SOC Analyst II

Posted 3 Days Ago
Be an Early Applicant
Monterey, CA, USA
In-Office
39-44 Hourly
Mid level
Aerospace • Information Technology • Professional Services • Defense
The Role
Provides Tier II SOC cybersecurity support through vulnerability assessments, threat and log analysis, incident detection and response, malware analysis, intrusion monitoring, evidence preservation, and remediation coordination. Configures security monitoring tools, manages incident tickets, reviews threat intelligence, conducts damage assessments, and briefs leadership. The role operates in a rotating 24/7 shift environment and may train Tier I analysts.
Summary Generated by Built In
Overview

Now Hiring at AMERICAN SYSTEMS


Epsilon, Inc. has joined AMERICAN SYSTEMS! As one organization, we offer expanded resources, streamlined operations, and increased opportunities for growth and development. 


Join us to be part of a dynamic, collaborative environment dedicated to innovation and customer success. 

Responsibilities

An Average Day:As the SOC Analyst II, you will provide tier II cybersecurity support in a Security Operations Center “SOC” environment. Daily responsibilities of the SOC are ever changing, however, you can expect to regularly conduct vulnerability assessments, analyze cyber threats, monitor the email gateway and create reports on all confirmed or suspicious activities. You will work closely with the Tier I and other Tier II personnel to effectively and efficiently provide optimum service to our customers as well as assist with training SOC Analyst I team members when needed. Additionally, in this position you will:

  • Use intrusion detection technologies to apply techniques for identifying host and network-based intrusions.
  • Create, update, and resolve incident tickets that have been tasked to Tier II and appropriately document all alerts and incidents in the ticketing system.
  • Review asset discovery and vulnerability assessment data.
  • Lead incidents from alert to resolution:
    • Leverage emerging threat intelligence (Indicators of Compromise, updated rules, etc.) to identify affected systems and the scope of the attack.
    • Review and collect asset data (logs, configurations, running processes, ) on these systems for further investigation.
    • Determine and direct remediation and recovery efforts including tasking of IHT1 as needed.
    • Determine and request engineering, forensics, or threat intelligencesupport.
    • Inform and brief status of incidents to CSOC manager, CISO, DCIO, or CIO.
  • May manage and configure security monitoring tools (SIEM, IDS, Firewall, Access Control Lists, etc.) to mitigate existing threats / vulnerabilities.
  • Interface and take guidance from the CSOC manager (government position).
  • Review trouble tickets generated by Tier 1.
  • Review threat intel and create notifications and share with specified personnel.
  • Handle other tasks that tier II level of experience and talent can complete.
  • Design incident response for cloud service models.
  • Perform damage assessments.
  • Preserve evidence integrity according to standard operating procedures or national standards.
  • Protect networks against (e.g., NIPS, anti-malware, restrict/prevent external devices, spam filters).
  • Recognize and categorize types of vulnerabilities and associated attacks.
  • Secure network communications.
  • Use security event correlation Tools.
  • Identify, capture, contain, and report malware.
  • Utilize the SOC standard operating procedures (SOP) to perform daily tasks, resolve incidents and preserve evidence integrity. May provide input for and assist with updating procedures.
Qualifications
  • As a requirement of this position, all candidates must be a U.S. Citizen in accordance with 8 U.S.C. 1324b(a)(2)(C).
  • Must hold an active Dept. of War Top Secret Clearance.
  • At least three (3) years of professional experience in incident detection and response, malware analysis, or cyber forensics and a bachelor’s degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field.
  • Hold at least one certification as required by DoD 8570.01-M and DoD Directive 8140.01, IAT Level II or higher. 
  • Must hold at least one of the following additional certifications: CompTIA CASP+, GIAC GCIH, Microsoft AZ-500, Microsoft SC-200, Splunk Core Certified Advanced Power User
  • Must have extensive experience working with various security methodologies, standard operating procedures, processes, and workflows. Experience configuring and implementing various technical security solutions, extensive experience providing analysis and trending of security log data from a large number of heterogeneous security devices.
  • Experience with some or all of the following is required:
    • Computer networking concepts, OSI model, and network protocols such as TCP/IP, Dynamic Host Configuration, Domain Name System (DNS), and directory services, and network security
    • Host/network access control mechanisms (e.g., access control list, capabilities lists).
    • network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
    • Network traffic analysis methods and packet-level
    • Cyber threats and vulnerabilities; cyber-attack stages, classes of attacks and attackers; cyber defense and information security policies, procedures, and
    • Incident response and handling methodologies, incident categories, and timelines for
    • Intrusion detection methodologies and techniques for detecting host and network-based intrusions.
    • Malware analysis concepts and
    • cloud service models and how those models can limit incident
    • Application Security Risks (e.g. Open Web Application Security Project Top 10 list)
    • System administration, network, and operating system hardening techniques as well as data backup and
    • System and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, return-oriented attacks, malicious code).
  • Experience with the following: JIRA (Atlassian issue tracking system), Palo Alto Firewall, SNORT IDS, AlienVault SIEM, Barracuda Mail Spam / Virus Firewall, and HBSS.
  • This team operates in a 24/7 shift environment. 1st, 2nd and 3rd shifts run Monday – Thursday or Friday – Monday, are 10 hours per day and rotate every 3 months.
Pay Transparency StatementAMERICAN SYSTEMS is committed to pay transparency for our applicants and employee-owners. The salary range for this position is USD $39.00/Hr. - USD $44/Hr. Actual compensation will be determined based on several factors permitted by law. AMERICAN SYSTEMS provides for the welfare of its employees and their dependents through a comprehensive benefits program by offering healthcare benefits, paid leave, retirement plans, insurance programs, and education and training assistance. EEO StatementEEO Race/Sex/Disability Status/Veteran Status

Skills Required

  • U.S. citizenship required under 8 U.S.C. 1324b(a)(2)(C).
  • Active Department of War Top Secret clearance.
  • At least three years of professional experience in incident detection and response, malware analysis, or cyber forensics.
  • Bachelor’s degree in Computer Science, Engineering, Information Technology, Cybersecurity, or a related field.
  • At least one certification meeting DoD 8570.01-M and DoD Directive 8140.01 requirements at IAT Level II or higher.
  • At least one additional certification: CompTIA CASP+, GIAC GCIH, Microsoft AZ-500, Microsoft SC-200, or Splunk Core Certified Advanced Power User.
  • Extensive experience with security methodologies, standard operating procedures, technical security solutions, and analysis of security logs from heterogeneous devices.
  • Experience with networking concepts, OSI model, TCP/IP, DHCP, DNS, directory services, and network security.
  • Experience with host and network access controls, security architecture, network traffic analysis, and packet-level analysis.
  • Knowledge of cyber threats, vulnerabilities, attack stages, cyber defense policies, incident response, intrusion detection, malware analysis, and cloud service models.
  • Knowledge of application security risks, system administration, network and operating system hardening, data backup, and application vulnerabilities.
  • Experience with JIRA, Palo Alto Firewall, SNORT IDS, AlienVault SIEM, Barracuda Mail Spam/Virus Firewall, and HBSS.
  • Availability to work a rotating 24/7 schedule across 10-hour first, second, and third shifts.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
2,235 Employees
Year Founded: 1975

What We Do

AMERICAN SYSTEMS is an employee-owned government services contractor that delivers professional, technical, information technology, engineering, analysis, testing, evaluation, and training solutions for complex national-priority programs. Based in McLean, Virginia, the company supports federal customers—particularly defense and other Department of Defense missions—with mission-essential and information engineering, digital engineering, systems integration, cybersecurity, cloud, data, and lifecycle IT services across critical public-sector environments.

Similar Jobs

Optum Logo Optum

Referral Coordinator

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Irvine, CA, USA
160000 Employees
16-29 Hourly

Optum Logo Optum

Associate Patient Care Coordinator

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Huntington Beach, CA, USA
160000 Employees
16-29 Hourly

Optum Logo Optum

Project Manager

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Irvine, CA, USA
160000 Employees
92K-164K Annually

Optum Logo Optum

Staff Pharmacist Full Time

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Norwalk, CA, USA
160000 Employees
44-79 Hourly

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Outpost Space Thumbnail
Aerospace • Defense
US
24 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account