Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Leidos

Tier 2 Security Operations Center (SOC) Analyst

Leidos

. Perform advanced analysis of cybersecurity events escalated from Tier 1 analysts or identified through enterprise monitoring capabilities .

Posted 9/23/2026full-timeUnited StatesMid-LevelSenior💰 $87,100 - $157,450 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in cybersecurity event analysis, incident response, and the use of security-analysis tools. Proficient in documenting findings and collaborating effectively in a 24x7 security operations environment.

Highest-signal resume keywords
Cybersecurity Event AnalysisIncident Response SupportSecurity Monitoring ToolsTier 2 Cybersecurity TroubleshootingDocumentation of Investigations

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Cybersecurity AnalysisIncident TriageThreat MitigationSecurity Telemetry CorrelationEndpoint Security InvestigationNetwork Security ConceptsCybersecurity Attack TechniquesEvent AnalysisSecurity Compliance CheckingSecurity Alert Tuning
Soft Skills
Team CollaborationEffective CommunicationAttention to Detail
Tools & Technologies
COTS Security-Analysis ToolsSIEM PlatformsCybersecurity Monitoring Tools
Certifications & Qualifications
Active Secret Security Clearance
Industry Keywords
SOC OperationsDepartment of DefenseRisk Management FrameworkCybersecurity Service ProviderDigital Evidence Preservation

Tech Stack

Tools & technologies
Cyber Security

About the role

Key responsibilities & impact
  • Perform advanced analysis of cybersecurity events escalated from Tier 1 analysts or identified through enterprise monitoring capabilities
  • Correlate alerts, security telemetry, and technical data to determine the nature, scope, severity, and potential impact of cybersecurity activity
  • Distinguish legitimate activity, false positives, policy violations, suspicious behavior, and potential cybersecurity incidents
  • Determine appropriate next actions using approved SOC procedures, playbooks, and escalation criteria
  • Recommend or initiate authorized actions to contain or mitigate identified threats
  • Support incident triage, escalation, and containment with the incident-response team
  • Preserve technical evidence for investigation and incident response
  • Document investigative actions, findings, and conclusions in Government-approved systems
  • Maintain event records, tickets, timelines, and supporting evidence
  • Contribute to SOC event reporting and operational status information
  • Perform Tier 2 troubleshooting of cybersecurity tools, alerts, security data, and related technical issues
  • Use approved COTS security-analysis tools to investigate cybersecurity events
  • Support security testing, mitigation activities, and cybersecurity compliance checking
  • Coordinate analysis with incident responders, network engineers, endpoint-security personnel, cybersecurity-tool teams, system administrators, and other stakeholders
  • Identify recurring false positives, detection gaps, or ineffective alerting and recommend monitoring improvements
  • Support tuning of cybersecurity monitoring capabilities
  • Contribute to SOC procedures, playbooks, and process improvements
  • Support knowledge transfer across SOC analysts in the 24x7 operating environment

Requirements

What you’ll need
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical discipline and 5 or more years of relevant cybersecurity experience; specific experience, education and training may be considered in lieu of degree
  • Experience performing cybersecurity event analysis, SOC operations, cyber defense, incident triage, or security monitoring
  • Experience analyzing and correlating alerts from multiple cybersecurity monitoring capabilities
  • Experience investigating endpoint, network, user-activity, or other cybersecurity events
  • Experience determining the scope, severity, and potential impact of suspicious cybersecurity activity
  • Experience supporting cybersecurity incident escalation, containment, mitigation, or evidence preservation
  • Experience using enterprise security-analysis or cybersecurity monitoring tools
  • Experience performing Tier 2 cybersecurity troubleshooting
  • Working knowledge of cybersecurity attack techniques, network-security concepts, endpoint security, event analysis, and incident-response processes
  • Ability to document investigations, findings, actions, and conclusions clearly and accurately
  • Ability to work effectively within a team-based 24x7 security operations environment
  • U.S. Citizenship required
  • Active Secret security clearance required at time of consideration
  • Preferred: experience supporting a Department of Defense or Federal Security Operations Center
  • Preferred: experience working in a 24x7 SOC or Cybersecurity Service Provider environment
  • Preferred: experience with SIEM platforms and enterprise cybersecurity monitoring tools
  • Preferred: experience analyzing endpoint, network, identity, user-activity, intrusion-detection, or other cybersecurity telemetry
  • Preferred: experience supporting cybersecurity incident response and digital-evidence preservation
  • Preferred: experience tuning security alerts, detection logic, or monitoring capabilities
  • Preferred: experience developing or refining SOC procedures, playbooks, or escalation criteria
  • Preferred: experience with cybersecurity mitigation, compliance checking, or security testing
  • Preferred: familiarity with Department of Defense cybersecurity requirements and Risk Management Framework processes
  • Preferred: familiarity with DHRA, DMDC, or comparable Department of Defense enterprise environments