SOC Incident Response Lead & Threat Hunter

Netrio

McKinney (TX)

On-site

USD 80,000 - 110,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Netrio is seeking a mid-level SOC Analyst II to investigate escalated alerts, perform root-cause analysis, and mentor Tier 1 analysts. You will lead containment and remediation actions for incidents across multi-tenant government client environments, coordinating with client contacts under defined protocols.

Responsibilities include threat hunting, detection engineering, evidence handling per CMMC/NIST frameworks, and participation in IR tabletop exercises. U.S.

Qualifications

  • 2–5 years of experience in a SOC/IR/threat hunting role
  • Experience with at least one SIEM/XDR platform and one EDR platform in production
  • Solid understanding of the cyber kill chain, MITRE ATT&CK framework, and common adversary TTPs
  • U.S. Citizenship and ability to pass a background check
  • Ability to pass a background investigation as required by client contracts

Responsibilities

  • Perform in-depth investigation of escalated alerts and incidents using SIEM/XDR and EDR platforms
  • Conduct root-cause analysis, threat correlation, and impact assessment across multi-tenant government client environments
  • Lead containment, eradication, and recovery actions for confirmed incidents per incident response playbooks
  • Own DFARS 252.204-7012 incident reporting workflow, including 72-hour DIBNet reporting coordination and 90-day data preservation requirements
  • Perform threat hunting across EDR, SIEM, and identity telemetry
  • Mentor and validate escalations from Tier 1 analysts; provide on-shift coaching and quality review of Tier 1 triage decisions
  • Refine and author detection use cases, correlation rules, and playbooks from findings
  • Coordinate with client POCs during active incidents per protocols
  • Support endpoint management (RMM) and email security investigations as they intersect with incidents
  • Maintain and validate chain-of-custody and evidence-handling procedures for CUI investigations under CMMC Level 2 / NIST SP 800-171
  • Participate in tabletop exercises, IR plan reviews, and audit/assessment support (C3PAO readiness)

Skills

SOC experience
Threat hunting
Incident response
Mentoring

Education

DoD 8140 certifications (CySA+/GCIH/GCFA)

Tools

SIEM/XDR
EDR

Job description

Netrio is seeking a mid-level SOC Analyst II to investigate escalated alerts, perform root-cause analysis, and mentor Tier 1 analysts. You will lead containment and remediation actions for incidents across multi-tenant government client environments, coordinating with client contacts under defined protocols.

Responsibilities include threat hunting, detection engineering, evidence handling per CMMC/NIST frameworks, and participation in IR tabletop exercises. U.S.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Level 2 Cyber Security Analyst
Level 2 Cyber Security Analyst

Netrio • McKinney (TX)

On-site
USD 80,000 - 110,000
Senior SOC Analyst - Lead Incident Response & Threat Hunting
Senior SOC Analyst - Lead Incident Response & Threat Hunting

Confidential • United States

Hybrid
USD 120,000 - 180,000
SOC Analyst II: Threat Hunting & Incident Response (Onsite)
SOC Analyst II: Threat Hunting & Incident Response (Onsite)

Lateral Insights LLC • Great Falls (VA)

On-site
USD 70,000 - 110,000
Senior Cybersecurity Analyst: Threat Hunting & IR Lead
Senior Cybersecurity Analyst: Threat Hunting & IR Lead

ActioNet, Inc. • Rockville (MD)

On-site
USD 130,000 - 170,000
Medical Insurance
Vision Insurance
Life and AD&D Insurance
+8
SOC Threat Hunter & Incident Response Lead
SOC Threat Hunter & Incident Response Lead

Weiatech, LLC • United States

Hybrid
USD 80,000 - 120,000
Medical benefits
Paid time off
Professional development opportunities
Remote SOC Engineer II - Threat Detection & Incident Lead
Remote SOC Engineer II - Threat Detection & Incident Lead

CTS • United States

On-site
USD 80,000 - 85,000
Health Insurance
401(k) with company match
Paid Time Off
+6
Senior SOC Threat Hunter & Incident Lead
Senior SOC Threat Hunter & Incident Lead

Weiatech, LLC • United States

Remote
USD 100,000 - 140,000
SOC Threat Hunter & Incident Response Engineer
SOC Threat Hunter & Incident Response Engineer

Cyberdata Technologies, Inc. • Herndon (VA)

On-site
USD 80,000 - 120,000
Tier 2 SOC Analyst: Incident Response & Threat Analysis
Tier 2 SOC Analyst: Incident Response & Threat Analysis

Jobtailor • California (MO)

On-site
USD 95,000 - 125,000
Tier 2 SOC Security Analyst – Incident Response & Hunting
Tier 2 SOC Security Analyst – Incident Response & Hunting

Tgi Main Company • West Caldwell (NJ), Cherry Hill Township (NJ), Boca Raton (FL)

On-site
USD 75,000 - 95,000
Dental insurance
Health insurance
Vision insurance
+3