ForgeApply
Try it free

ForgeApply · Job listing

Tier 2 Security Operations Center (SOC) Analyst

Leidos

Alexandria, VA | Seaside, US$87k – $157konsite

See all 242 open roles at Leidos

Tailor your resume for this Leidos job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Leidos's site. Free trial, no card required.

About this role

Leidos is seeking an experienced Tier 2 Security Operations Center (SOC) Analyst to support the Defense Manpower Data Center (DMDC)   CyberPRIMES   program. Leidos is a major partner on the contract and will provide a substantial   portion   of the cybersecurity workforce supporting the Defense Human Resources Activity (DHRA) and DMDC.   

The Tier 2 SOC Analyst will perform advanced analysis of cybersecurity events escalated from Tier 1 or   identified   through enterprise monitoring capabilities. This position will correlate security data,   determine   the scope and potential impact of suspicious activity, support incident triage and containment, preserve evidence, and coordinate with incident responders and other cybersecurity teams to protect DHRA systems and networks. 

Work Locations: 

• Mark Center, Alexandria, Virginia – 3 positions 

• Department of Defense Center – Monterey Bay, Seaside, California – 3 positions 

Clearance: Active Secret security clearance required at time of consideration. U.S. Citizen is a must.

Mission Environment 

DMDC supports the Defense Human Resources Activity within the Office of the Under Secretary of Defense for Personnel and Readiness (OUSD(P&R)) and maintains the Department of Defense’s largest and most comprehensive central repository of personnel, manpower, casualty, pay, entitlement, personnel security, identity, readiness, training, and related data. The DHRA Information Technology (IT) environment includes approximately 15,000 network and endpoint devices supporting more than 600 Government-Off-The-Shelf (GOTS) applications and approximately 100 Risk Management Framework (RMF) authorization boundaries managed through the Enterprise Mission Assurance Support Service (eMASS). The Tier 2 SOC Analysts   operate   within a 24x7 security operations environment responsible for detecting, analyzing, escalating, and supporting response to cybersecurity activity affecting DHRA systems and networks. Tier 2 analysts provide the deeper technical analysis   required   when events cannot be resolved through   initial   Tier 1 triage. 

Primary Responsibilities:

• Perform advanced analysis of cybersecurity events escalated from Tier 1 analysts or   identified   through endpoint, user-activity, network, and other enterprise monitoring capabilities. 

• Correlate alerts, security telemetry, and supporting technical data to   determine   the nature, scope, severity, and potential impact of cybersecurity activity. 

• Distinguish legitimate activity, false positives, policy violations, suspicious behavior, and potential cybersecurity incidents. 

• Determine   appropriate next   actions based on approved SOC procedures, playbooks, and escalation criteria. 

• Recommend or   initiate   authorized actions to   contain   or mitigate   identified   threats. 

• Support cybersecurity incident triage, escalation, and containment in coordination with the incident-response team. 

• Preserve relevant technical evidence and supporting information required for further investigation and incident response. 

• Document investigative actions, analysis, findings, and conclusions in Government-approved systems. 

• Maintain complete and   accurate   event records, tickets, timelines, and supporting evidence. 

• Contribute to required SOC event reporting and operational status information. 

• Perform Tier 2 troubleshooting of cybersecurity tools, alerts, security data, and related technical issues. 

• Use approved Commercial-Off-The-Shelf (COTS) security-analysis tools to investigate cybersecurity events. 

• Support security testing, mitigation activities, and cybersecurity compliance checking as required by SOC operations. 

• Coordinate analysis with incident responders, network engineers, endpoint-security personnel, cybersecurity-tool teams, system administrators, and other cybersecurity stakeholders. 

• Identify   recurring false positives, detection gaps, or ineffective alerting and recommend improvements to   monitoring   and detection capabilities. 

• Support tuning of cybersecurity monitoring capabilities to improve detection accuracy and analyst effectiveness. 

• Contribute to SOC procedure, playbook, and process improvements based on operational experience and lessons learned. 

• Support knowledge transfer across SOC analysts to improve consistent analysis and response within the 24x7 operating environment. 

Basic Qualifications:

• Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical discipline and 5 or more years of relevant cybersecurity experience. Specific experience, education and training may be considered in lieu of degree.

• Experience performing cybersecurity event analysis, SOC operations, cyber defense, incident triage, or security monitoring. 

• Experience analyzing and correlating alerts from multiple cybersecurity monitoring capabilities. 

• Experience investigating endpoint, network, user-activity, or other cybersecurity events. 

• Experience   determining   the scope, severity, and potential impact of suspicious cybersecurity activity. 

• Experience supporting cybersecurity incident escalation, containment, mitigation, or evidence preservation. 

• Experience using enterprise security-analysis or cybersecurity monitoring tools. 

• Experience performing Tier 2 cybersecurity troubleshooting. 

• Working knowledge of cybersecurity attack techniques, network-security concepts, endpoint security, event analysis, and incident-response processes. 

• Ability to document investigations, findings, actions, and conclusions clearly and accurately. 

• Ability to work effectively within a team-based 24x7 security operations environment. 

• U.S. Citizenship   required. 

• Active Secret security clearance   required. 

Preferred Qualifications:

• Experience supporting a Department of Defense or Federal Security Operations Center. 

• Experience working in a 24x7 SOC or Cybersecurit

Salary insight

The midpoint of this range ($122k) is about 6% below the median disclosed salary for Washington DC roles listed on ForgeApply ($131k across 2,065 jobs).

See full Operations salary data for Washington DC

Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.

Tailor your resume for this Leidos role before you apply.

Tailor my resume for this job

Similar jobs

More like this: Operations Jobs · Operations Jobs in Washington DC · Browse all jobs

Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)