Role: SOC Analyst 2 Location: Harrisburg PA (Onsite Only Role) We are seeking an experienced SOC Analyst 2 to support Security Operations Center (SOC) activities and help protect the confidentiality, integrity, and availability of the Commonwealth's information technology assets. This position is responsible for security event triage, investigation, escalation, threat detection, and incident response while contributing to the continuous improvement of network and security monitoring capabilities. The SOC Analyst will investigate security alerts, analyze network and endpoint telemetry, identify indicators of compromise, conduct threat hunting, and improve detection rules and SOC processes. The ideal candidate will have hands-on experience working within a Security Operations Center and be comfortable supporting a 24/7/365 operational environment. Key Responsibilities Perform continuous information security and network monitoring and proactively respond to potential threats affecting mission-critical systems and communication environments. Triage, capture, document, and respond to security events received through SIEM platforms, email, chat, telecommunications, and other security systems. Investigate alerts escalated within the SOC to determine scope, potential root cause, impact, and appropriate response. Analyze advanced security logs, network packet captures, endpoint telemetry, and other security data to identify malicious activity and Indicators of Compromise (IOCs). Conduct initial threat-hunting activities to proactively identify security anomalies, suspicious behavior, and potential adversary activity. Tune and optimize existing detection rules, alerts, and correlation logic to reduce false positives and improve detection accuracy and fidelity. Monitor external intelligence sources for emerging threats, vulnerabilities, IOCs, and actionable security information. Provide incident response support during network and cybersecurity events and assist with containment, investigation, remediation, and resolution. Participate in root-cause analysis and lessons-learned sessions following security incidents. Follow established SOC playbooks and Standard Operating Procedures (SOPs) and contribute to their development and continuous improvement. Maintain accurate documentation of security incidents, investigations, response activities, findings, and resolutions. Develop queries, reports, and scripts using applicable security coding and SIEM query languages. Escalate unique, complex, or high-risk security incidents to appropriate leadership or senior SOC personnel. Collaborate effectively with security, network, infrastructure, and other technical teams during investigations and incident response. Support continuous improvement of SOC monitoring, detection, investigation, and response capabilities.
|