Hiring.Camp

SOC Analyst II

Sentinel Blue

·

Yesterday

Salary
$70k – $80k/yr
Location
Any Location, US
Workplace
Remote
Type
Full-time
Experience
2+ years
Visa
Not sponsored
Clearance
Required
Source
Breezy HR

Description

Sentinel Blue is seeking a Security Operations Center (SOC) Analyst II to join our Overwatch Team. In this role, the SOC Analyst II will lead the analysis, containment, and remediation of complex threats that extend beyond initial triage.

The ideal candidate can manage concurrent investigations across a multi-tenant client base, determine scope of impact, and investigate incidents from detection through resolution. They can think like an attacker and reconstruct how compromises occurred, drive improvements to workflows, playbooks, and documentation, and help advance our capabilities in digital forensics and incident response (DFIR), threat hunting, vulnerability management, and threat intelligence. Collaboration and mentoring junior staff will be key as we work to drive innovation.

This is a full-time position that is fully remote. Due to the nature of our work, you must be a U.S. citizen with eligibility for a clearance. No exceptions.

What We Can Offer:

Sentinel Blue is a young company with a focused mission: we’re bringing enterprise-class cybersecurity to small and medium sized businesses. Frankly, we’re pushing the envelope of how things are done and constantly seeking innovative ways to meet that mission. The pace is fast, and we’re always learning new things. This is a great place if you want to expose yourself to new and emerging technologies, want to be challenged, and want to build your skills. Further, success in this role can quickly transition into a team leadership role. The right person will find themselves in a fun, dynamic environment, working on interesting problems and making a real difference.

Requirements:

  • U.S. citizenship - by nature of our work with the defense industry, all employees must be eligible for a Secret clearance.
  • Minimum of 2-5 years of experience in a Security Operations Center and/or a combination of experience in cyber-adjacent or IT administration roles such as.

Responsibilities:

  • Serve as the primary escalation point for Tier I analysts and take ownership of critical/high-severity alerts and escalated security incidents.
  • Analyze endpoints, network traffic, and other log data to validate security incidents and perform root cause analysis.
  • Lead containment, eradication, and recovery during active security incidents, ensuring Standard Operating Procedures (SOPs) and Incident Response (IR) Plans are followed and documented.
  • Reconstruct attack chains, utilizing the MITRE ATT&CK Framework and Cyber Kill Chain to map adversary tactics, techniques, and procedures (TTPs).
  • Conduct intelligence and/or hypothesis-driven threat hunts across environments to detect advanced threats that evade security tools and controls.
  • Write executive reports with a clear narrative structure, detailed analysis, and actionable recommendations.
  • Manage the vulnerability management lifecycle by analyzing scan results, prioritizing critical vulnerabilities based on risk and exploitability, and coordinating remediation efforts with IT/Engineering.
  • Develop and maintain IR playbooks and SOPs to ensure consistent and efficient event handling.
  • Provide technical guidance, training, and feedback to Tier 1 analysts to improve their triage capabilities and knowledge.
  • Participate in an on-call rotation to provide coverage for critical security incidents outside of standard business hours.

Knowledge & Skills

  • Incident Response: Perform deep dives, event correlation across logs, host and network artifacts for root cause analysis and respond across the IR lifecycle with remediation/containment actions.
  • Windows OS Internals: Intermediate to advanced understanding of various components and internal workings of the Windows OS such as Event Tracing for Windows, Win32 API, the Registry, Memory, and Process operations.

Attack Lifecycles & Frameworks: Map adversary tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework.

  • Threat Intelligence Integration: Correlate incidents with threat feeds using Indicators of Compromise (IoCs), threat actor attribution, and vulnerability exploitation patterns.
  • Networking & Protocols: Intermediate to advanced understanding of common network protocols such as TCP/IP, DNS, HTTP, SSL/TLS, etc.
  • Scripting & Automation: Intermediate to advanced writing and interpretation of Python or PowerShell scripts to parse logs or automate manual, repetitive tasks. Other scripting languages are beneficial as well.
  • System Administration: Ability to safely manage Windows devices via the command line using PowerShell or Batch.
  • Basic Malware Analysis: Ability to detect and reverse engineer malicious scripts or other high-level languages. Understanding of various code injection technique and other attack / evasion techniques as they relate to Windows.
  • Tools: Prior experience with SIEM platforms such as Microsoft Sentinel, ELK/Elastic Stack, Splunk, etc; Hands-on experience with Sysinternals Suite (Process Explorer, Autoruns, etc); Volatility; SIFT Workstation; CyberChef; Forensic Browser for SQLite; Velociraptor; Explorer Suite; Wireshark; malware analysis sandboxes, etc. Other equivalent tools are acceptable.
  • Adversarial Tradecraft: Familiarity of trending malware development, social engineering, phishing, exploitations, persistence, evasion techniques, credential theft, C2, exfiltration, and lateral movement.

Desired Qualifications:

  • Possession of intermediate to advanced certifications such as: GCIH/GCIA/GCFA, OSCP, BTL2, or equivalent is highly desired.
  • Previous experience in a team lead or supervisory leadership capacity, demonstrating the ability to drive operational goals, manage complex escalations, and effectively mentor junior staff.
  • Experience with Azure, Microsoft Sentinel/Defender XDR, Entra ID, and Kusto Query Language (KQL).
  • Active participation in Capture-the-Flag (CTF) events and homelabbing, a plus.
  • Understanding of various low-level mechanics such as x64 assembly, Windows data structures, and researching undocumented parts of the Windows OS.
  • Familiarity with low level reverse engineering, debugging and related tools such as Ghidra, x64dbg, IDA, etc.

Benefits:

  • Fully paid individual healthcare, vision and dental insurance for the employee.
  • Paid certification and training opportunities.
  • Three weeks of paid vacation + 11 paid holidays.
  • A supportive environment with a focus on keeping healthy work-life balance.
  • Retirement benefit (401k) with company match.

Skills

PythonAzureSQLiteCybersecuritySIEMSOCSplunkTCP/IP

Similar Jobs

5

SOC Analyst II

Kinettix Inc 2·Cebu City

1w ago

SOC Analyst II

AMERICAN SYSTEMS·Monterey, CA

3mo ago

SOC Analyst II

Edgewaterit·Oak Ridge, TN·Onsite

1y+ ago

Cybersecurity SOC Analyst II

Chaosindustries·Washington, District of Columbia +2

3mo ago

SOC Analyst, Tier III

Interac Corp.·Interac Corp. Head Office, Canada

2mo ago