SOC Analyst Tier II

Blu Omega
Sully Square, VA, United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$75,000.0 - $115,000.0
Working hours
Shift work

Tech stack

Multitier Architecture Cloud Computing Cyber Security Query Languages Domain Name System (DNS) Hypertext Transfer Protocols (HTTP) Networking Hardware Intrusion Detection Systems Python (Programming Language) Log Analysis Simple Mail Transfer Protocols Network Protocols
+9 more
Windows PowerShell Security Information and Event Management TCP/IP Scripting Firewalls (Computer Science) Tanium Platform Expertise Fireeye 3-tier Architectures Splunk

Job description

Schedule: Shift-based environment. Initial day shift during onboarding, transitioning to assigned shifts (Back Half Days Wed-Sat, 6am-6pm; Back Half Nights Wed-Sat, 6pm-6am). Overview

Blu Omega is seeking a SOC Analyst Tier 2 to support a federal cybersecurity program in a 24/7 Security Operations Center (SOC) environment. In this role, you will focus on monitoring and triaging security alerts, conducting initial investigations, documenting findings, and escalating confirmed or complex incidents to senior analysts and incident responders. This is a great opportunity for analysts who want to deepen their incident response and threat analysis skills while working with modern enterprise tooling. Program overview

Mission: Support cybersecurity operations through 24/7 SOC monitoring, incident handling, and continuous improvement of detection and response processes.

Environment/tooling (not all required): Splunk, Tanium, Trellix, Zscaler, Microsoft Defender, FireEye., * Monitor and triage security events and alerts generated by SIEM and security tools in a 24/7 SOC environment.

  • Perform initial incident investigation: validate alerts, gather evidence, enrich events, and determine severity and next steps.
  • Analyze logs and telemetry from endpoints, network devices, firewalls, IDS/IPS, and cloud/security platforms.
  • Document findings clearly in ticketing/case systems, including timelines, affected assets, and recommended actions.
  • Escalate confirmed incidents and complex investigations to Tier 3/IR personnel with complete context and supporting evidence.
  • Follow playbooks and standard operating procedures; recommend improvements based on trends, false positives, and observed gaps.
  • Participate in shift handoffs and contribute to daily operational reporting.

Requirements

  • 2+ years of experience in a SOC, NOC, or security monitoring environment (or equivalent hands-on security operations experience).
  • Experience triaging alerts and investigating security events using a SIEM (Splunk experience strongly preferred).
  • Familiarity with endpoint security/EDR tooling and basic incident response concepts (identify, contain, remediate, recover).
  • Working knowledge of Windows fundamentals and common enterprise/network protocols (TCP/IP, DNS, HTTP/HTTPS, SMTP).
  • Ability to write clear, detailed documentation and communicate effectively during escalations.
  • Ability to work onsite in a shift-based environment., * Experience supporting a federal/government SOC environment.
  • Exposure to any of the following: Tanium, Trellix, Zscaler, Microsoft Defender, FireEye.
  • Security certifications (nice to have): Security+, CySA+, SSCP, or similar.
  • Experience with basic scripting or query languages for investigation (PowerShell, Python, SPL) a plus., High School Diploma required; higher education preferred.

Benefits & conditions

Salary Range: $75,000 - $115,000 Final compensation is based on technical skills, experience, education, certifications, and clearance. Benefits & perks

  • Medical, Dental, and Vision coverage
  • 401(k) with company match (eligible after 6 months; vesting applies)
  • Company-paid Life and AD&D insurance, voluntary options available
  • Short-term and long-term disability options
  • Employee Assistance Program (EAP)
  • Telehealth and virtual care options
  • Paid Time Off (PTO) and federal holidays
  • Wellness programs, discounts, and lifestyle benefits

About the company

Blu Omega is a Woman-Owned Small Business (WOSB) delivering technology and cybersecurity solutions to federal agencies and enterprise clients nationwide. Headquartered in Ashburn, VA, we support mission-critical programs across civilian and defense sectors.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

1:23 min

Understanding the complexity of cybersecurity domains

Jennifer Reif · LIVE

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

3:50 min

Queues in TCP stacks and continuous network connections

Clemens Vasters Clemens Vasters · WWC 2022

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all