Security Operations Center Analyst II (SOC Analyst II)
Old Second National Bank · Downers Grove, IL · 1 mo ago
Information Technology$69k–$90k/yrFull-time
Responsibilities
- Provides first response support by analyzing alerts and gathering information about potential incidents or vulnerabilities.
- Conducts first-level triage of security events and incidents, including phishing attempts, malware detections, dark-web exposures, suspicious email activity, and security tool alerts.
- Investigates suspicious emails identified through email security systems or reported by employees.
- Administers Business Email Compromise (BEC) response activities, including quarantine actions, email release reviews, and coordination with Fraud and Information Technology teams.
- Affords assessment, prioritization, documentation, and escalation of security alerts generated by security monitoring technologies according to established procedures and incident response playbooks.
- Executes security event investigations utilizing SIEM, EDR, email security, threat intelligence, and other security monitoring platforms.
- Documents findings, collects evidence, and maintains incident records throughout the Incident Response Lifecycle.
- Monitors threat intelligence feeds, vulnerability disclosures, vendor security notifications, and emerging threats that may impact Bank operations.
- Maintains, tests, and improves incident response playbooks, runbooks, escalation procedures, and audit-ready evidence.
- Supports user access review execution by collecting access materials, validating user and role information, identifying exceptions, and supporting remediation efforts.
- Participates in Business Continuity Planning and operational resilience activities, including tabletop exercises, vendor outage scenarios, disaster recovery testing support, and lessons-learned documentation.
- Supports the collection of evidence and documentation required for audits, examinations, compliance reviews, and risk assessments.
- Performs daily operational review activities and other Information Security monitoring tasks as assigned.
Additional Responsibilities
- Provides second-level response support by analyzing complex security alerts, validating findings, coordinating escalations, and supporting containment, eradication, and recovery activities.
- Serves as a senior technical and operational security resource responsible for advanced investigations, SOC process improvement, security governance support, operational resilience activities, and continuous improvement of Security Operations processes.
- Leads or coordinates advanced security investigations and support escalation decisions for complex incidents, vulnerabilities, and threat activity.
- Maintains, tests, and improves incident response playbooks, runbooks, escalation procedures, and audit-ready evidence.
- Serves as department lead for assigned incident response events and manages post-incident reviews with management.
- Validates SOC metrics and provides management reporting related to phishing testing, security awareness training, incidents, vulnerabilities, and operational trends.
- Develops, maintains, and distributes internal security awareness materials.
- Conducts risk assessments to determine the impact, criticality, and remediation timelines for identified vulnerabilities.
- Develops the quarterly Information Security trends newsletter and uses relevant current events to support tabletop exercise planning.
- Leads or coordinates assigned User Access Reviews, supports Segregation of Duties and Password Complexity control assessments, maintains UAR evidence, and assists with audit-ready documentation and final review packages.
- Leads assigned BCP/tabletop scenarios for SOC-managed platforms and ensures playbooks, escalation paths, alternate monitoring methods, and recovery procedures remain current.
Minimum Requirements
- Bachelor’s degree in computer science, Engineering or Related Field (logic, philosophy, systemic theology or related discipline with ability to apply concepts to technology) and three or more years of experience in one or a combination of the following: information security, compliance, operational risk management (includes audit, legal, credit risk, market risk, or the management of a process or business with accountability for compliance or operational risk); or equivalent combination of education and experience.
- Four years of related experience may substitute for the education requirement.
Competencies
- Strong problem-solving skills.
- Ideal candidate prefers to work on a series of short-duration complex problems (vs. a single problem over a long period).
- Excellent written and verbal communication skills.
- Strong project management, analytical skills and administrative skills.
- Excellent organizational skills, ability to multitask and demonstrate flexibility.
- Demonstrates initiative and creativity in problem-solving; self-motivated/self-starter; works independently with minimal supervision; works well under pressure, develops strong relationships with subordinates, peers, and senior managers; demonstrates commitment and accountability.