Tier 2 Security Operations Center (SOC) Analyst

Jobtailor

California (MO)

On-site

USD 95,000 - 125,000

Full time

7 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Jobtailor seeks an experienced cybersecurity analyst to perform advanced analysis of security events escalated from Tier 1 or identified through enterprise monitoring. You will correlate alerts, determine nature and impact, and distinguish true incidents from false positives while following SOC procedures.

You will support incident triage, containment, and evidence preservation, documenting actions and findings in government-approved systems.

Qualifications

  • Bachelor's degree or higher in a technical field and 5+ years of relevant cybersecurity experience
  • Experience performing cybersecurity event analysis, SOC operations, cyber defense, incident triage, or security monitoring
  • Experience analyzing and correlating alerts from multiple cybersecurity monitoring capabilities
  • Experience investigating endpoint, network, user-activity, or other cybersecurity events
  • Experience determining the scope, severity, and potential impact of suspicious cybersecurity activity
  • Experience supporting cybersecurity incident escalation, containment, mitigation, or evidence preservation
  • Experience using enterprise security-analysis or cybersecurity monitoring tools
  • Experience performing Tier 2 cybersecurity troubleshooting
  • Working knowledge of cybersecurity attack techniques, network-security concepts, endpoint security, event analysis, and incident-response processes
  • Ability to document investigations, findings, actions, and conclusions clearly and accurately
  • Ability to work effectively within a team-based 24x7 security operations environment
  • U.S. Citizenship required
  • Active Secret security clearance required at time of consideration

Responsibilities

  • Perform advanced analysis of cybersecurity events escalated from Tier 1 or identified through monitoring
  • Correlate alerts and data to determine nature, scope, severity, and potential impact
  • Distinguish legitimate activity, false positives, and potential incidents
  • Determine actions based on SOC procedures and escalation criteria
  • Recommend or initiate authorized actions to contain or mitigate threats
  • Support incident triage, escalation, and containment with incident-response team
  • Preserve evidence and required information for investigation
  • Document actions, findings, and conclusions in government-approved systems
  • Maintain accurate event records, tickets, and timelines
  • Contribute to SOC event reporting and operational status
  • Perform Tier 2 troubleshooting of cybersecurity tools and data
  • Use approved tools to investigate events
  • Support testing, mitigation, and compliance activities
  • Coordinate analyses with cybersecurity stakeholders
  • Identify false positives, detection gaps, or ineffective alerting and recommend improvements
  • Support tuning of monitoring capabilities for detection accuracy
  • Contribute to SOC process improvements and knowledge transfer

Skills

Cybersecurity Event Analysis
Incident Triage
Security Monitoring
Alert Correlation
Evidence Preservation
Cyber Defense
Network Security Concepts
Endpoint Security
Event Analysis
Incident-Response Processes

Education

Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering

Tools

COTS Security-Analysis Tools
Cybersecurity Monitoring Tools

Job description

  • Perform advanced analysis of cybersecurity events escalated from Tier 1 analysts or identified through enterprise monitoring capabilities
  • Correlate alerts, security telemetry, and supporting technical data to determine the nature, scope, severity, and potential impact of cybersecurity activity
  • Distinguish legitimate activity, false positives, policy violations, suspicious behavior, and potential cybersecurity incidents
  • Determine appropriate next actions based on approved SOC procedures, playbooks, and escalation criteria
  • Recommend or initiate authorized actions to contain or mitigate identified threats
  • Support cybersecurity incident triage, escalation, and containment in coordination with the incident-response team
  • Preserve relevant technical evidence and supporting information required for further investigation and incident response
  • Document investigative actions, analysis, findings, and conclusions in Government-approved systems
  • Maintain complete and accurate event records, tickets, timelines, and supporting evidence
  • Contribute to required SOC event reporting and operational status information
  • Perform Tier 2 troubleshooting of cybersecurity tools, alerts, security data, and related technical issues
  • Use approved COTS security-analysis tools to investigate cybersecurity events
  • Support security testing, mitigation activities, and cybersecurity compliance checking as required by SOC operations
  • Coordinate analysis with incident responders, network engineers, endpoint-security personnel, cybersecurity-tool teams, system administrators, and other cybersecurity stakeholders
  • Identify recurring false positives, detection gaps, or ineffective alerting and recommend improvements to monitoring and detection capabilities
  • Support tuning of cybersecurity monitoring capabilities to improve detection accuracy and analyst effectiveness
  • Contribute to SOC procedure, playbook, and process improvements based on operational experience and lessons learned
  • Support knowledge transfer across SOC analysts within the 24x7 operating environment
Requirements
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical discipline and 5 or more years of relevant cybersecurity experience
  • Specific experience, education and training may be considered in lieu of degree
  • Experience performing cybersecurity event analysis, SOC operations, cyber defense, incident triage, or security monitoring
  • Experience analyzing and correlating alerts from multiple cybersecurity monitoring capabilities
  • Experience investigating endpoint, network, user-activity, or other cybersecurity events
  • Experience determining the scope, severity, and potential impact of suspicious cybersecurity activity
  • Experience supporting cybersecurity incident escalation, containment, mitigation, or evidence preservation
  • Experience using enterprise security-analysis or cybersecurity monitoring tools
  • Experience performing Tier 2 cybersecurity troubleshooting
  • Working knowledge of cybersecurity attack techniques, network-security concepts, endpoint security, event analysis, and incident-response processes
  • Ability to document investigations, findings, actions, and conclusions clearly and accurately
  • Ability to work effectively within a team-based 24x7 security operations environment
  • U.S. Citizenship required
  • Active Secret security clearance required at time of consideration
Core Competencies

Demonstrates expertise in cybersecurity event analysis, incident response, and SOC operations, with a strong ability to document findings and collaborate effectively in a 24x7 environment. Proficient in using security-analysis tools and understanding cybersecurity attack techniques and network-security concepts.

Highest-signal resume keywords
  • Cybersecurity Event Analysis
  • Incident Response Coordination
  • SOC Operations Experience
  • Security-Analysis Tools Proficiency
  • Tier 2 Cybersecurity Troubleshooting
ATS Optimization Keywords
Hard Skills
  • Cybersecurity Event Analysis
  • Incident Triage
  • Security Monitoring
  • Alert Correlation
  • Evidence Preservation
  • Cyber Defense
  • Network Security Concepts
  • Endpoint Security
  • Event Analysis
  • Incident-Response Processes
Soft Skills
  • Team Collaboration
  • Clear Documentation
Certifications & Qualifications
  • Active Secret Security Clearance
Industry Keywords
  • Cybersecurity
  • SOC Procedures
  • Operational Status Reporting
  • False Positive Identification
  • Detection Gaps
Tools & Technologies
  • COTS Security-Analysis Tools
  • Cybersecurity Monitoring Tools
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Technology Security Analyst
Senior Information Technology Security Analyst

Jobtailor • Philadelphia

On-site
USD 110,000 - 160,000
Security Operations Center Technical Lead
Security Operations Center Technical Lead

Invictus International Consulting, LLC. • Colorado Springs (CO)

On-site
USD 120,000 - 170,000
Security Operations Center Technical Lead
Security Operations Center Technical Lead

Invictus International • Colorado Springs (CO)

On-site
USD 130,000 - 180,000
Security Operations Lead
Security Operations Lead

Jobtailor • Pennsylvania

On-site
USD 120,000 - 160,000
Cybersecurity Analyst II
Cybersecurity Analyst II

Jobtailor • Reading

On-site
USD 90,000 - 120,000
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

10xTalents • Washington

On-site
USD 80,000 - 110,000
Cybersecurity Manager I
Cybersecurity Manager I

Jobtailor • Colorado

On-site
USD 150,000 - 210,000
SOC Analyst
SOC Analyst

KeenLogic • Fairfax (CA)

On-site
USD 100,000 - 130,000
Health benefits
PTO
401(k)
+1
Cybersecurity Watch Operations Subject Matter Expert IV
Cybersecurity Watch Operations Subject Matter Expert IV

Invictus International Consulting, LLC. • Colorado Springs (CO)

On-site
USD 150,000 - 190,000
Cybersecurity Watch Operations Subject Matter Expert IV
Cybersecurity Watch Operations Subject Matter Expert IV

Invictus International Consulting, LLC. • Alexandria (VA)

On-site
USD 150,000 - 190,000