SOC Tier 2 Watch Analyst

Sentar

United States

On-site

USD 95,000 - 125,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Employee ownership
401k match
PTO & holidays
Tuition reimbursement
Professional development

Job summary

Sentar seeks a Tier 2 Watch Analyst at Fort Bragg to join the 24/7 Blue Team. The role spans investigation and correlation across SIEM, EDR, and network telemetry, owning incidents to closure and coordinating containment actions as needed.

You will work rotating shifts on site, conduct initial data captures, preserve chain of custody, and support ongoing hunts and exercises while reporting findings to stakeholders.

Qualifications

  • DoD 814003 qualified for DCWF 511/531, intermediate level.
  • 5+ years in a DoD/enterprise SOC or similar role.
  • Familiarity with multi-source investigation and correlation.

Responsibilities

  • Stand watch 24/7 rotating shifts and perform Tier 1/2 duties.
  • Correlate anomalous activity across SIEM and telemetry sources.
  • Own incident records through closure with proper reporting.
  • Provide quality control and contribute to weekly/monthly reports.

Skills

DoD 814003
Elastic SIEM
Incident response
CJCSM 651001B
IR coordination

Education

Bachelor's degree
AA with experience

Tools

Elastic
EDR tools

Job description

Sentar is proud to be an employee owned company fostering a culture of empowerment collaboration and innovation Sentar is dedicated to developing the critical talent that the connected world demands to create solutions to address the convergence of cybersecurity intelligence analytics and systems engineering We invite you to join the team where you can build innovate and secure your career Sentar is seeking a Tier 2 Watch Analyst in Ft Bragg NC to serve as the investigation and correlation layer of the 247365 Blue Team watch Tier 2 analysts stand watch on the rotation own incident records from creation through closure perform multi source correlation recommend containment and eradication actions and quality control Tier 1 work before closure Role Description Watch Operations Stand assigned watch periods on the approved 247365 rotation performing Tier 1 and Tier 2 functions on console within qualification and SOP boundaries Execute pass down log entries verbal handoff briefings and critical incident re confirmation at every shift change Support hunts training and exercises only after watch coverage is protected Investigation and Correlation Correlate anomalous activity across SIEM Elastic Trellix ENS Tychon EDR full packet capture NetFlow IDSIPS proxy routerfirewall syslog and boundary device telemetry to characterize event scope Escalate suspected APT activity complex intrusions and uncertain containment to the Blue Team Lead Tier 3 without delay Incident Handling and Response Own incident records through closure including CJCSM 651001B category assignment timely reporting and currency of the ARCYBER incident handling portal Recommend containment and eradication actions in coordination with the affected mission owner and ISSO; execute approved critical blocks within the two hour standard Capture and perform initial analysis of volatile data logs and captured traffic; maintain chain of custody and coordinate evidence shipment to ARCYBER F&MA when required On Call Responsibilities Phone response within 30 mins of incident and on site reporting within one hour when required Quality Control and Reporting Perform quality control review of Tier 1 tickets prior to closure; conduct incident trend analysis Provide technical inputs to the Daily Blue Team Operations Report and weekly and monthly Blue Team reporting Work Environment Onsite presence at USARC Headquarters Fort Bragg NC required Rotating 8 hour shifts on a 247365 watch including nights weekends and Federal holidays Solo watch assignments during evening night weekend and holiday periods Qualifications Bachelors degree and 5 years of experience or AA with 7 years DoDM 814003 qualification for DCWF 511 Cyber Defense Analyst at Intermediate proficiency required for any solo watch assignment DoDM 814003 qualification for DCWF 531 Cyber Defense Incident Responder at Intermediate proficiency required for selected positions assigned incident response duties Favorably adjudicated Tier 3 investigation; Tier 5 required prior to any privileged access US Citizenship required Current DoD SECRET clearance required interim SECRET acceptable at start; final SECRET required within 120 days of award Ability to obtain and maintain a DoD Common Access Card and USARC installation access Completion of DoD Cyber Awareness training prior to system access and annually thereafter; AT Level I OPSEC Level I TARP and CUI training within 30 days of start SPECIFIC KNOWLEDGE SKILLS & ABILITIES Demonstrated experience in a DoD or enterprise SOC performing multi source investigation and correlation Hands on proficiency with an enterprise SIEM Elastic preferred and with host based security EDR PCAP NetFlow and IDSIPS analysis Working knowledge of MITRE ATT&CK CJCSM 651001B incident categories and DoD incident reporting timelines Familiarity with volatile data capture evidence preservation and chain of custody procedures Familiarity with Windows Linux and macOS operating systems and with Wireshark and scripting for repeatable triage Ability to work rotating shifts and to maintain accuracy and attention during extended monitoring periods Working knowledge of CJCSM 651001B incident categories and DoDArmy cyber incident reporting requirements Excellent interpersonal and written communication skills to interact effectively with Government stakeholders ARCYBER and Regional Cyber Center counterparts and team members The ability to communicate complex technical findings clearly to non technical audiences A willingness to uncover document and communicate deviations from planned outcomes in order to improve processes and prevent recurrence A passion for continuous learning and a commitment to stay current with emerging threats adversary tradecraft and defensive technologies Clearance Level Secret Education BABS with 5 years or AA with 7 years Certifications DoDM 814003 qualified as DCWF 511 Cyber Defense Analyst Intermediate 531 Incident Responder Intermediate for IR assigned seats

Benefits at Sentar

Our unique employee ownership model attracts top talent giving employees the freedom to take initiative and drive meaningful improvements In addition to cultivating a thriving and inclusive work environment Sentar offers an extensive benefits package designed to support the well being of employees and their families Employee ownership is the foundation of our culture promoting participation teamwork and accountability while ensuring long term financial security and a commitment to excellence

  • Voluntary Medical Dental Vision with Flexible Spending Plan options
  • Voluntary Life Critical Illness Accident and Long Term Care insurance options
  • Group Term Life Short Term and Long Term Disability is provided by Sentar to all qualifying employees
  • Generous 401k match
  • Competitive PTO plan that graduates quickly with years of service
  • Other leave programs; holiday schedule along with bereavement maternity jury and military duty
  • Tuition reimbursement
  • Professional development reimbursement
  • Recognition and Awards programs
EEO and Equal Opportunity Employer

Sentar is an Aff

Build Innovate Secure Your Career at Sentar

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Tier 2 Watch Analyst
SOC Tier 2 Watch Analyst

Sentar • Fort Bragg (NC)

On-site
USD 95,000 - 135,000
401(k) match
Generous PTO
Medical/Dental/Vision
Senior Integrated Assessment / Malware Analyst
Senior Integrated Assessment / Malware Analyst

Sentar • United States

On-site
USD 120,000 - 170,000
Voluntary MedicalDentalVision options
Generous 401k match
Competitive PTO
Blue Team Lead / Sr Cyber Defense Analyst
Blue Team Lead / Sr Cyber Defense Analyst

Sentar • Northern (KY)

On-site
USD 120,000 - 180,000
Voluntary Medical, Dental, Vision
Flexible Spending Plan options
Group Term Life, Disability
+3
Red Team Operator (Hybrid)
Red Team Operator (Hybrid)

Sentar • Quantico (VA)

On-site
USD 150,000 - 210,000
Voluntary Medical Dental Vision
401k match
Professional development reimbursement
+3
Cyber Threat Intelligence (CTI) Analyst
Cyber Threat Intelligence (CTI) Analyst

Sentar • Fort Bragg (NC)

On-site
USD 90,000 - 130,000
Employee ownership
401(k) match
Paid time off
+1
Senior Integrated Assessment / Malware Analyst
Senior Integrated Assessment / Malware Analyst

Sentar • Fort Bragg (NC)

On-site
USD 120,000 - 170,000
Medical/Dental/Vision coverage
Life insurance
Group 401(k) match
+1
Blue Team Lead / Sr Cyber Defense Analyst
Blue Team Lead / Sr Cyber Defense Analyst

Sentar Inc. • Fort Bragg (NC)

On-site
USD 120,000 - 160,000
Voluntary medical, dental, vision
401(k) match
Paid time off
+4
Blue Team Lead / Sr Cyber Defense Analyst
Blue Team Lead / Sr Cyber Defense Analyst

Sentar • Fort Bragg (NC)

On-site
USD 110,000 - 140,000
Medical/Dental/Vision
Life & Disability Insurance
Group Term Life
+3
Action Officer
Action Officer

Sentar Inc. • Charleston (AR)

On-site
USD 120,000 - 150,000
Voluntary Medical, Dental, Vision
Generous 401(k) match
Tuition reimbursement
+5
Battle Watch Captain
Battle Watch Captain

Sentar Inc. • Pearl City (HI)

On-site
USD 80,000 - 120,000
Voluntary Medical, Dental, Vision options
Generous 401(k) match
Tuition reimbursement
+1