Security Operations Center (SOC) Analyst II

ASM Research$75K — $95K *
US-AnywhereRemote in United States
Education, Government & Non-Profit
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in Computer Science, Cybersecurity, or related field or equivalent experience.
  • 3-5 years in SOC or cyber incident response, focusing on Tier 1/Tier 2 investigations.
  • Hands-on experience with SIEM, EDR/XDR, IDS/IPS, and SOC tools in enterprise environments.
  • Strong log analysis and network traffic review skills to evaluate incidents effectively.
  • Understanding of cyber threat intelligence and related concepts for enhancing detection.
  • U.S. Citizenship required; must pass background checks for federal environments.
  • Effective communication skills for 24x7 SOC operations.

Responsibilities

  • Analyze escalated security alerts to determine incident scope and root cause.
  • Tune SOC tools like SIEM and EDR/XDR to enhance detection capabilities.
  • Execute Tier 2 incident responses and coordinate with teams for remediation.
  • Integrate cyber threat intelligence into monitoring use cases and rules.
  • Maintain detailed records in ticketing systems for operational clarity.
  • Follow SOPs and incident handling processes in a regulated government setting.
  • Mentor Tier 1 analysts on investigation techniques and best practices.

Benefits

  • Comprehensive benefits package including health and wellness programs.
  • Continuous professional development opportunities.
  • Supportive work environment fostering collaboration and mentorship.
  • Work schedule flexibility catering to 24x7 operations.
  • Possibility of contributing to mission-critical government projects.
Full Job Description
The Security Operations Center (SOC) Analyst II serves as a mid-level cyber defender responsible for continuous monitoring, investigation, and response to security events across enterprise networks, endpoints, and cloud environments in a highly regulated government setting. This Tier 2 role handles alerts escalated from Tier 1, performing deeper analysis, driving containment and mitigation recommendations, and supporting coordinated remediation for mission-critical systems. The analyst helps operate and tune SOC technologies such as SIEM, EDR/XDR, IDS/IPS, and threat intelligence platforms while improving playbooks, use cases, and procedures to enhance detection fidelity and reduce false positives.

Key Responsibilities
  • Conduct in-depth analysis of security alerts escalated from Tier 1, correlating logs, network traffic, endpoint telemetry, and threat intelligence to determine incident scope, impact, and root cause.
  • Operate and tune SIEM, EDR/XDR, IDS/IPS, and related SOC tooling to improve detection fidelity, reduce false positives, and enhance visibility across on-premises and cloud environments.
  • Execute Tier 2 incident response activities, including containment and mitigation recommendations, coordination with infrastructure and application teams, and support for digital evidence collection and documentation.
  • Review and apply emerging cyber threat intelligence, including indicators of compromise and adversary TTPs, to update rules, playbooks, and monitoring use cases aligned to frameworks such as MITRE ATT&CK.
  • Maintain accurate and detailed case records in ticketing and case-management systems, supporting 24x7 operations with clear handoffs, status reporting, and after-action inputs.
  • Support compliance-driven operations in a highly regulated government environment by following established SOPs, incident handling processes, and security control requirements for mission-critical systems.
  • Collaborate with and mentor Tier 1 analysts by providing guidance on triage techniques, escalation criteria, and best practices for investigating suspicious activity.

Required Qualifications
  • Bachelor's Degree in Computer Science, Information Assurance, Cybersecurity, or a closely related field, or equivalent relevant experience (aligned to Operations Security Planner II standard).Standard-Job-Titles-SharePoint-2-11.xlsx
  • Typically 3-5 years of prior experience in a SOC, cyber incident response, or closely related security operations role handling Tier 1/Tier 2 investigations.
  • Demonstrated hands-on experience operating and tuning SIEM, endpoint security (EDR/XDR), IDS/IPS, and related SOC tools in enterprise environments.
  • Strong analytical skills in log analysis, network traffic review, and endpoint telemetry, with the ability to determine incident scope, impact, and probable root cause.
  • Familiarity with cyber threat intelligence concepts, indicators of compromise, and adversary TTPs, and experience applying these within monitoring and detection use cases.
  • U.S. Citizenship required, with ability to satisfy background investigation requirements appropriate to a federal IT environment.
  • Ability to work effectively as part of a 24x7 SOC operation, including clear written and verbal communication for case documentation and handoffs.

Preferred Qualifications
  • Experience with leading SIEM and endpoint security platforms such as Splunk, Microsoft Sentinel, Microsoft Defender, or similar tools.
  • Industry certifications such as Security+, CySA+, GCIH, or equivalent SOC/incident response credentials.
  • Prior experience supporting federal or other highly regulated environments requiring U.S. citizenship and eligibility for a clearance or public trust.
  • Familiarity with frameworks such as MITRE ATT&CK and NIST 800-series as they relate to SOC use cases, detection engineering, and incident handling.


Compensation Ranges

Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.

Disclaimer

The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.

Similar Jobs

More Jobs at ASM Research

More Education, Government & Non-Profit Jobs

Find similar Security Operations Center (SOC) Analyst II jobs: