SOC Analyst 2 102-186

Ic-cap Llc
Colorado Springs, CO, United States
3 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Active Directory Data Analysis Apple Mac Systems Border Gateway Protocol Big Data Cyber Security Computer Networks Dynamic Host Configuration Protocol Linux Domain Name System (DNS) Event Logging
+16 more
Hypertext Transfer Protocols (HTTP) Internet Control Message Protocol Intrusion Detection Systems Multi-protocol Systems Simple Mail Transfer Protocols SAP ERP Routing Pattern Recognition SAP (Applications) Security Information and Event Management SQL Databases Transmission Control Protocol (TCP) Web Applications Computer Networking Systems Malware Cybercrime

Job description

Security Operation Center (SOC) Analyst 2’s primary function is to provide comprehensive Computer Network Defense and Response support through 24×7×365 monitoring and analysis of potential threat activity targeting the enterprise. This position will conduct security event monitoring, advanced analytics and response activities in support of the government’s mission. This position requires a solid understanding of cyber threats and information security in the domains of TTP’s, Threat Actors, Campaigns, and Observables. Additionally, this candidate must be familiar with intrusion detection systems, intrusion analysis, security information event management platforms, endpoint threat detection tools, and security operations ticket management. This position will support activities within Special Access Programs (SAP) supporting Department of Defense (DoD) agencies, such as HQ Air Force, Office of the Secretary of Defense (OSD) and Military Compartments efforts. The position will provide “day-to-day” support for Collateral, Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.

Requirements

  • Must have strong analytical and technical skills in computer network defense operations, ability to lead efforts in Incident Handling (Detection, Analysis, Triage), Hunting (anomalous pattern detection and content management) and Malware Analysis
  • Experience and ability to with analyzing information technology security events to discern events that qualify as legitimate security incidents as opposed to non-incidents. This includes security event triage, incident investigation, implementing countermeasures, and conducting incident response
  • Must be knowledgeable and have hands-on experience with a Security Information and Event Monitoring (SIEM) platforms and/or log management systems that perform log collection, analysis, correlation, and alerting
  • Strong logical/critical thinking abilities, especially analyzing security events (windows event logs, network traffic, IDS events for malicious intent)
  • Excellent organizational and attention to details in tracking activities within various Security Operation workflows
  • A working knowledge of the various operating systems (e.g. Windows, OS X, Linux, etc.) commonly deployed in enterprise networks, a conceptual understanding of Windows Active Directory is also required, and a working knowledge of network communications and routing protocols (e.g. TCP, UDP, ICMP, BGP, MPLS, etc.) and common internet applications and standards (e.g. SMTP, DNS, DHCP, SQL, HTTP, HTTPS, etc.)
  • Experience with the identification and implementation of counter-measures or mitigating controls for deployment and implementation in the enterprise network environment
  • Experience with one or more of the following technologies Network Threat Hunting, Big Data Analytics, Endpoint Threat Detection and Response, SIEM, workflow and ticketing, and Intrusion Detection System, * Bachelor’s degree AND 5 years related experience -OR- 9+ years of additional, relevant experience, in lieu of degree
  • Prior performance in roles such as ISSO or ISSM
  • SAP Experience

Training :

  • CSSP Auditor or CSSP Incident Responder (in lieu of Cybersecurity Service Provider Analyst).
  • Combatting Trafficking in Persons (CTIP)

Security Clearance:

  • Active TS/SCI Clearance and the willingness to sit for a CI polygraph, if needed

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady ¡ World Congress 2026 Europe

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard ¡ World Congress 2025

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 ¡ LIVE

2:04 min

Enhancing network privacy with routing fees and onion routing

Andreas M Antonopoulos ¡ LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin ¡ World Congress 2022

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani ¡ Europe 2026 Virtual

Videos

See all

Related articles

See all