Tier 2 Security Operations Center (SOC) Analyst

Via Logic LLC

Alexandria (VA)

On-site

USD 87,000 - 157,000

Full time

6 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Leidos is seeking an experienced Tier 2 Security Operations Center (SOC) Analyst to support the DMDC CyberPRIMES program. The role operates in a 24x7 security environment, performing advanced event analysis, correlation, and escalation for DHRA/DMDC systems.

Locations include Mark Center, Alexandria, VA, and Monterey Bay, CA. Active Secret clearance and U.S. citizenship are required; a bachelor’s degree plus 5+ years in cybersecurity is expected.

Qualifications

  • Bachelor’s degree plus 5+ years of cybersecurity experience; degree may be substituted with equivalent experience.
  • Experience performing cybersecurity event analysis and SOC operations.
  • Experience analyzing and correlating alerts from multiple monitoring capabilities.
  • Experience investigating endpoint, network, and user-activity events.
  • Ability to document investigations clearly and work in a 24x7 SOC environment.

Responsibilities

  • Perform advanced analysis of cybersecurity events escalated from Tier 1.
  • Correlate alerts and telemetry to determine nature, scope and impact.
  • Distinguish legitimate activity from false positives and incidents.
  • Determine next actions per SOC procedures and escalation criteria.
  • Support incident triage, containment, and evidence preservation.
  • Document actions, findings, and conclusions in government-approved systems.
  • Maintain complete event records and supporting evidence.
  • Coordinate with incident responders, network engineers, and admins.
  • Contribute to SOC playbooks and improvement initiatives.

Skills

Cybersecurity event analysis
SOC operations
Incident triage
Security monitoring
Team collaboration
Endpoint security

Education

Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related

Tools

SIEM platforms
Enterprise security-monitoring tools

Job description

Leidos is seeking an experienced Tier 2 Security Operations Center (SOC) Analyst to support the Defense Manpower Data Center (DMDC) CyberPRIMES program. Leidos is a major partner on the contract and will provide a substantial portion of the cybersecurity workforce supporting the Defense Human Resources Activity (DHRA) and DMDC.

Work Locations
  • Mark Center, Alexandria, Virginia - 3 positions
  • Department of Defense Center - Monterey Bay, Seaside, California - 3 positions
Clearance

Active Secret security clearance required at time of consideration. U.S. Citizen is a must.

Mission Environment

DMDC supports the Defense Human Resources Activity within the Office of the Under Secretary of Defense for Personnel and Readiness (OUSD(P&R)) and maintains the Department of Defense’s largest and most comprehensive central repository of personnel, manpower, casualty, pay, entitlement, personnel security, identity, readiness, training, and related data. The DHRA Information Technology (IT) environment includes approximately 15,000 network and endpoint devices supporting more than 600 Government-Off-The-Shelf (GOTS) applications and approximately 100 Risk Management Framework (RMF) authorization boundaries managed through the Enterprise Mission Assurance Support Service (eMASS). The Tier 2 SOC Analysts operate within a 24x7 security operations environment responsible for detecting, analyzing, escalating, and supporting response to cybersecurity activity affecting DHRA systems and networks. Tier 2 analysts provide the deeper technical analysis required when events cannot be resolved through initial Tier 1 triage.

Primary Responsibilities
  • Perform advanced analysis of cybersecurity events escalated from Tier 1 analysts or identified through endpoint, user-activity, network, and other enterprise monitoring capabilities.
  • Correlate alerts, security telemetry, and supporting technical data to determine the nature, scope, severity, and potential impact of cybersecurity activity.
  • Distinguish legitimate activity, false positives, policy violations, suspicious behavior, and potential cybersecurity incidents.
  • Determine appropriate next actions based on approved SOC procedures, playbooks, and escalation criteria.
  • Recommend or initiate authorized actions to contain or mitigate identified threats.
  • Support cybersecurity incident triage, escalation, and containment in coordination with the incident-response team.
  • Preserve relevant technical evidence and supporting information required for further investigation and incident response.
  • Document investigative actions, analysis, findings, and conclusions in Government-approved systems.
  • Maintain complete and accurate event records, tickets, timelines, and supporting evidence.
  • Contribute to required SOC event reporting and operational status information.
  • Perform Tier 2 troubleshooting of cybersecurity tools, alerts, security data, and related technical issues.
  • Use approved Commercial-Off-The-Shelf (COTS) security-analysis tools to investigate cybersecurity events.
  • Support security testing, mitigation activities, and cybersecurity compliance checking as required by SOC operations.
  • Coordinate analysis with incident responders, network engineers, endpoint-security personnel, cybersecurity-tool teams, system administrators, and other cybersecurity stakeholders.
  • Identify recurring false positives, detection gaps, or ineffective alerting and recommend improvements to monitoring and detection capabilities.
  • Support tuning of cybersecurity monitoring capabilities to improve detection accuracy and analyst effectiveness.
  • Contribute to SOC procedure, playbook, and process improvements based on operational experience and lessons learned.
  • Support knowledge transfer across SOC analysts to improve consistent analysis and response within the 24x7 operating environment.
Basic Qualifications
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical discipline and 5 or more years of relevant cybersecurity experience. Specific experience, education and training may be considered in lieu of degree.
  • Experience performing cybersecurity event analysis, SOC operations, cyber defense, incident triage, or security monitoring.
  • Experience analyzing and correlating alerts from multiple cybersecurity monitoring capabilities.
  • Experience investigating endpoint, network, user-activity, or other cybersecurity events.
  • Experience determining the scope, severity, and potential impact of suspicious cybersecurity activity.
  • Experience supporting cybersecurity incident escalation, containment, mitigation, or evidence preservation.
  • Experience using enterprise security-analysis or cybersecurity monitoring tools.
  • Experience performing Tier 2 cybersecurity troubleshooting.
  • Working knowledge of cybersecurity attack techniques, network-security concepts, endpoint security, event analysis, and incident-response processes.
  • Ability to document investigations, findings, actions, and conclusions clearly and accurately.
  • Ability to work effectively within a team-based 24x7 security operations environment.
  • U.S. Citizenship required.
  • Active Secret security clearance required.
Preferred Qualifications
  • Experience supporting a Department of Defense or Federal Security Operations Center.
  • Experience working in a 24x7 SOC or Cybersecurity Service Provider environment.
  • Experience with Security Information and Event Management (SIEM) platforms and enterprise cybersecurity monitoring tools.
  • Experience analyzing endpoint, network, identity, user-activity, intrusion-detection, or other cybersecurity telemetry.
  • Experience supporting cybersecurity incident response and digital-evidence preservation.
  • Experience tuning security alerts, detection logic, or monitoring capabilities to reduce false positives and improve detection quality.
  • Experience developing or refining SOC procedures, playbooks, or escalation criteria.
  • Experience with cybersecurity mitigation, compliance checking, or security testing.
  • Familiarity with Department of Defense cybersecurity requirements and Risk Management Framework processes.
  • Familiarity with DHRA, DMDC, or comparable Department of Defense enterprise environments.

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.

Pay Range

Pay Range $87,100.00 - $157,450.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.

Pay and Benefits

Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers.

  • Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement.

More details are available at www.leidos.com/careers/pay-benefits.

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

#Remote

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Tier 2 Security Operations Center (SOC) Analyst
Tier 2 Security Operations Center (SOC) Analyst

Via Logic LLC • Seaside (CA)

On-site
USD 87,000 - 157,000
Health and Wellness programs
Paid Leave
Retirement plan
Tier 2 Security Operations Center (SOC) Analyst
Tier 2 Security Operations Center (SOC) Analyst

Koitecc Solutions • Alexandria (VA)

On-site
USD 87,000 - 157,000
Tier 2 Security Operations Center (SOC) Analyst
Tier 2 Security Operations Center (SOC) Analyst

Koitecc Solutions • Seaside (CA)

On-site
USD 87,000 - 157,000
Tier 2 Security Operations Center (SOC) Analyst
Tier 2 Security Operations Center (SOC) Analyst

Leidos • Seaside (OR)

On-site
USD 87,000 - 157,000
Tier 2 Security Operations Center (SOC) Analyst
Tier 2 Security Operations Center (SOC) Analyst

Leidos Inc • Alexandria (VA)

On-site
USD 87,000 - 157,000
Tier 2 Security Operations Center (SOC) Analyst
Tier 2 Security Operations Center (SOC) Analyst

Leidos Inc • Seaside (CA)

On-site
USD 87,000 - 157,000
DMDC SOC Manager - Deputy Program Manager
DMDC SOC Manager - Deputy Program Manager

Via Logic LLC • Alexandria (VA)

On-site
USD 131,000 - 237,000
Health and Wellness programs
Paid Leave and Retirement
DMDC SOC Manager - Deputy Program Manager
DMDC SOC Manager - Deputy Program Manager

Via Logic LLC • Seaside (CA)

On-site
USD 131,000 - 237,000
Incident Response Analyst
Incident Response Analyst

Koitecc Solutions • Seaside (CA)

On-site
USD 87,000 - 157,000
Incident Response Analyst
Incident Response Analyst

Via Logic LLC • Seaside (CA)

On-site
USD 87,000 - 157,000