SOC Analyst, Tier II

Indigo IT LLC

Fort Bragg (NC)

On-site

USD 75,000 - 110,000

Full time

33 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical insurance
Dental coverage
Vision coverage
401(k) match
Paid time off
Education support
Bonuses & recognition

Job summary

Indigo IT LLC, Fort Bragg, NC, seeks Tier 2 Watch Analysts to join the 24/7 Blue Team for US Army Reserve cyber defense. You will own incident records, perform multi-source correlation, and recommend containment actions while coordinating with the Blue Team lead and ISSO.

This role requires DoD experience, DoD 8140.03 intermediate qualifications, and a current DoD SECRET clearance, along with on-site work at Fort Bragg. Eligible candidates possess strong communication and analytic skills.

Qualifications

  • Bachelor's degree in a related field.
  • 5+ years of DoD/cyber operations experience.
  • DoD 8140.03 Intermediate qualification.
  • US Citizenship required.
  • Current DoD SECRET clearance required.
  • DoD Cyber Awareness training within 30 days.

Responsibilities

  • Stand watch on a 24/7/365 rotation performing Tier 1 and Tier 2 functions.
  • Correlate anomalous activity across SIEM/EDR/network data to characterize event scope.
  • Own incident records through closure; coordinate containment/eradication actions.
  • Provide quality-control review and contribute to daily/weekly reporting.

Skills

DoD/Army cyber operations
Multisource investigation
SIEM analysis
EDR & PCAP analysis
Network security monitoring
Stakeholder communication
Scripting familiarity

Education

Bachelor's degree
5 years experience
DoD 8140.03 (Intermediate)
US Citizenship
DoD SECRET clearance
Security training (Awareness)

Tools

Elastic SIEM
Trellix ENS
Tychon EDR
Wireshark

Job description

SUMMARY

Founded in 2001, Indigo IT is an award-winning information technology consulting and services company. We are a trusted services provider to government agencies seeking innovative Cloud, Cybersecurity, Knowledge Management, and Enterprise solutions. We know our defense, federal, and civilian customers have critical IT infrastructures that must remain reliable, available, and maximized. Indigo IT is mission focused and committed to maintaining a sense of urgency in anticipating and supporting our customers’ technology goals and objectives. Our unique ability to think beyond today allows our clients to stay ahead of their IT challenges. As a Veteran-Friendly employer, we are proudly partnered with the Virginia Values Veterans (V3) Program, and a recipient of the HIRE Vets Gold Medallion Award, which recognizes our commitment to recruiting our nation’s Veterans. Recognized on the Inc. 5000 list of America’s fastest growing companies in 2020 & 2021 and named as one of the 2022 Best Places to Work in Virginia, we are always looking to hire top talent in the field - come join us today!

Fort Bragg, NC
SUMMARY

Founded in 2001, Indigo IT is an award-winning information technology consulting and services company. We are a trusted services provider to government agencies seeking innovative Cloud, Cybersecurity, Knowledge Management, and Enterprise solutions. We know our defense, federal, and civilian customers have critical IT infrastructures that must remain reliable, available, and maximized. Indigo IT is mission focused and committed to maintaining a sense of urgency in anticipating and supporting our customers’ technology goals and objectives. Our unique ability to think beyond today allows our clients to stay ahead of their IT challenges. As a Veteran-Friendly employer, we are proudly partnered with the Virginia Values Veterans (V3) Program, and a recipient of the HIRE Vets Gold Medallion Award, which recognizes our commitment to recruiting our nation’s Veterans. Recognized on the Inc. 5000 list of America’s fastest growing companies in 2020 & 2021 and named as one of the 2022 Best Places to Work in Virginia, we are always looking to hire top talent in the field - come join us today!

The USARC Defensive Cyberspace Operations Mission Support Services (DCOMSS) program establishes a dedicated, 24/7/365 cyber defense capability for the U.S. Army Reserve Command CIO/G-6, operating as a Cyber Security Service Provider - Executor (CSSP-E). The team performs continuous network security monitoring, detection, analysis, and incident response across NIPRNet and SIPRNet; integrated assessments under the Computer Defense Assistance Program (Network Assistance Visits, Network Damage Assessments, and web assessments); and Cyber Threat Intelligence collection, correlation, signature development, and finished intelligence production in support of approximately 205,000 Army Reserve personnel.

We are seeking Tier 2 Watch Analysts to serve as the investigation and correlation layer of the 24/7/365 Blue Team watch. Tier 2 analysts stand watch on the rotation, own incident records from creation through closure, perform multi-source correlation, recommend containment and eradication actions, and quality-control Tier 1 work before closure.

ESSENTIAL FUNCTIONS/RESPONSIBILITIES
Watch Operations
  • Stand assigned watch periods on the approved 24/7/365 rotation, performing Tier 1 and Tier 2 functions on console within qualification and SOP boundaries
  • Execute pass-down log entries, verbal handoff briefings, and critical-incident re-confirmation at every shift change
  • Support hunts, training, and exercises only after watch coverage is protected
Investigation and Correlation
  • Correlate anomalous activity across SIEM (Elastic), Trellix ENS, Tychon EDR, full packet capture, NetFlow, IDS/IPS, proxy, router/firewall syslog, and boundary-device telemetry to characterize event scope
  • Escalate suspected APT activity, complex intrusions, and uncertain containment to the Blue Team Lead (Tier 3) without delay
Incident Handling and Response
  • Own incident records through closure, including CJCSM 6510.01B category assignment, timely reporting, and currency of the ARCYBER incident-handling portal
  • Recommend containment and eradication actions in coordination with the affected mission owner and ISSO; execute approved critical blocks within the two-hour standard
  • Capture and perform initial analysis of volatile data, logs, and captured traffic; maintain chain of custody and coordinate evidence shipment to ARCYBER F&MA when required
  • On-Call Responsibilities – Phone response within 30 mins of incident and on-site reporting within one hour, when required
Quality Control and Reporting
  • Perform quality-control review of Tier 1 tickets prior to closure; conduct incident trend analysis
  • Provide technical inputs to the Daily Blue Team Operations Report and weekly and monthly Blue Team reporting
EDUCATION, EXPERIENCE, & CERTIFICATIONS
  • Bachelor's degree and 5 years of experience
  • DoDM 8140.03 qualification for DCWF 511 Cyber Defense Analyst at Intermediate proficiency (required for any solo watch assignment)
  • DoDM 8140.03 qualification for DCWF 531 Cyber Defense Incident Responder at Intermediate proficiency required for selected positions assigned incident-response duties
  • Favorably adjudicated Tier 3 investigation; Tier 5 required prior to any privileged access
  • US Citizenship required
  • Current DoD SECRET clearance required (interim SECRET acceptable at start; final SECRET required within 120 days of award)
  • Ability to obtain and maintain a DoD Common Access Card and USARC installation access
  • Completion of DoD Cyber Awareness training prior to system access and annually thereafter; AT Level I, OPSEC Level I, TARP, and CUI training within 30 days of start
SPECIFIC KNOWLEDGE, SKILLS, & ABILITIES
  • Demonstrated experience in a DoD or enterprise SOC performing multi-source investigation and correlation
  • Hands-on proficiency with an enterprise SIEM (Elastic preferred) and with host-based security, EDR, PCAP, NetFlow, and IDS/IPS analysis
  • Working knowledge of MITRE ATT&CK, CJCSM 6510.01B incident categories, and DoD incident reporting timelines
  • Familiarity with volatile data capture, evidence preservation, and chain-of-custody procedures
  • Familiarity with Windows, Linux, and macOS operating systems and with Wireshark and scripting for repeatable triage
  • Ability to work rotating shifts and to maintain accuracy and attention during extended monitoring periods
  • Working knowledge of CJCSM 6510.01B incident categories and DoD/Army cyber incident reporting requirements
  • Excellent interpersonal and written communication skills to interact effectively with Government stakeholders, ARCYBER and Regional Cyber Center counterparts, and team members
  • The ability to communicate complex technical findings clearly to non-technical audiences
  • A willingness to uncover, document, and communicate deviations from planned outcomes in order to improve processes and prevent recurrence
  • A passion for continuous learning and a commitment to stay current with emerging threats, adversary tradecraft, and defensive technologies
Work Environment
  • Onsite presence at USARC Headquarters, Fort Bragg, NC required
  • Rotating 8-hour shifts on a 24/7/365 watch including nights, weekends, and Federal holidays
  • Solo watch assignments during evening, night, weekend, and holiday periods

At Indigo IT, we offer an expansive benefits package for our employees, which includes: Medical, Dental, and Vision coverage options. In addition, we offer 401(k) with company match, Group life and disability, Flex Spending Accounts (FSA), Paid Time Off (PTO), Paid holidays, and Education assistance. We also have in house training programs for employees, we reward thought leadership with bonuses and recognition for publishing, speaking, and innovative thought leadership in our industry.

Indigo IT is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. This employer uses E-Verify.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Analyst, Tier II
SOC Analyst, Tier II

Indigo IT, LLC • Fort Bragg (NC)

On-site
USD 80,000 - 110,000
Medical, Dental, Vision coverage
401(k) with company match
Life and disability insurance
+1
SOC Analyst, Tier I
SOC Analyst, Tier I

Indigo IT LLC • Fort Bragg (NC)

On-site
USD 70,000 - 95,000
Medical, Dental, Vision
401(k) with company match
Paid Time Off
+2
SOC Analyst, Tier I
SOC Analyst, Tier I

Indigo IT, LLC • Fort Bragg (NC)

On-site
USD 60,000 - 87,000
Medical/Dental/Vision
401(k) with company match
PTO & Holidays
+1
Malware Analyst
Malware Analyst

Indigo IT LLC • Fort Bragg (NC)

On-site
USD 110,000 - 150,000
Medical, Dental, Vision coverage
401(k) with company match
Group life and disability
+5
Malware Analyst
Malware Analyst

Indigo IT, LLC • Fort Bragg (NC)

On-site
USD 75,000 - 130,000
Medical, Dental, Vision coverage
401(k) with company match
Paid time off
+3
Cyber Threat Intelligence (CTI) Analyst
Cyber Threat Intelligence (CTI) Analyst

Indigo IT LLC • Fort Bragg (NC)

On-site
USD 95,000 - 150,000
Medical benefits
Dental benefits
Vision benefits
+9
Blue Team Lead / Sr Cyber Defense Analyst
Blue Team Lead / Sr Cyber Defense Analyst

Indigo IT, LLC • Fort Bragg (NC)

On-site
USD 125,000 - 150,000
Medical, Dental, and Vision coverage
401(k) with company match
Group life and disability
+4
Cyber Threat Intelligence (CTI) Analyst
Cyber Threat Intelligence (CTI) Analyst

Indigo IT, LLC • Fort Bragg (NC)

On-site
USD 90,000 - 110,000
Medical coverage
401(k) with company match
Paid holidays
+2
DCOMSS - Blue Team Lead / Senior Cyber Defense Analyst
DCOMSS - Blue Team Lead / Senior Cyber Defense Analyst

Technology,-Automation,-and-Management,-Inc. • Fort Bragg (NC)

On-site
USD 120,000 - 180,000
Relocation Assistance
Sign-on Bonus
Travel Required
Intermediate SOC Analyst (Fort Bragg, NC)
Intermediate SOC Analyst (Fort Bragg, NC)

ADP, Inc. • Fort Bragg (NC)

On-site
USD 80,000 - 90,000
Health plans
401(k) plan with employer match
Paid time off