The SOC Analyst 2 performs event triage and internal SOC escalations to protect the confidentiality, integrity, and availability of the Commonwealth's information technology assets through prompt and accurate threat handling, while also identifying and closing security gaps through detection engineering, threat hunting, intelligence gathering, and investigation, thereby contributing to the continuous improvement of network and security monitoring.
Description of Duties:
Perform ongoing, on-site information security and network monitoring with proactive response for mission-critical communication sites and systems.
Capture, log, and respond to events received from email, chat, telecommunication systems, and other security systems, ensuring accurate documentation of incoming data.
Perform security investigation for alerts escalated within the Security Operation Center, determining full scope, potential root cause, and potential impact.
Follow, create, and improve established playbooks and SOPs used by the SOC.
Document security incidents, responses, and related information in accordance with established procedures.
Analyze advanced logs, network capture, end-point telemetry to identify malicious activity and indicators of compromise (IOCs).
Conduct initial threat hunting to proactively identify security anomalies and adversary activity.
Conduct tuning and optimization of existing detection rules, alerts, and correlation logic to reduce false positives and improve detection fidelity.
Participate in root cause analysis or lessons learned sessions.
Monitor external event sources for security intelligence and actionable incidents.
Provide incident response support as needed and directed during network and security events providing support for incident resolution.
Maintain flexibility to work in various shift rotations to support 24/7/365 operations, including days, nights, holidays, and weekends.
Performs other related duties as required.
Decision Making:
Make informed and timely decisions on the appropriate response to security alerts. Unique issues or problems may be escalated to supervisor. Work is reviewed periodically for adherence to established standards and established schedules.
Essential Functions:
Use personal computer/laptop with Microsoft Office products and other business software
Analyze and interpret various information
Create queries, reports and scripts leveraging current security coding and SIEM query languages
Prioritize tasks effectively.
Communicates effectively orally and in writing.
Working knowledge of troubleshooting tools (software)
Work independently and as a team member
Numbers & Facts
Location
Harrisburg, PA
Skills
Analysis Skillsunmatched
Business Solutionsunmatched
Communication Skillsunmatched
Communication Systemsunmatched
Computer Hackingunmatched
Computer Securityunmatched
Continuous Improvementunmatched
Database Programming Languagesunmatched
Documentationunmatched
Establish Prioritiesunmatched
Huntingunmatched
Incident Responseunmatched
Information Assetsunmatched
Information Technology & Information Systemsunmatched
Information/Data Security (InfoSec)unmatched
Intelligence Gatheringunmatched
Laptop PCunmatched
Microsoft Officeunmatched
Microsoft Product Familyunmatched
Network Monitoringunmatched
Network Securityunmatched
Patient Assessmentunmatched
Procedure Developmentunmatched
Root Cause Analysisunmatched
Schedule Developmentunmatched
Scripting (Scripting Languages)unmatched
Security Attacksunmatched
Security Information and Event Management (SIEM)unmatched
Security Monitoringunmatched
Software Administrationunmatched
Standard Operating Procedures (SOP)unmatched
Team Playerunmatched
Telecommunicationsunmatched
Telemetryunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.