SOC Analyst II

atSentinel BlueRemoteUS flagUnited StatesFull-timeSecurity OperationsJuniorMid-level$70k – $80k/year

Posted 8 hours ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Act as the main escalation point for Tier I analysts.

• Take responsibility for critical/high-severity alerts and escalated security incidents.

• Evaluate endpoints, network traffic, and log data to confirm incidents and conduct root cause analysis.

• Lead the processes of containment, eradication, and recovery during active security incidents.

• Adhere to and document Standard Operating Procedures and Incident Response Plans.

• Reconstruct attack vectors using the MITRE ATT&CK Framework and Cyber Kill Chain.

• Execute intelligence- and hypothesis-driven threat hunting activities.

• Compose executive reports with clear narratives, thorough analyses, and practical recommendations.

• Oversee the vulnerability management lifecycle, including scan analysis, risk-based prioritization, and coordination of remediation efforts.

• Create and maintain incident response playbooks and SOPs.

• Offer technical guidance, training, and feedback to Tier 1 analysts.

• Participate in an on-call rotation for critical incidents outside regular business hours.

• Collaborate with and mentor junior personnel.

• Assist in enhancing capabilities in digital forensics and incident response, threat hunting, vulnerability management, and threat intelligence.


⛳️ Requirements

• U.S. citizenship is required.

• Must qualify for a Secret clearance.

• A minimum of 2–5 years of experience in a Security Operations Center and/or cyber-adjacent or IT administration roles is necessary.

• Intermediate to advanced knowledge of Windows OS internals, including Event Tracing for Windows, Win32 API, Registry, Memory, and Process operations.

• Intermediate to advanced understanding of TCP/IP, DNS, HTTP, SSL/TLS, and other common network protocols.

• Intermediate to advanced skills in writing and interpreting Python or PowerShell scripts.

• Capability to manage Windows devices via command line using PowerShell or Batch.

• Proficiency in detecting and reverse engineering malicious scripts or other high-level languages.

• Understanding of code injection and attack/evasion techniques related to Windows.

• Previous experience with SIEM platforms like Microsoft Sentinel, ELK/Elastic Stack, or Splunk.

• Practical experience with Sysinternals Suite, Volatility, SIFT Workstation, CyberChef, Forensic Browser for SQLite, Velociraptor, Explorer Suite, Wireshark, and malware analysis sandboxes, or equivalent tools.

• Familiarity with malware development, social engineering, phishing, exploitation, persistence, evasion, credential theft, C2, exfiltration, and lateral movement.

• Intermediate to advanced certification such as GCIH/GCIA/GCFA, OSCP, BTL2, or equivalent is highly preferred.

• Prior team lead or supervisory experience is desired.

• Experience with Azure, Microsoft Sentinel/Defender XDR, Entra ID, and Kusto Query Language (KQL) is preferred.

• Active involvement in Capture-the-Flag events and homelabbing is advantageous.

• Understanding of x64 assembly, Windows data structures, and undocumented components of the Windows OS is desired.

• Familiarity with low-level reverse engineering and debugging tools such as Ghidra, x64dbg, and IDA is preferred.

• Must participate in an on-call rotation.


🏝️ Benefits

• Fully covered individual healthcare, vision, and dental insurance for the employee.

• Paid opportunities for certification and training.

• Three weeks of paid vacation time.

• 11 paid holidays throughout the year.

• A supportive environment emphasizing a healthy work-life balance.

• Retirement benefits (401k) with company matching.

• Potential for transition into a team leadership position.

• Exposure to new and emerging technologies.

• A fun, dynamic environment tackling interesting challenges.

People also viewed

It4us Cyber Security13 hours ago

SecOps Analyst

BR flagBrazil OnlyFreelanceSecurity Operations
ApplyView job
Malwarebytes1 day ago

Manager, Information Security Operations

US flagUnited States OnlyFull-timeSecurity Operations$133k – $190k/year
ApplyView job
ThreatDown1 day ago

Manager, Information Security Operations

US flagUnited States OnlyFull-timeSecurity Operations$133k – $190k/year
ApplyView job
Ontinue1 day ago

Cyber Defender – SOC Analyst

CA flagCanada OnlyFull-timeSecurity Operations
ApplyView job
Unifique1 day ago

SOC Analyst

BR flagBrazil OnlyFull-timeSecurity Operations
ApplyView job
HiddenLayer2 days ago

Security Operations Specialist

US flagUnited States OnlyFull-timeSecurity Operations
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers