> Markdown version of [/jobs/ext/1977382-soc-analyst-ii](https://www.wearedevelopers.com/jobs/ext/1977382-soc-analyst-ii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SOC Analyst II - **Company:** Resourcesoft, Inc. - **Location:** Bellaire, TX, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Application Layers, Cloud Computing, Cyber Security, Dynamic Host Configuration Protocol, Domain Name System (DNS), Intrusion Detection Systems, Log Analysis, Network Protocols, Security Information and Event Management, TCP/IP, Software Vulnerability Management, Mitre Att&ck, Firewalls (Computer Science), ArcSight Event Correlation, User Accounts - **Published:** August 7, 2026 - **Apply:** https://www.careerjet.com/jobad/usf9601e091411ac93d82c0030eda8eb20 ## About the Role 4+ years of professional experience operating within a Security Operations Center (SOC) at an L2 capacity. Proficiency in Rapid7 InsightIDR or equivalent enterprise SIEM platforms for advanced log analysis and event correlation. Experience with networking protocols and infrastructure including TCP/IP, DNS, DHCP, firewalls, and common ports. Experience in Level 2 security alert investigation across endpoints, user accounts, and diverse cloud infrastructure. Experience with incident response lifecycles, containment strategies, and threat-analysis frameworks like MITRE ATT&CK. Experience with EDR solutions, intrusion detection systems, and vulnerability management tools to identify malicious traffic. Excellent communication skills for documenting technical findings and coordinating escalations with stakeholders. ## Description Analyze and validate security alerts generated within the Rapid7 SIEM to distinguish legitimate threats from false positives. Lead Level 2 triage and deep-dive investigation of suspicious activity across network, endpoint, and application layers. Correlate security telemetry from multiple sources to identify complex attack patterns and indicators of compromise. Orchestrate incident containment and remediation activities in collaboration with technical infrastructure and networking teams. Maintain accurate security incident tickets and produce detailed reports on technical findings and investigative actions. Evaluate recurring alerts and monitoring trends to improve detection logic and optimize SIEM performance. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Leveraging Large Language Models for Legacy Code Translation: Challenges and Solutions](https://www.wearedevelopers.com/videos/1157-leveraging-large-language-models-for-legacy-code-translation-challenges-and-solutions) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)