SOC Tier Two Analyst

Strategic Operational Solutions, Inc

Fort Bragg (NC)

On-site

USD 85,000 - 125,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Strategic Operational Solutions, Inc. (STOPSO) is seeking a SOC Tier 2 Analyst to support the USARC DCOMSS program at Fort Bragg, NC. The role involves investigating escalated cyber events, correlating telemetry sources, maintaining incident records, and recommending response actions.

The ideal candidate has at least 3 years of cyber defense experience, DoD-specific certifications, and SECRET clearance. On-site work in a secure government facility is required, with occasional after-hours support

Qualifications

  • Minimum 3 years of documented relevant experience in cyber defense analysis and incident investigation.
  • DoD Cyber Workforce Framework 511 – Intermediate proficiency required.
  • Meet DoDM 8140.03 qualification requirements before independent cyber work.
  • Current 511 Intermediate certifications (CEH(P), Cloud+, FITSP-O, GCED, GDSA, GMON, GRID, GSEC, PenTest+, Security+).

Responsibilities

  • Investigate escalated alerts using SIEM, EDR, NetFlow, packet capture, and related data.
  • Develop event timelines, identify affected systems, and assess mission impact.
  • Recommend containment and eradication steps to Government personnel.
  • Maintain incident records and portal updates through closure with evidence and rationale.
  • Coach Tier 1 analysts and review investigations for quality.
  • Escalate complex intrusions to Tier 3 and support shifts and exercises.

Skills

SIEM proficiency
EDR proficiency
NetFlow analysis
Incident investigation
Multi-source correlation
Evidence preservation
Communication skills

Education

DCWF 511 Intermediate

Tools

SIEM
EDR
NetFlow
Packet capture
IDS/IPS
Incident-management systems

Job description

Position Summary

Strategic Operational Solutions (STOPSO) is seeking a SOC Tier 2 Analyst to support the U.S. Army Reserve Command (USARC) Defensive Cyberspace Operations Mission Support Services (DCOMSS) program at Fort Bragg, North Carolina. Investigate escalated cyber events, correlate multiple telemetry sources, maintain incident records, and recommend response actions. The Tier 2 Analyst provides deeper analysis and quality review within the Blue Team.

Essential Duties and Responsibilities
  • Investigate escalated alerts using SIEM, EDR, network flow, packet, firewall, authentication, proxy, and host data.
  • Develop event timelines, identify affected systems and indicators, and assess scope and potential mission impact.
  • Recommend containment and eradication steps to authorized Government personnel and track approved actions.
  • Maintain incident records and required portal updates through closure, with evidence and rationale for decisions.
  • Review Tier 1 tickets for completeness and coach analysts on investigation and documentation quality.
  • Escalate complex intrusions and suspected advanced activity to Tier 3; support shifts and exercises as assigned.
  • Perform other duties as assigned consistent with the position's responsibilities, qualifications, clearance, and authorized scope.
Required Qualifications
Education and Experience
  • Minimum 3 years of documented relevant experience. Relevant cyber defense analysis and incident investigation experience, including SIEM, network traffic analysis, multi-source correlation, and incident documentation.
  • DoD Cyber Workforce Framework (DCWF) 511, Cyber Defense Analyst, Intermediate proficiency.
  • Meet DoDM 8140.03 qualification requirements for every assigned work role and proficiency through an approved education, training, certification, or authorized experience route before independent cyber work. Document work-role appointment and qualification; maintain required residential qualification and continuing learning. A higher-level approved option may qualify the same role at a lower level.
  • Current matrix-listed certification options for 511 Intermediate: CEH(P), Cloud+, FITSP-O, GCED, GDSA, GMON, GRID, GSEC, PenTest+, Security+.
Knowledge, Skills and Abilities
  • Demonstrated knowledge of Multi-source correlation, network traffic analysis, incident investigation, evidence preservation, and standardized response.
  • Proficiency with SIEM, EDR, NetFlow, packet capture, IDS/IPS, and incident-management systems appropriate to assigned duties and approved access.
  • Ability to produce accurate records, explain findings and decisions, and follow approved procedures and security requirements.
  • Strong written and verbal communication skills and sound judgment when coordinating with technical staff and Government stakeholders.
  • Strong organizational skills, confidentiality, and ability to work independently and collaboratively in a mission-focused environment.
Preferred Qualifications
  • Experience investigating incidents in a DoD or enterprise security operations center.
  • Relevant DoD or enterprise IT experience with mission tooling and operational reporting.
Security Clearance

Active SECRET clearance and ability to maintain assigned system access. U.S. citizenship is required.

Supervisory Responsibilities

No formal supervisory responsibilities; provides technical review and coaching to Tier 1 analysts.

Work Environment and Physical Requirements

Work is primarily performed on site in a secure Government facility using computer systems and standard office equipment. The employee must be able to perform sustained computer-based analysis or coordination, communicate effectively, and support operational activities outside standard business hours when assigned. Mission-essential watch roles may include shifts, weekends, and holidays.

Reasonable accommodations may be made to enable qualified individuals with disabilities to perform the essential functions of the position.

Travel

Occasional local, CONUS, or OCONUS travel may be required for authorized mission activities, exercises, assessments, or conferences.

Equal Employment Opportunity

STOPSO is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, veteran status, genetic information, or any other characteristic protected by applicable federal, state, or local law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Tier 3 and Incident Response Lead
SOC Tier 3 and Incident Response Lead

Strategic Operational Solutions, Inc • Fort Bragg (NC)

On-site
USD 120,000 - 170,000
SOC Tier II Analyst — Advanced Incident Response
SOC Tier II Analyst — Advanced Incident Response

Strategic Operational Solutions, Inc • Fort Bragg (NC)

On-site
USD 85,000 - 125,000
Blue Team Lead and Senior Cyber Defense Analyst
Blue Team Lead and Senior Cyber Defense Analyst

Strategic Operational Solutions, Inc • Fort Bragg (NC)

On-site
USD 110,000 - 160,000
Vulnerability Assessment Analyst
Vulnerability Assessment Analyst

Strategic Operational Solutions, Inc • Fort Bragg (NC)

On-site
USD 85,000 - 120,000
Threat Hunter
Threat Hunter

Strategic Operational Solutions, Inc • Fort Bragg (CA)

On-site
USD 120,000 - 165,000
Threat Hunter
Threat Hunter

Strategic Operational Solutions, Inc • Fort Bragg (NC)

On-site
USD 110,000 - 140,000
SOC Analyst - Tier 1
SOC Analyst - Tier 1

Evans & Chambers • Maryland

On-site
USD 88,000 - 118,000
Tool Administrator and Lab Manager
Tool Administrator and Lab Manager

Strategic Operational Solutions, Inc • Fort Bragg (NC)

On-site
USD 85,000 - 125,000
SOC Analyst, Tier I
SOC Analyst, Tier I

Indigo IT LLC • Fort Bragg (NC)

On-site
USD 70,000 - 95,000
Medical, Dental, Vision
401(k) with company match
Paid Time Off
+2
Tool Administrator and Lab Manager
Tool Administrator and Lab Manager

Strategic Operational Solutions, Inc • Fort Bragg (CA)

On-site
USD 90,000 - 120,000