Quick Summary
Serve as the primary escalation point for Tier I analysts and take ownership of critical/high-severity alerts and escalated security incidents. Analyze endpoints, network traffic,
U.S. citizenship - by nature of our work with the defense industry, all employees must be eligible for a Secret clearance.
Sentinel Blue is seeking a Security Operations Center (SOC) Analyst II to join our Overwatch Team. In this role, the SOC Analyst II will lead the analysis, containment, and remediation of complex threats that extend beyond initial triage.
The ideal candidate can manage concurrent investigations across a multi-tenant client base, determine scope of impact, and investigate incidents from detection through resolution. They can think like an attacker and reconstruct how compromises occurred, drive improvements to workflows, playbooks, and documentation, and help advance our capabilities in digital forensics and incident response (DFIR), threat hunting, vulnerability management, and threat intelligence. Collaboration and mentoring junior staff will be key as we work to drive innovation.
This is a full-time position that is fully remote. Due to the nature of our work, you must be a U.S. citizen with eligibility for a clearance. No exceptions.
Sentinel Blue is a young company with a focused mission: we’re bringing enterprise-class cybersecurity to small and medium sized businesses. Frankly, we’re pushing the envelope of how things are done and constantly seeking innovative ways to meet that mission. The pace is fast, and we’re always learning new things. This is a great place if you want to expose yourself to new and emerging technologies, want to be challenged, and want to build your skills. Further, success in this role can quickly transition into a team leadership role. The right person will find themselves in a fun, dynamic environment, working on interesting problems and making a real difference.
Responsibilities
~1 min read- →Serve as the primary escalation point for Tier I analysts and take ownership of critical/high-severity alerts and escalated security incidents.
- →Analyze endpoints, network traffic, and other log data to validate security incidents and perform root cause analysis.
- →Lead containment, eradication, and recovery during active security incidents, ensuring Standard Operating Procedures (SOPs) and Incident Response (IR) Plans are followed and documented.
- →Reconstruct attack chains, utilizing the MITRE ATT&CK Framework and Cyber Kill Chain to map adversary tactics, techniques, and procedures (TTPs).
- →Conduct intelligence and/or hypothesis-driven threat hunts across environments to detect advanced threats that evade security tools and controls.
- →Write executive reports with a clear narrative structure, detailed analysis, and actionable recommendations.
- →Manage the vulnerability management lifecycle by analyzing scan results, prioritizing critical vulnerabilities based on risk and exploitability, and coordinating remediation efforts with IT/Engineering.
- →Develop and maintain IR playbooks and SOPs to ensure consistent and efficient event handling.
- →Provide technical guidance, training, and feedback to Tier 1 analysts to improve their triage capabilities and knowledge.
- →Participate in an on-call rotation to provide coverage for critical security incidents outside of standard business hours.
Requirements
~1 min read- Possession of intermediate to advanced certifications such as: GCIH/GCIA/GCFA, OSCP, BTL2, or equivalent is highly desired.
- Previous experience in a team lead or supervisory leadership capacity, demonstrating the ability to drive operational goals, manage complex escalations, and effectively mentor junior staff.
- Experience with Azure, Microsoft Sentinel/Defender XDR, Entra ID, and Kusto Query Language (KQL).
- Active participation in Capture-the-Flag (CTF) events and homelabbing, a plus.
- Understanding of various low-level mechanics such as x64 assembly, Windows data structures, and researching undocumented parts of the Windows OS.
- Familiarity with low level reverse engineering, debugging and related tools such as Ghidra, x64dbg, IDA, etc.
What We Offer
~1 min readLocation & Eligibility
Listing Details
- First seen
- October 7, 2026
- Last seen
- October 7, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 58%
- Scored at
- October 7, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.
