Position Summary
Strategic Operational Solutions (STOPSO) is seeking a SOC Tier 2 Analyst to support the U.S. Army Reserve Command (USARC) Defensive Cyberspace Operations Mission Support Services (DCOMSS) program at Fort Bragg, North Carolina. Investigate escalated cyber events, correlate multiple telemetry sources, maintain incident records, and recommend response actions. The Tier 2 Analyst provides deeper analysis and quality review within the Blue Team.
Essential Duties and Responsibilities
• Investigate escalated alerts using SIEM, EDR, network flow, packet, firewall, authentication, proxy, and host data.
• Develop event timelines, identify affected systems and indicators, and assess scope and potential mission impact.
• Recommend containment and eradication steps to authorized Government personnel and track approved actions.
• Maintain incident records and required portal updates through closure, with evidence and rationale for decisions.
• Review Tier 1 tickets for completeness and coach analysts on investigation and documentation quality.
• Escalate complex intrusions and suspected advanced activity to Tier 3; support shifts and exercises as assigned.
• Perform other duties as assigned consistent with the position's responsibilities, qualifications, clearance, and authorized scope.
Required Qualifications
Education and Experience
• Minimum 3 years of documented relevant experience. Relevant cyber defense analysis and incident investigation experience, including SIEM, network traffic analysis, multi-source correlation, and incident documentation.
• DoD Cyber Workforce Framework (DCWF) 511, Cyber Defense Analyst, Intermediate proficiency.
• Meet DoDM 8140.03 qualification requirements for every assigned work role and proficiency through an approved education, training, certification, or authorized experience route before independent cyber work. Document work-role appointment and qualification; maintain required residential qualification and continuing learning. A higher-level approved option may qualify the same role at a lower level.
• Current matrix-listed certification options for 511 Intermediate: CEH(P), Cloud+, FITSP-O, GCED, GDSA, GMON, GRID, GSEC, PenTest+, Security+.
Knowledge, Skills and Abilities
• Demonstrated knowledge of Multi-source correlation, network traffic analysis, incident investigation, evidence preservation, and standardized response.
• Proficiency with SIEM, EDR, NetFlow, packet capture, IDS/IPS, and incident-management systems appropriate to assigned duties and approved access.
• Ability to produce accurate records, explain findings and decisions, and follow approved procedures and security requirements.
• Strong written and verbal communication skills and sound judgment when coordinating with technical staff and Government stakeholders.
• Strong organizational skills, confidentiality, and ability to work independently and collaboratively in a mission-focused environment.
Preferred Qualifications
• Experience investigating incidents in a DoD or enterprise security operations center.
• Relevant DoD or enterprise IT experience with mission tooling and operational reporting.
Security Clearance
Active SECRET clearance and ability to maintain assigned system access. U.S. citizenship is required.
Supervisory Responsibilities
No formal supervisory responsibilities; provides technical review and coaching to Tier 1 analysts.
Work Environment and Physical Requirements
Work is primarily performed on site in a secure Government facility using computer systems and standard office equipment. The employee must be able to perform sustained computer-based analysis or coordination, communicate effectively, and support operational activities outside standard business hours when assigned. Mission-essential watch roles may include shifts, weekends, and holidays.
Reasonable accommodations may be made to enable qualified individuals with disabilities to perform the essential functions of the position.
Travel
Occasional local, CONUS, or OCONUS travel may be required for authorized mission activities, exercises, assessments, or conferences.