Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Sentinel Blue

SOC Analyst II

Sentinel Blue

. Serve as the primary escalation point for Tier I analysts .

Posted 10/7/2026full-timeRemote • United StatesJuniorMid-Level💰 $70,000 - $80,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in incident response, threat hunting, and vulnerability management, with a strong ability to analyze and mitigate security incidents using advanced technical skills and tools. Proficient in developing incident response playbooks and providing guidance to junior analysts while managing critical security alerts.

Highest-signal resume keywords
Incident Response ManagementThreat HuntingVulnerability ManagementPython ScriptingSIEM Platform Experience

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Windows OS InternalsTCP/IPDNSHTTPSSL/TLSPowerShell ScriptingMalicious Script DetectionCode Injection TechniquesCyber Kill ChainMITRE ATT&CK Framework
Soft Skills
LeadershipMentoringCollaborationCommunication
Tools & Technologies
Microsoft SentinelELK/Elastic StackSplunkSysinternals SuiteVolatilitySIFT WorkstationCyberChefWiresharkMalware Analysis SandboxesGhidra
Certifications & Qualifications
GCIHGCIAGCFAOSCPBTL2
Industry Keywords
Security Operations CenterIncident Response PlansThreat IntelligenceDigital ForensicsCapture-the-Flag Events

Tech Stack

Tools & technologies
AssemblyAzureDNSPythonSplunkSQLiteTCP/IP

About the role

Key responsibilities & impact
  • Serve as the primary escalation point for Tier I analysts
  • Take ownership of critical/high-severity alerts and escalated security incidents
  • Analyze endpoints, network traffic, and log data to validate incidents and perform root cause analysis
  • Lead containment, eradication, and recovery during active security incidents
  • Follow and document Standard Operating Procedures and Incident Response Plans
  • Reconstruct attack chains using the MITRE ATT&CK Framework and Cyber Kill Chain
  • Conduct intelligence- and hypothesis-driven threat hunts
  • Write executive reports with clear narratives, detailed analysis, and actionable recommendations
  • Manage the vulnerability management lifecycle, including scan analysis, risk-based prioritization, and remediation coordination
  • Develop and maintain incident response playbooks and SOPs
  • Provide technical guidance, training, and feedback to Tier 1 analysts
  • Participate in an on-call rotation for critical incidents outside standard business hours
  • Collaborate with and mentor junior staff
  • Help advance capabilities in digital forensics and incident response, threat hunting, vulnerability management, and threat intelligence

Requirements

What you’ll need
  • U.S. citizenship
  • Must be eligible for a Secret clearance
  • Minimum of 2–5 years of experience in a Security Operations Center and/or cyber-adjacent or IT administration roles
  • Intermediate to advanced understanding of Windows OS internals, including Event Tracing for Windows, Win32 API, Registry, Memory, and Process operations
  • Intermediate to advanced understanding of TCP/IP, DNS, HTTP, SSL/TLS, and other common network protocols
  • Intermediate to advanced ability to write and interpret Python or PowerShell scripts
  • Ability to manage Windows devices via command line using PowerShell or Batch
  • Ability to detect and reverse engineer malicious scripts or other high-level languages
  • Understanding of code injection and attack/evasion techniques related to Windows
  • Prior experience with SIEM platforms such as Microsoft Sentinel, ELK/Elastic Stack, or Splunk
  • Hands-on experience with Sysinternals Suite, Volatility, SIFT Workstation, CyberChef, Forensic Browser for SQLite, Velociraptor, Explorer Suite, Wireshark, and malware analysis sandboxes, or equivalent tools
  • Familiarity with malware development, social engineering, phishing, exploitation, persistence, evasion, credential theft, C2, exfiltration, and lateral movement
  • Intermediate to advanced certification such as GCIH/GCIA/GCFA, OSCP, BTL2, or equivalent is highly desired
  • Previous team lead or supervisory leadership experience is desired
  • Experience with Azure, Microsoft Sentinel/Defender XDR, Entra ID, and Kusto Query Language (KQL) is desired
  • Active participation in Capture-the-Flag events and homelabbing is a plus
  • Understanding of x64 assembly, Windows data structures, and undocumented parts of Windows OS is desired
  • Familiarity with low-level reverse engineering and debugging tools such as Ghidra, x64dbg, and IDA is desired
  • Must participate in an on-call rotation

Benefits

Comp & perks
  • Fully paid individual healthcare, vision and dental insurance for the employee
  • Paid certification and training opportunities
  • Three weeks of paid vacation
  • 11 paid holidays
  • Supportive environment with a focus on keeping healthy work-life balance
  • Retirement benefit (401k) with company match
  • Potential transition into a team leadership role
  • Exposure to new and emerging technologies
  • Fun, dynamic environment working on interesting problems