker and reconstruct how compromises occurred, drive improvements to workflows, playbooks, and documentation, and help advance our capabilities in digital forensics and incident response (DFIR), threat hunting, vulnerability management, and threat intelligence. Collaboration and mentoring junior staff will be key as we work to drive innovation.

This is a full-time position that is fully remote. Due to the nature of our work, you must be a U.S. citizen with eligibility for a clearance. No exceptions.

What We Can Offer:

Sentinel Blue is a young company with a focused mission: we're bringing enterprise-class cybersecurity to small and medium sized businesses. Frankly, we're pushing the envelope of how things are done and constantly seeking innovative ways to meet that mission. The pace is fast, and we're always learning new things. This is a great place if you want to expose yourself to new and emerging technologies, want to be challenged, and want to build your skills. Further, success in this role can quickly transition into a team leadership role. The right person will find themselves in a fun, dynamic environment, working on interesting problems and making a real difference.

Requirements:
  • U.S. citizenship - by nature of our work with the defense industry, all employees must be eligible for a Secret clearance.
  • Minimum of 2-5 years of experience in a Security Operations Center and/or a combination of experience in cyber-adjacent or IT administration roles such as.
Responsibilities:
  • Serve as the primary escalation point for Tier I analysts and take ownership of critical/high-severity alerts and escalated security incidents.
  • Analyze endpoints, network traffic, and other log data to validate security incidents and perform root cause analysis.
  • Lead containment, eradication, and recovery during active security incidents, ensuring Standard Operating Procedures (SOPs) and Incident Response (IR) Plans are followed and documented.
  • Reconstruct attack chains, utilizing the MITRE ATT&CK Framework and Cyber Kill Chain to map adversary tactics, techniques, and procedures (TTPs).
  • Conduct intelligence and/or hypothesis-driven threat hunts across environments to detect advanced threats that evade security tools and controls.
  • Write executive reports with a clear narrative structure, detailed analysis, and actionable recommendations.
  • Manage the vulnerability management lifecycle by analyzing scan results, prioritizing critical vulnerabilities based on risk and exploitability, and coordinating remediation efforts with IT/Engineering.
  • Develop and maintain IR playbooks and SOPs to ensure consistent and efficient event handling.
  • Provide technical guidance, training, and feedback to Tier 1 analysts to improve their triage capabilities and knowledge.
  • Participate in an on-call rotation to provide coverage for critical security incidents outside of standard business hours.
Knowledge & Skills
  • Incident Response: Perform deep dives, event correlation across logs, host and network artifacts for root cause analysis and respond across the IR lifecycle with remediation/containment actions.
  • Windows OS Internals: Intermediate to advanced understanding of various components and internal workings of the Windows OS such as Event Tracing for Windows, Win32 API, the Registry, Memory, and Process operations.
  • Attack Lifecycles & Frameworks: Map adversary tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework.
  • Threat Intelligence Integration: Correlate incidents with threat feeds using Indicators of Compromise (IoCs), threat actor attribution, and vulnerability exploitation patterns.
  • Networking & Protocols: Intermediate to advanced understanding of common network protocols such as TCP/IP, DNS, HTTP, SSL/TLS, etc.
  • Scripting & Automation: Intermediate to advanced writing and interpretation of Python or PowerShell scripts to parse logs or automate manual, repetitive tasks. Other scripting languages are beneficial as well.
  • System Administration: Ability to safely manage Windows devices via the command line using PowerShell or Batch.
  • Basic Malware Analysis: Ability to detect and reverse engineer malicious scripts or other high-level languages. Understanding of various code injection technique and other attack / evasion techniques as they relate to Windows.
  • Tools: Prior experience with SIEM platforms such as Microsoft Sentinel, ELK/Elastic Stack, Splunk, etc; Hands-on experience with Sysinternals Suite (Process Explorer, Autoruns, etc); Volatility; SIFT Workstation; CyberChef; Forensic Browser for SQLite; Velociraptor; Explorer Suite; Wireshark; malware analysis sandboxes, etc. Other equivalent tools are acceptable.
  • Adversarial Tradecraft: Familiarity of trending malware development, social engineering, phishing, exploitations, persistence, evasion techniques, credential theft, C2, exfiltration, and lateral movement.
Desired Qualifications:
  • Possession of intermediate to advanced certifications such as: GCIH/GCIA/GCFA, OSCP, BTL2, or equivalent is highly desired.
  • Previous experience in a team lead or supervisory leadership capacity, demonstrating the ability to drive operational goals, manage complex escalations, and effectively mentor junior staff.
  • Experience with Azure, Microsoft Sentinel/Defender XDR, Entra ID, and Kusto Query Language (KQL).
  • Active participation in Capture-the-Flag (CTF) events and homelabbing, a plus.
  • Understanding of various low-level mechanics such as x64 assembly, Windows data structures, and researching undocumented parts of the Windows OS.
  • Familiarity with low level reverse engineering, debugging and related tools such as Ghidra, x64dbg, IDA, etc.
Benefits:
  • Fully paid individual healthcare, vision and dental insurance for the employee.
  • Paid certification and training opportunities.
  • Three weeks of paid vacation + 11 paid holidays.
  • A supportive environment with a focus on keeping healthy work-life balance.
  • Retirement benefit (401k) with company match.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Analyst II (Fully Remote)
SOC Analyst II (Fully Remote)

Sentinel Blue • United States

Remote
USD 85,000 - 110,000
Fully remote
Health benefits
401(k)
+4
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
SOC Analyst I
SOC Analyst I

SOClogix, Inc. • Catonsville (MD)

On-site
USD 55,000 - 75,000
Health insurance
Dental insurance
Vision insurance
+6
Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

On-site
USD 97,600 - 109,800
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
Senior Detection and Response Analyst
Senior Detection and Response Analyst

Prestige Staffing • Dallas (TX)

On-site
USD 120,000 - 180,000
Contract extension potential
Remote work
Career growth
+2
Incident Responder
Incident Responder

SOClogix • Catonsville (MD)

Hybrid
USD 100,000 - 145,000
Health, dental, and vision insurance
401(k) with company match
Unlimited PTO
+1
Engineer, Security
Engineer, Security

11:11 Systems • United States

On-site
USD 120,000 - 160,000
Security Operations Analyst (L1)
Security Operations Analyst (L1)

Greenhouse Software, Inc. • United States

Remote
USD 65,000 - 90,000
20 paid vacation days per year
10 paid sick leave days per year
Public holidays as per company policy
+5
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

OneMain Financial • Washington

On-site
USD 140,000 - 190,000
Senior Security Operations Analyst - Onsite
Senior Security Operations Analyst - Onsite

Core Specialty Insurance Holdings, Inc. • Dallas (TX)

On-site
USD 90,000 - 130,000