The Security Operations Center (SOC) Analyst II serves as a mid-level cyber defender responsible for continuous monitoring, investigation, and response to security events across enterprise networks, endpoints, and cloud environments in a highly regulated government setting. This Tier 2 role handles alerts escalated from Tier 1, performing deeper analysis, driving containment and mitigation recommendations, and supporting coordinated remediation for mission-critical systems. The analyst helps operate and tune SOC technologies such as SIEM, EDR/XDR, IDS/IPS, and threat intelligence platforms while improving playbooks, use cases, and procedures to enhance detection fidelity and reduce false positives.
Key Responsibilities- Conduct in-depth analysis of security alerts escalated from Tier 1, correlating logs, network traffic, endpoint telemetry, and threat intelligence to determine incident scope, impact, and root cause.
- Operate and tune SIEM, EDR/XDR, IDS/IPS, and related SOC tooling to improve detection fidelity, reduce false positives, and enhance visibility across on-premises and cloud environments.
- Execute Tier 2 incident response activities, including containment and mitigation recommendations, coordination with infrastructure and application teams, and support for digital evidence collection and documentation.
- Review and apply emerging cyber threat intelligence, including indicators of compromise and adversary TTPs, to update rules, playbooks, and monitoring use cases aligned to frameworks such as MITRE ATT&CK.
- Maintain accurate and detailed case records in ticketing and case-management systems, supporting 24x7 operations with clear handoffs, status reporting, and after-action inputs.
- Support compliance-driven operations in a highly regulated government environment by following established SOPs, incident handling processes, and security control requirements for mission-critical systems.
- Collaborate with and mentor Tier 1 analysts by providing guidance on triage techniques, escalation criteria, and best practices for investigating suspicious activity.
Required Qualifications- Bachelor's Degree in Computer Science, Information Assurance, Cybersecurity, or a closely related field, or equivalent relevant experience (aligned to Operations Security Planner II standard).Standard-Job-Titles-SharePoint-2-11.xlsx
- Typically 3-5 years of prior experience in a SOC, cyber incident response, or closely related security operations role handling Tier 1/Tier 2 investigations.
- Demonstrated hands-on experience operating and tuning SIEM, endpoint security (EDR/XDR), IDS/IPS, and related SOC tools in enterprise environments.
- Strong analytical skills in log analysis, network traffic review, and endpoint telemetry, with the ability to determine incident scope, impact, and probable root cause.
- Familiarity with cyber threat intelligence concepts, indicators of compromise, and adversary TTPs, and experience applying these within monitoring and detection use cases.
- U.S. Citizenship required, with ability to satisfy background investigation requirements appropriate to a federal IT environment.
- Ability to work effectively as part of a 24x7 SOC operation, including clear written and verbal communication for case documentation and handoffs.
Preferred Qualifications- Experience with leading SIEM and endpoint security platforms such as Splunk, Microsoft Sentinel, Microsoft Defender, or similar tools.
- Industry certifications such as Security+, CySA+, GCIH, or equivalent SOC/incident response credentials.
- Prior experience supporting federal or other highly regulated environments requiring U.S. citizenship and eligibility for a clearance or public trust.
- Familiarity with frameworks such as MITRE ATT&CK and NIST 800-series as they relate to SOC use cases, detection engineering, and incident handling.
Compensation RangesCompensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.
DisclaimerThe preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.