SOC Analyst II

Job not on LinkedIn

🔥 3 minutes ago

🇺🇸 United States – Remote

💵 $70k - $80k / year

⏰ Full Time

🟢 Junior

🟡 Mid-level

🛡️ Security Operations

🚫👨‍🎓 No degree required

👻 Ghost score 2%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Sentinel Blue

Sentinel Blue

11 - 50 employees

💼 Consulting

🎖️ Defense

📦 Logistics

Consulting • Defense • Logistics

Sentinel Blue is a cybersecurity services firm based in Warrenton, VA, offering comprehensive cybersecurity solutions tailored to small and medium-sized businesses. The company specializes in fully managed cybersecurity services, compliance advisory, and Gov Cloud solutions, ensuring organizations are protected and compliant with industry standards. Utilizing best-in-class technologies like Microsoft Sentinel, Azure Government, and Zero Trust frameworks, Sentinel Blue provides services such as virtual CISO and CIO roles, security operations centers, and extended detection and response. The company is committed to enhancing its clients' cybersecurity maturity and regulatory compliance, particularly focusing on CMMC and risk assessments. Sentinel Blue prides itself on its core values of emerging technology leadership, excellence, and a client-centric approach.

📋 Description

• Serve as the primary escalation point for Tier I analysts • Take ownership of critical/high-severity alerts and escalated security incidents • Analyze endpoints, network traffic, and log data to validate incidents and perform root cause analysis • Lead containment, eradication, and recovery during active security incidents • Follow and document Standard Operating Procedures and Incident Response Plans • Reconstruct attack chains using the MITRE ATT&CK Framework and Cyber Kill Chain • Conduct intelligence- and hypothesis-driven threat hunts • Write executive reports with clear narratives, detailed analysis, and actionable recommendations • Manage the vulnerability management lifecycle, including scan analysis, risk-based prioritization, and remediation coordination • Develop and maintain incident response playbooks and SOPs • Provide technical guidance, training, and feedback to Tier 1 analysts • Participate in an on-call rotation for critical incidents outside standard business hours • Collaborate with and mentor junior staff • Help advance capabilities in digital forensics and incident response, threat hunting, vulnerability management, and threat intelligence

🎯 Requirements

• U.S. citizenship • Must be eligible for a Secret clearance • Minimum of 2–5 years of experience in a Security Operations Center and/or cyber-adjacent or IT administration roles • Intermediate to advanced understanding of Windows OS internals, including Event Tracing for Windows, Win32 API, Registry, Memory, and Process operations • Intermediate to advanced understanding of TCP/IP, DNS, HTTP, SSL/TLS, and other common network protocols • Intermediate to advanced ability to write and interpret Python or PowerShell scripts • Ability to manage Windows devices via command line using PowerShell or Batch • Ability to detect and reverse engineer malicious scripts or other high-level languages • Understanding of code injection and attack/evasion techniques related to Windows • Prior experience with SIEM platforms such as Microsoft Sentinel, ELK/Elastic Stack, or Splunk • Hands-on experience with Sysinternals Suite, Volatility, SIFT Workstation, CyberChef, Forensic Browser for SQLite, Velociraptor, Explorer Suite, Wireshark, and malware analysis sandboxes, or equivalent tools • Familiarity with malware development, social engineering, phishing, exploitation, persistence, evasion, credential theft, C2, exfiltration, and lateral movement • Intermediate to advanced certification such as GCIH/GCIA/GCFA, OSCP, BTL2, or equivalent is highly desired • Previous team lead or supervisory leadership experience is desired • Experience with Azure, Microsoft Sentinel/Defender XDR, Entra ID, and Kusto Query Language (KQL) is desired • Active participation in Capture-the-Flag events and homelabbing is a plus • Understanding of x64 assembly, Windows data structures, and undocumented parts of Windows OS is desired • Familiarity with low-level reverse engineering and debugging tools such as Ghidra, x64dbg, and IDA is desired • Must participate in an on-call rotation

🏖️ Benefits

• Fully paid individual healthcare, vision and dental insurance for the employee • Paid certification and training opportunities • Three weeks of paid vacation • 11 paid holidays • Supportive environment with a focus on keeping healthy work-life balance • Retirement benefit (401k) with company match • Potential transition into a team leadership role • Exposure to new and emerging technologies • Fun, dynamic environment working on interesting problems

Apply Now

Similar Jobs

🔥 21 hours ago

Malwarebytes

501 - 1000

🔒 Cybersecurity

🤝 B2B

👥 B2C

Security operations manager leading global SecOps, incident response, and threat management for Malwarebytes cybersecurity and ThreatDown MDR. Building resilient 24x7 protection across distributed teams and systems.

🔥 21 hours ago

ThreatDown

501 - 1000

Information Security Operations Manager leading Malwarebytes’ global Security Operations team. Owning SIEM, incident response, vulnerability management, threat hunting, DLP, and AI security for its cybersecurity business.

🕒 2 days ago

HiddenLayer

51 - 200

🤖 Artificial Intelligence

🔒 Cybersecurity

💳 Fintech

Security Operations Specialist securing HiddenLayer’s AI deployments, cloud infrastructure, and enterprise systems. Supporting threat hunting, vulnerability management, compliance controls, and customer-facing AIDR demonstrations.

🕒 5 days ago

OSIbeyond

11 - 50

💼 Consulting

🏥 Healthcare

📦 Logistics

SOC Analyst monitoring, investigating, and containing threats across client environments. Supporting OSIbeyond’s managed cybersecurity platform through automation, incident response, and vulnerability management.

🕒 6 days ago

UltraViolet Cyber

201 - 500

💼 Consulting

📦 Logistics

🔒 Cybersecurity

Associate SOC Analyst monitoring and triaging cyber threats for UltraViolet Cyber’s unified security operations platform. Supporting vulnerability analysis, incident reporting, and 24x7x365 customer security services.

🇺🇸 United States – Remote

💵 $60k - $72k / year

⏰ Full Time

🟢 Junior

🟡 Mid-level

🛡️ Security Operations

🚫👨‍🎓 No degree required