Cybersecurity SOC Analyst II
CHAOS Industries · San Francisco, CA · 4 wk ago
On-siteInformation Technology$110k–$160k/yrFull-time
Role Overview
We are seeking a SOC Analyst II to join our growing Security Operations team and help defend the organization against evolving cyber threats. This role supports day-to-day monitoring, triage, investigation, and response activities across enterprise systems, endpoints, cloud infrastructure, and collaboration environments.
Responsibilities
- Monitor and triage security alerts and events across enterprise systems, endpoints, cloud platforms, and networks
- Investigate suspicious activity, indicators of compromise, phishing attempts, malware detections, and unauthorized access attempts
- Escalate validated security incidents to senior analysts or engineering teams as appropriate
- Support containment, remediation, and recovery activities during cybersecurity incidents
- Aid in root cause analysis and incident documentation
- Support administration and monitoring of cybersecurity platforms including: Microsoft GCC High, CrowdStrike, and other EDR/XDRs, PIM/PAM Tools, Various SIEMs, Azure Sentinel, Monitor endpoint detection and response (EDR/XDR) alerts and telemetry
- Aid in tuning alerting rules and reducing false positives
- Support vulnerability management and remediation tracking activities
- Help maintain endpoint, identity, and cloud security configurations
- Review logs and security telemetry from SIEM, endpoint, network, and cloud security platforms
- Identify anomalous or malicious behavior patterns
- Aid in development and improvement of detection rules, playbooks, and response procedures
- Participate in threat hunting and proactive security monitoring initiatives
Minimum Requirements
- 3–5+ years of experience in cybersecurity, IT support, systems administration, or SOC operations
- Foundational understanding of cybersecurity concepts including networking, endpoint security, identity management, and incident response
- Familiarity with security monitoring and alert triage processes
- Experience working with Managed Security Service Providers (MSSPs)
- Experience or exposure to enterprise security platforms such as: Microsoft GCC High, CrowdStrike, and other EDR/XDRs, App Allow/Block-listing tools, PIM/PAM Tools, Various SIEMs, Azure Sentinel
- Strong understanding of Windows, Linux, macOS, and cloud-based environments
- Basic understanding of SIEM, EDR/XDR, phishing analysis, and log analysis
- Strong analytical, troubleshooting, and problem-solving skills
- Excellent written and verbal communication skills
- Ability to prioritize and manage multiple tasks in a fast-paced environment
- Must be a U.S. Citizen eligible for government facilities and sensitive information
Preferred Requirements
- Active Security Clearance
- Experience supporting defense, aerospace, government contracting, or regulated technology environments
- Familiarity with Microsoft GCC High environments
- Familiarity with using AI and LLM tools within the SOC
- Familiarity with monitoring AI and LLM tools
- Exposure to compliance frameworks such as NIST 800-171, CMMC, CIS Controls, or ISO 27001
- Experience with scripting or automation using PowerShell, Python, or Bash
- Familiarity with digital forensic process and chain of custody
- Knowledge of MITRE ATT&CK framework and common threat actor techniques
- Security certifications such as Security+, CySA+, SC-900, Network+, or equivalent
- Experience working in a 24/7 or operational security environment