## Position Overview
We are seeking an experienced **SOC Analyst II** to join a 24/7 Security Operations Center supporting mission-critical information systems and communications infrastructure.
The SOC Analyst II will investigate escalated security alerts, analyze advanced security data, conduct threat hunting, support incident response activities, and improve detection capabilities. The successful candidate will help protect the confidentiality, integrity, and availability of enterprise technology assets while contributing to the continuous improvement of security monitoring and response operations.
## Key Responsibilities
* Monitor enterprise networks, systems, endpoints, and security tools for suspicious or malicious activity.
* Triage security events and investigate alerts escalated within the Security Operations Center.
* Determine the scope, potential root cause, severity, and business impact of cybersecurity incidents.
* Capture, log, track, and respond to security events received through email, chat, telecommunications systems, SIEM platforms, and other security tools.
* Analyze advanced system logs, network traffic, packet captures, endpoint telemetry, and security alerts to identify indicators of compromise.
* Conduct threat-hunting activities to proactively identify security anomalies, vulnerabilities, and adversary behavior.
* Create and execute SIEM queries, reports, scripts, dashboards, and searches using current security coding and query languages.
* Tune and optimize detection rules, alerting thresholds, and correlation logic to reduce false positives and improve detection accuracy.
* Support incident containment, investigation, remediation, recovery, and resolution activities.
* Monitor external threat-intelligence sources for emerging threats, vulnerabilities, malicious indicators, and actionable security information.
* Follow established incident-response playbooks, standard operating procedures, and escalation processes.
* Create, update, and improve SOC playbooks, procedures, investigation workflows, and response documentation.
* Maintain complete and accurate documentation of incidents, investigative findings, actions taken, and resolution details.
* Participate in root-cause analysis, post-incident reviews, and lessons-learned sessions.
* Escalate complex, high-risk, or unusual security incidents to the appropriate leadership or technical teams.
* Communicate security findings clearly to technical teams, management, and other stakeholders.
* Work independently while collaborating effectively with SOC analysts, incident-response teams, network teams, and security leadership.
* Perform other related cybersecurity and monitoring duties as assigned.
## Required Qualifications
* Experience working in a Security Operations Center or similar cybersecurity monitoring environment.
* Experience investigating escalated security alerts and potential security incidents.
* Ability to create queries, reports, and scripts using SIEM query languages and security coding tools.
* Experience analyzing system logs, endpoint telemetry, network traffic, packet captures, and other security data.
* Understanding of indicators of compromise, common attack techniques, and malicious activity.
* Experience with threat hunting, incident investigation, or incident-response support.
* Knowledge of SIEM platforms, security-monitoring tools, and alert-management processes.
* Working knowledge of software-based troubleshooting and diagnostic tools.
* Ability to analyze, interpret, and correlate information from multiple technical sources.
* Strong organizational skills with the ability to prioritize multiple alerts and assignments effectively.
* Strong written and verbal communication skills.
* Ability to accurately document security incidents, investigative findings, and response activities.
* Ability to make informed and timely decisions when responding to security alerts.
* Ability to work independently and collaboratively within a team environment.
* Proficiency with Microsoft Office and standard business software.
* Ability to work full-time onsite in Harrisburg, Pennsylvania.
* Flexibility to work rotating shifts in support of 24/7/365 operations, including nights, weekends, and holidays.
* Ability to successfully complete an enhanced background check.
## Preferred Qualifications
* Experience tuning SIEM detection rules, alerts, and correlation logic.
* Experience reducing false positives and improving detection fidelity.
* Familiarity with security playbooks, standard operating procedures, and escalation workflows.
* Experience with root-cause analysis and post-incident reviews.
* Knowledge of cyber threat intelligence sources and intelligence-gathering techniques.
* Experience supporting mission-critical, government, enterprise, or highly regulated environments.
* Familiarity with scripting or automation used for security analysis and reporting.
## Ideal Candidate
The ideal candidate is a detail-oriented cybersecurity professional who can confidently investigate complex security alerts, correlate information from multiple sources, identify potential threats, and communicate findings clearly. This individual should be comfortable working in a fast-paced, shift-based SOC environment and capable of balancing independent decision-making with established escalation procedures.