Tier 2 Security Operations Center (SOC) Analyst

Leidos Holding$87K — $157K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, IT, Engineering, or related field with 5+ years of relevant cybersecurity experience.
  • Experience in cybersecurity event analysis and SOC operations.
  • Proficiency in analyzing alerts from various cybersecurity monitoring systems.
  • Ability to evaluate and investigate endpoint, network, and user activity for security events.
  • Experience with incident escalation and evidence preservation in cybersecurity contexts.
  • Familiarity with enterprise security-analysis tools and Tier 2 cybersecurity troubleshooting.
  • Active Secret security clearance and U.S. Citizenship are mandatory.

Responsibilities

  • Conduct advanced analysis of escalated cybersecurity events and enterprise monitoring alerts.
  • Correlate security alerts and technical data to assess impact of cybersecurity activities.
  • Identify legitimate activities versus suspicious behaviors and potential incidents.
  • Make decisions on subsequent actions based on SOC procedures and escalation criteria.
  • Initiate or recommend actions to mitigate identified threats as necessary.
  • Assist incident-response teams with triage, escalation, and containment activities.
  • Document investigations, analysis, and findings accurately in government systems.
  • Maintain records of events, tickets, and supporting evidence for further inquiry.

Benefits

  • Comprehensive health insurance options including medical, dental, and vision coverage.
  • 401(k) plan with company match to support retirement savings.
  • Generous paid time off (PTO) policy to encourage work-life balance.
  • Opportunities for professional development and training to enhance skills.
  • Flexible work schedule options to accommodate personal needs.
Full Job Description
The Tier 2 SOC Analyst will perform advanced analysis of cybersecurity events escalated from Tier 1 or identified through enterprise monitoring capabilities. This position will correlate security data, determine the scope and potential impact of suspicious activity, support incident triage and containment, preserve evidence, and coordinate with incident responders and other cybersecurity teams to protect DHRA systems and networks.

Work Locations:

  • Mark Center, Alexandria, Virginia - 3 positions


  • Department of Defense Center - Monterey Bay, Seaside, California - 3 positions


Clearance: Active Secret security clearance required at time of consideration. U.S. Citizen is a must.

Mission Environment

DMDC supports the Defense Human Resources Activity within the Office of the Under Secretary of Defense for Personnel and Readiness (OUSD(P&R)) and maintains the Department of Defense's largest and most comprehensive central repository of personnel, manpower, casualty, pay, entitlement, personnel security, identity, readiness, training, and related data. The DHRA Information Technology (IT) environment includes approximately 15,000 network and endpoint devices supporting more than 600 Government-Off-The-Shelf (GOTS) applications and approximately 100 Risk Management Framework (RMF) authorization boundaries managed through the Enterprise Mission Assurance Support Service (eMASS). The Tier 2 SOC Analysts operate within a 24x7 security operations environment responsible for detecting, analyzing, escalating, and supporting response to cybersecurity activity affecting DHRA systems and networks. Tier 2 analysts provide the deeper technical analysis required when events cannot be resolved through initial Tier 1 triage.

Primary Responsibilities:

  • Perform advanced analysis of cybersecurity events escalated from Tier 1 analysts or identified through endpoint, user-activity, network, and other enterprise monitoring capabilities.


  • Correlate alerts, security telemetry, and supporting technical data to determine the nature, scope, severity, and potential impact of cybersecurity activity.


  • Distinguish legitimate activity, false positives, policy violations, suspicious behavior, and potential cybersecurity incidents.


  • Determine appropriate next actions based on approved SOC procedures, playbooks, and escalation criteria.


  • Recommend or initiate authorized actions to contain or mitigate identified threats.


  • Support cybersecurity incident triage, escalation, and containment in coordination with the incident-response team.


  • Preserve relevant technical evidence and supporting information required for further investigation and incident response.


  • Document investigative actions, analysis, findings, and conclusions in Government-approved systems.


  • Maintain complete and accurate event records, tickets, timelines, and supporting evidence.


  • Contribute to required SOC event reporting and operational status information.


  • Perform Tier 2 troubleshooting of cybersecurity tools, alerts, security data, and related technical issues.


  • Use approved Commercial-Off-The-Shelf (COTS) security-analysis tools to investigate cybersecurity events.


  • Support security testing, mitigation activities, and cybersecurity compliance checking as required by SOC operations.


  • Coordinate analysis with incident responders, network engineers, endpoint-security personnel, cybersecurity-tool teams, system administrators, and other cybersecurity stakeholders.


  • Identify recurring false positives, detection gaps, or ineffective alerting and recommend improvements to monitoring and detection capabilities.


  • Support tuning of cybersecurity monitoring capabilities to improve detection accuracy and analyst effectiveness.


  • Contribute to SOC procedure, playbook, and process improvements based on operational experience and lessons learned.


  • Support knowledge transfer across SOC analysts to improve consistent analysis and response within the 24x7 operating environment.


Basic Qualifications:

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical discipline and 5 or more years of relevant cybersecurity experience. Specific experience, education and training may be considered in lieu of degree.


  • Experience performing cybersecurity event analysis, SOC operations, cyber defense, incident triage, or security monitoring.


  • Experience analyzing and correlating alerts from multiple cybersecurity monitoring capabilities.


  • Experience investigating endpoint, network, user-activity, or other cybersecurity events.


  • Experience determining the scope, severity, and potential impact of suspicious cybersecurity activity.


  • Experience supporting cybersecurity incident escalation, containment, mitigation, or evidence preservation.


  • Experience using enterprise security-analysis or cybersecurity monitoring tools.


  • Experience performing Tier 2 cybersecurity troubleshooting.


  • Working knowledge of cybersecurity attack techniques, network-security concepts, endpoint security, event analysis, and incident-response processes.


  • Ability to document investigations, findings, actions, and conclusions clearly and accurately.


  • Ability to work effectively within a team-based 24x7 security operations environment.


  • U.S. Citizenship required.


  • Active Secret security clearance required.


Preferred Qualifications:

  • Experience supporting a Department of Defense or Federal Security Operations Center.


  • Experience working in a 24x7 SOC or Cybersecurity Service Provider environment.


  • Experience with Security Information and Event Management (SIEM) platforms and enterprise cybersecurity monitoring tools.


  • Experience analyzing endpoint, network, identity, user-activity, intrusion-detection, or other cybersecurity telemetry.


  • Experience supporting cybersecurity incident response and digital-evidence preservation.


  • Experience tuning security alerts, detection logic, or monitoring capabilities to reduce false positives and improve detection quality.


  • Experience developing or refining SOC procedures, playbooks, or escalation criteria.


  • Experience with cybersecurity mitigation, compliance checking, or security testing.


  • Familiarity with Department of Defense cybersecurity requirements and Risk Management Framework processes.


  • Familiarity with DHRA, DMDC, or comparable Department of Defense enterprise environments.


Original Posting:
September 2, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:
Pay Range $87,100.00 - $157,450.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

About Leidos Holding

Leidos Holding Careers

Joining Leidos Holding presents an unparalleled opportunity to advance one's career with a leader in innovation and technology. The company offers a plethora of job opportunities aimed at fostering professional growth and development in a diverse and inclusive environment.

Explore Career Opportunities

Leidos Holding is actively seeking skilled professionals who are passionate about leveraging their expertise to drive innovation and leadership in their fields. With a variety of open positions, Leidos Holding provides a platform for individuals to challenge themselves in a dynamic work environment.

Innovation and Professional Growth

At Leidos Holding, innovation is at the core of everything they do. Employees are encouraged to think creatively and push boundaries. The company supports this drive for innovation through comprehensive professional development and diversity training programs that are designed to enhance skills and foster leadership.

Commitment to Diversity and Inclusion

Leidos Holding is committed to creating a workplace where diversity is not only recognized but celebrated. With a culture that values and promotes diversity, Leidos Holding ensures that all team members have the opportunity to contribute, learn, and grow.

Internship Programs

For those starting their career, Leidos Holding offers internship programs that provide a robust foundation in the industry. Internships are a great way to develop essential skills, gain valuable work experience, and build professional networks.

Benefits and Culture

Employees at Leidos Holding enjoy a range of benefits designed to support their professional and personal lives. The company culture is built on a foundation of respect and integrity, providing a supportive and collaborative environment where every team member is valued.

Join the Team

Leidos Holding is hiring! Explore job opportunities that match your skills and interests. Leidos Holding looks for driven, curious, and innovative individuals to join their team. Positions are available across various disciplines and experience levels.

Stay Connected

Stay informed with the latest career tips, industry insights, and company news from Leidos Holding. Subscribe to receive updates and be the first to know about new job opportunities, company developments, and more.

Prepare for Your Interview

To prepare for an interview at Leidos Holding, candidates should familiarize themselves with the company's missions and values, update their resumes, and be ready to discuss how their background and skills align with the position they are applying for.

Networking and Career Advancement

Leidos Holding encourages its employees to engage in networking within the company to discover new opportunities for career advancement. The leadership team at Leidos Holding is dedicated to supporting employees in their career paths with ample opportunities for networking and growth.

Explore Leidos Holding Jobs and Careers

Discover the exciting career opportunities at Leidos Holding today. With a commitment to employee growth, innovation, and diversity, Leidos Holding is the perfect place to advance your career. Check out the latest job listings and find your perfect fit at Leidos Holding.

SEARCH LEIDOS HOLDING JOBS

READ CAREERS BLOG

Job Alert Emails

Customize your subscription to receive job alerts and insider tips tailored to your preferences from Leidos Holding. See what exciting and rewarding opportunities await in your professional journey.
Learn more about Leidos Holding

Similar Jobs

More Jobs at Leidos Holding

More Information Technology Jobs

Find similar Tier 2 Security Operations Center (SOC) Analyst jobs: