New

SOC Analyst II

United StatesUnited States·Any Locationmid
Soc AnalystCybersecurity
2 views0 saves0 applied

Quick Summary

Key Responsibilities

Serve as the primary escalation point for Tier I analysts and take ownership of critical/high-severity alerts and escalated security incidents. Analyze endpoints, network traffic,

Requirements Summary

U.S. citizenship - by nature of our work with the defense industry, all employees must be eligible for a Secret clearance.

Technical Tools
Soc AnalystCybersecurity

Sentinel Blue is seeking a Security Operations Center (SOC) Analyst II to join our Overwatch Team. In this role, the SOC Analyst II will lead the analysis, containment, and remediation of complex threats that extend beyond initial triage.

The ideal candidate can manage concurrent investigations across a multi-tenant client base, determine scope of impact, and investigate incidents from detection through resolution. They can think like an attacker and reconstruct how compromises occurred, drive improvements to workflows, playbooks, and documentation, and help advance our capabilities in digital forensics and incident response (DFIR), threat hunting, vulnerability management, and threat intelligence. Collaboration and mentoring junior staff will be key as we work to drive innovation.

This is a full-time position that is fully remote. Due to the nature of our work, you must be a U.S. citizen with eligibility for a clearance. No exceptions.

Sentinel Blue is a young company with a focused mission: we’re bringing enterprise-class cybersecurity to small and medium sized businesses. Frankly, we’re pushing the envelope of how things are done and constantly seeking innovative ways to meet that mission. The pace is fast, and we’re always learning new things. This is a great place if you want to expose yourself to new and emerging technologies, want to be challenged, and want to build your skills. Further, success in this role can quickly transition into a team leadership role. The right person will find themselves in a fun, dynamic environment, working on interesting problems and making a real difference.

Responsibilities

~1 min read
  • →Serve as the primary escalation point for Tier I analysts and take ownership of critical/high-severity alerts and escalated security incidents.
  • →Analyze endpoints, network traffic, and other log data to validate security incidents and perform root cause analysis.
  • →Lead containment, eradication, and recovery during active security incidents, ensuring Standard Operating Procedures (SOPs) and Incident Response (IR) Plans are followed and documented.
  • →Reconstruct attack chains, utilizing the MITRE ATT&CK Framework and Cyber Kill Chain to map adversary tactics, techniques, and procedures (TTPs).
  • →Conduct intelligence and/or hypothesis-driven threat hunts across environments to detect advanced threats that evade security tools and controls.
  • →Write executive reports with a clear narrative structure, detailed analysis, and actionable recommendations.
  • →Manage the vulnerability management lifecycle by analyzing scan results, prioritizing critical vulnerabilities based on risk and exploitability, and coordinating remediation efforts with IT/Engineering.
  • →Develop and maintain IR playbooks and SOPs to ensure consistent and efficient event handling.
  • →Provide technical guidance, training, and feedback to Tier 1 analysts to improve their triage capabilities and knowledge.
  • →Participate in an on-call rotation to provide coverage for critical security incidents outside of standard business hours.

Requirements

~1 min read
  • Possession of intermediate to advanced certifications such as: GCIH/GCIA/GCFA, OSCP, BTL2, or equivalent is highly desired.
  • Previous experience in a team lead or supervisory leadership capacity, demonstrating the ability to drive operational goals, manage complex escalations, and effectively mentor junior staff.
  • Experience with Azure, Microsoft Sentinel/Defender XDR, Entra ID, and Kusto Query Language (KQL).
  • Active participation in Capture-the-Flag (CTF) events and homelabbing, a plus.
  • Understanding of various low-level mechanics such as x64 assembly, Windows data structures, and researching undocumented parts of the Windows OS.
  • Familiarity with low level reverse engineering, debugging and related tools such as Ghidra, x64dbg, IDA, etc.

What We Offer

~1 min read
✓Fully paid individual healthcare, vision and dental insurance for the employee.
✓Paid certification and training opportunities.
✓Three weeks of paid vacation + 11 paid holidays.
✓A supportive environment with a focus on keeping healthy work-life balance.
✓Retirement benefit (401k) with company match.

Location & Eligibility

Where is the job
Any Location, United States
On-site at the office
Who can apply
US

Listing Details

First seen
October 7, 2026
Last seen
October 7, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
58%
Scored at
October 7, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Employees
30
Founded
2020
View company profile

1 other job at

View all →

Explore open roles at .

Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

SOC Analyst II