> Markdown version of [/jobs/ext/3622596-soc-analyst-ii](https://www.wearedevelopers.com/jobs/ext/3622596-soc-analyst-ii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SOC Analyst II - **Company:** Sentinel Blue - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Microsoft Azure, Command-Line Interface, Computer Networks, Data Structures, Software Debugging, Domain Name System (DNS), Elasticsearch, Hypertext Transfer Protocols (HTTP), Python (Programming Language), Windows API, Network Protocols, Windows PowerShell, Anti-Phishing, Kusto Query Language, Reverse Engineering, Security Information and Event Management, SQLite, TCP/IP, Wireshark, Software Vulnerability Management, Scripting, Transport Layer Security, Mitre Att&ck, Malware, Cyber Threat Analysis, SC Clearance, Microsoft Sentinel, Splunk - **Published:** October 8, 2026 - **Apply:** https://startup.jobs/soc-analyst-ii-sentinel-blue-10332946 ## About the Role * U.S. citizenship - by nature of our work with the defense industry, all employees must be eligible for a Secret clearance. * Minimum of 2-5 years of experience in a Security Operations Center and/or a combination of experience in cyber-adjacent or IT administration roles such as., * System Administration: Ability to safely manage Windows devices via the command line using PowerShell or Batch. * Basic Malware Analysis: Ability to detect and reverse engineer malicious scripts or other high-level languages. Understanding of various code injection technique and other attack / evasion techniques as they relate to Windows. * Tools: Prior experience with SIEM platforms such as Microsoft Sentinel, ELK/Elastic Stack, Splunk, etc; Hands-on experience with Sysinternals Suite (Process Explorer, Autoruns, etc); Volatility; SIFT Workstation; CyberChef; Forensic Browser for SQLite; Velociraptor; Explorer Suite; Wireshark; malware analysis sandboxes, etc. Other equivalent tools are acceptable. * Adversarial Tradecraft: Familiarity of trending malware development, social engineering, phishing, exploitations, persistence, evasion techniques, credential theft, C2, exfiltration, and lateral movement. Desired Qualifications: * Possession of intermediate to advanced certifications such as: GCIH/GCIA/GCFA, OSCP, BTL2, or equivalent is highly desired. * Previous experience in a team lead or supervisory leadership capacity, demonstrating the ability to drive operational goals, manage complex escalations, and effectively mentor junior staff. * Experience with Azure, Microsoft Sentinel/Defender XDR, Entra ID, and Kusto Query Language (KQL). * Active participation in Capture-the-Flag (CTF) events and homelabbing, a plus. * Understanding of various low-level mechanics such as x64 assembly, Windows data structures, and researching undocumented parts of the Windows OS. * Familiarity with low level reverse engineering, debugging and related tools such as Ghidra, x64dbg, IDA, etc. ## Description * Serve as the primary escalation point for Tier I analysts and take ownership of critical/high-severity alerts and escalated security incidents. * Analyze endpoints, network traffic, and other log data to validate security incidents and perform root cause analysis. * Lead containment, eradication, and recovery during active security incidents, ensuring Standard Operating Procedures (SOPs) and Incident Response (IR) Plans are followed and documented. * Reconstruct attack chains, utilizing the MITRE ATT&CK Framework and Cyber Kill Chain to map adversary tactics, techniques, and procedures (TTPs). * Conduct intelligence and/or hypothesis-driven threat hunts across environments to detect advanced threats that evade security tools and controls. * Write executive reports with a clear narrative structure, detailed analysis, and actionable recommendations. * Manage the vulnerability management lifecycle by analyzing scan results, prioritizing critical vulnerabilities based on risk and exploitability, and coordinating remediation efforts with IT/Engineering. * Develop and maintain IR playbooks and SOPs to ensure consistent and efficient event handling. * Provide technical guidance, training, and feedback to Tier 1 analysts to improve their triage capabilities and knowledge. * Participate in an on-call rotation to provide coverage for critical security incidents outside of standard business hours. Knowledge & Skills * Incident Response: Perform deep dives, event correlation across logs, host and network artifacts for root cause analysis and respond across the IR lifecycle with remediation/containment actions. * Windows OS Internals: Intermediate to advanced understanding of various components and internal workings of the Windows OS such as Event Tracing for Windows, Win32 API, the Registry, Memory, and Process operations. Attack Lifecycles & Frameworks: Map adversary tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework. * Threat Intelligence Integration: Correlate incidents with threat feeds using Indicators of Compromise (IoCs), threat actor attribution, and vulnerability exploitation patterns. * Networking & Protocols: Intermediate to advanced understanding of common network protocols such as TCP/IP, DNS, HTTP, SSL/TLS, etc. * Scripting & Automation: Intermediate to advanced writing and interpretation of Python or PowerShell scripts to parse logs or automate manual, repetitive tasks. Other scripting languages are beneficial as well.