Level 2 Cyber Security Analyst
Indexed description
Key Responsibilities
- Perform in-depth investigation of escalated alerts and incidents using SIEM/XDR and EDR platforms
- Conduct root-cause analysis, threat correlation, and impact assessment across multi-tenant government client environments
- Lead containment, eradication, and recovery actions for confirmed incidents per incident response playbooks
- Own DFARS 252.204-7012 incident reporting workflow, including 72-hour DIBNet reporting coordination and 90-day data preservation requirements
- Perform threat hunting activities across EDR, SIEM, and identity telemetry (conditional access alerts, sign-in logs)
- Mentor and validate escalations from Tier 1 analysts; provide on-shift coaching and quality review of Tier 1 triage decisions
- Refine and author detection use cases, correlation rules, and playbooks based on investigation findings
- Coordinate with client points of contact during active incidents, within defined communication protocols
- Support endpoint management (RMM) and email security investigations as they intersect with broader incidents
- Maintain and validate chain-of-custody and evidence-handling procedures for CUI-related investigations under CMMC Level 2 / NIST SP 800-171
- Participate in tabletop exercises, incident response plan reviews, and audit/assessment support (C3PAO readiness activities)
- 2–5 years of experience in a SOC analyst, incident response, or threat hunting role
- Demonstrated experience with at least one SIEM/XDR platform and one EDR platform in a production capacity
- Solid understanding of the cyber kill chain, MITRE ATT&CK framework, and common adversary TTPs
- Experience with log analysis, network traffic analysis, and basic malware/artifact triage
- Strong incident documentation and client communication skills, including under time pressure
- U.S. Citizenship (required for access to government client environments)
- Ability to pass a background investigation as required by client contracts
If not held at hire, required certification(s) must be obtained within the first 6 months of employment as a condition of continued assignment to government client accounts (DoD 8140 intermediate-level certification requirement).
Preferred Qualifications
- Prior experience supporting CMMC, FedRAMP, or NIST 800-171/800-53 controlled environments
- Experience in a multi-tenant MSSP or managed detection and response (MDR) setting
- Scripting/automation experience (PowerShell, Python) for detection engineering or response automation
- Familiarity with government cloud administrative constructs (e.g., GCC High, Azure Government, or equivalent)
- Experience mentoring or leading junior analysts
- Extended periods at a workstation monitoring multiple screens/dashboards and investigation tooling
- Ability to work rotating shifts, including nights, weekends, and holidays
- Ability to respond to off-hours pages/alerts during on-call rotation, including leading response for active incidents outside normal working hours
- This is a 24/7 operational function — reliable attendance and shift punctuality are essential job functions
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search