- Perform advanced analysis of cybersecurity events escalated from Tier 1 analysts or identified through enterprise monitoring capabilities
- Correlate alerts, security telemetry, and supporting technical data to determine the nature, scope, severity, and potential impact of cybersecurity activity
- Distinguish legitimate activity, false positives, policy violations, suspicious behavior, and potential cybersecurity incidents
- Determine appropriate next actions based on approved SOC procedures, playbooks, and escalation criteria
- Recommend or initiate authorized actions to contain or mitigate identified threats
- Support cybersecurity incident triage, escalation, and containment in coordination with the incident-response team
- Preserve relevant technical evidence and supporting information required for further investigation and incident response
- Document investigative actions, analysis, findings, and conclusions in Government-approved systems
- Maintain complete and accurate event records, tickets, timelines, and supporting evidence
- Contribute to required SOC event reporting and operational status information
- Perform Tier 2 troubleshooting of cybersecurity tools, alerts, security data, and related technical issues
- Use approved COTS security-analysis tools to investigate cybersecurity events
- Support security testing, mitigation activities, and cybersecurity compliance checking as required by SOC operations
- Coordinate analysis with incident responders, network engineers, endpoint-security personnel, cybersecurity-tool teams, system administrators, and other cybersecurity stakeholders
- Identify recurring false positives, detection gaps, or ineffective alerting and recommend improvements to monitoring and detection capabilities
- Support tuning of cybersecurity monitoring capabilities to improve detection accuracy and analyst effectiveness
- Contribute to SOC procedure, playbook, and process improvements based on operational experience and lessons learned
- Support knowledge transfer across SOC analysts within the 24x7 operating environment
Requirements
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical discipline and 5 or more years of relevant cybersecurity experience
- Specific experience, education and training may be considered in lieu of degree
- Experience performing cybersecurity event analysis, SOC operations, cyber defense, incident triage, or security monitoring
- Experience analyzing and correlating alerts from multiple cybersecurity monitoring capabilities
- Experience investigating endpoint, network, user-activity, or other cybersecurity events
- Experience determining the scope, severity, and potential impact of suspicious cybersecurity activity
- Experience supporting cybersecurity incident escalation, containment, mitigation, or evidence preservation
- Experience using enterprise security-analysis or cybersecurity monitoring tools
- Experience performing Tier 2 cybersecurity troubleshooting
- Working knowledge of cybersecurity attack techniques, network-security concepts, endpoint security, event analysis, and incident-response processes
- Ability to document investigations, findings, actions, and conclusions clearly and accurately
- Ability to work effectively within a team-based 24x7 security operations environment
- U.S. Citizenship required
- Active Secret security clearance required at time of consideration
Core Competencies
Demonstrates expertise in cybersecurity event analysis, incident response, and SOC operations, with a strong ability to document findings and collaborate effectively in a 24x7 environment. Proficient in using security-analysis tools and understanding cybersecurity attack techniques and network-security concepts.
Highest-signal resume keywords
- Cybersecurity Event Analysis
- Incident Response Coordination
- SOC Operations Experience
- Security-Analysis Tools Proficiency
- Tier 2 Cybersecurity Troubleshooting
ATS Optimization Keywords
Hard Skills
- Cybersecurity Event Analysis
- Incident Triage
- Security Monitoring
- Alert Correlation
- Evidence Preservation
- Cyber Defense
- Network Security Concepts
- Endpoint Security
- Event Analysis
- Incident-Response Processes
Soft Skills
- Team Collaboration
- Clear Documentation
Certifications & Qualifications
- Active Secret Security Clearance
Industry Keywords
- Cybersecurity
- SOC Procedures
- Operational Status Reporting
- False Positive Identification
- Detection Gaps
Tools & Technologies
- COTS Security-Analysis Tools
- Cybersecurity Monitoring Tools