
SOC Analyst II
Posted 8 hours ago

Posted 8 hours ago
This is a fully remote position, open to applicants in United States.
• Act as the main escalation point for Tier I analysts.
• Take responsibility for critical/high-severity alerts and escalated security incidents.
• Evaluate endpoints, network traffic, and log data to confirm incidents and conduct root cause analysis.
• Lead the processes of containment, eradication, and recovery during active security incidents.
• Adhere to and document Standard Operating Procedures and Incident Response Plans.
• Reconstruct attack vectors using the MITRE ATT&CK Framework and Cyber Kill Chain.
• Execute intelligence- and hypothesis-driven threat hunting activities.
• Compose executive reports with clear narratives, thorough analyses, and practical recommendations.
• Oversee the vulnerability management lifecycle, including scan analysis, risk-based prioritization, and coordination of remediation efforts.
• Create and maintain incident response playbooks and SOPs.
• Offer technical guidance, training, and feedback to Tier 1 analysts.
• Participate in an on-call rotation for critical incidents outside regular business hours.
• Collaborate with and mentor junior personnel.
• Assist in enhancing capabilities in digital forensics and incident response, threat hunting, vulnerability management, and threat intelligence.
• U.S. citizenship is required.
• Must qualify for a Secret clearance.
• A minimum of 2–5 years of experience in a Security Operations Center and/or cyber-adjacent or IT administration roles is necessary.
• Intermediate to advanced knowledge of Windows OS internals, including Event Tracing for Windows, Win32 API, Registry, Memory, and Process operations.
• Intermediate to advanced understanding of TCP/IP, DNS, HTTP, SSL/TLS, and other common network protocols.
• Intermediate to advanced skills in writing and interpreting Python or PowerShell scripts.
• Capability to manage Windows devices via command line using PowerShell or Batch.
• Proficiency in detecting and reverse engineering malicious scripts or other high-level languages.
• Understanding of code injection and attack/evasion techniques related to Windows.
• Previous experience with SIEM platforms like Microsoft Sentinel, ELK/Elastic Stack, or Splunk.
• Practical experience with Sysinternals Suite, Volatility, SIFT Workstation, CyberChef, Forensic Browser for SQLite, Velociraptor, Explorer Suite, Wireshark, and malware analysis sandboxes, or equivalent tools.
• Familiarity with malware development, social engineering, phishing, exploitation, persistence, evasion, credential theft, C2, exfiltration, and lateral movement.
• Intermediate to advanced certification such as GCIH/GCIA/GCFA, OSCP, BTL2, or equivalent is highly preferred.
• Prior team lead or supervisory experience is desired.
• Experience with Azure, Microsoft Sentinel/Defender XDR, Entra ID, and Kusto Query Language (KQL) is preferred.
• Active involvement in Capture-the-Flag events and homelabbing is advantageous.
• Understanding of x64 assembly, Windows data structures, and undocumented components of the Windows OS is desired.
• Familiarity with low-level reverse engineering and debugging tools such as Ghidra, x64dbg, and IDA is preferred.
• Must participate in an on-call rotation.
• Fully covered individual healthcare, vision, and dental insurance for the employee.
• Paid opportunities for certification and training.
• Three weeks of paid vacation time.
• 11 paid holidays throughout the year.
• A supportive environment emphasizing a healthy work-life balance.
• Retirement benefits (401k) with company matching.
• Potential for transition into a team leadership position.
• Exposure to new and emerging technologies.
• A fun, dynamic environment tackling interesting challenges.
It4us Cyber Security
Malwarebytes
ThreatDown
Get handpicked remote jobs straight to your inbox weekly.