ECS

SOC Tier 2 Analyst

ECS  •  Portland, OR (Onsite)  •  7 days ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Everforth ECS is seeking a SOC Tier 2 Analyst to work in our Portland, OR office. Please Note: This position is contingent upon contract award.

The SOC Analyst 2 supports the organization's security operations by conducting deeper investigation of escalated alerts, correlating security telemetry, supporting incident response activities, and preparing incident summaries and recommendations. This role is the mid-level investigation and response-support tier within the SOC Analyst role family.

The ideal candidate has hands-on SOC or security operations experience, understands common attack techniques and defensive technologies, and can independently investigate security events while coordinating with SOC Analyst 1, SOC Analyst 3, threat intelligence, threat hunting, forensics, engineering, and business stakeholders.

Key Responsibilities

Escalated Alert Investigation & Correlation

  • Review and investigate alerts escalated by SOC Analyst 1 or automated SOC workflows to validate severity, scope, potential impact, and required response actions.
  • Analyze suspicious activity, indicators of compromise, anomalous behavior, and policy violations using logs, endpoint telemetry, network data, identity data, cloud events, and other evidence.
  • Correlate evidence across security platforms to identify affected assets, affected accounts, attack paths, timeline of activity, and potential business or mission impact.
  • Map observed behaviors to applicable frameworks and threat models such as MITRE ATT&CK when useful for investigation, reporting, or detection improvement.

Incident Response & Coordination Support

  • Support containment, eradication, and recovery activities for standard or moderate incidents in alignment with incident response plans and approved playbooks.
  • Coordinate with system owners, security engineers, senior analysts, and other technical teams to gather evidence, validate impact, and support response actions.
  • Escalate complex, high-impact, evidence-sensitive, or ambiguous incidents to SOC Analyst 3, SOC leadership, Forensics, Threat Hunter, Threat Intelligence Analyst, or other specialized roles as appropriate
  • Maintain accurate incident status, action tracking, and communications during investigation and response activities.

Detection, Tuning & Process Improvement Input

  • Analyze recurring alerts, false positives, attack patterns, threat intelligence, vulnerabilities, and emerging tactics to identify opportunities to improve detection and response.
  • Recommend updates to correlation rules, alert logic, dashboards, use cases, response playbooks, and triage procedures based on investigation outcomes.
  • Operationalize threat intelligence in triage and investigation workflows by applying relevant indicators, adversary behaviors, vulnerabilities, and contextual reporting.
  • Provide operational requirements and validation feedback to SOC Analyst 3, SOC Threat Hunter, Senior Splunk Engineer, Splunk Architect/Lead, Security Engineer, and SOC Technical Writer as appropriate

Reporting & Documentation

  • Document investigation activities, evidence, decisions, response actions, and outcomes clearly and accurately.
  • Prepare incident summaries, ticket updates, timelines, shift handoff notes, and supporting information for after-action documentation.
  • Communicate technical findings in clear operational, business, and risk language for SOC leadership and affected stakeholders.
  • Provide evidence summaries and analysis notes that can be used by Forensics or specialized teams when deeper analysis is required

Mentorship & Continuous Improvement

  • Provide escalation guidance, quality feedback, and informal mentoring to SOC Analyst 1 personnel.
  • Participate in lessons-learned activities, tabletop exercises, detection reviews, and SOC process improvement efforts.
  • Stay current with evolving cyber threats, vulnerabilities, detection techniques, and security operations best practices.
  • Contribute to continuous improvement of SOC workflows, investigation checklists, documentation practices, and escalation procedures.

Qualifications

  • 3-5 years of experience in SOC operations, incident response, security monitoring, threat monitoring, or related technical cybersecurity roles.
  • Experience triaging escalated alerts and investigating security events using SIEM, EDR, ticketing, case management, and log analysis tools.
  • Intermediate knowledge of Windows, Linux, networking, cloud, identity, endpoint, and application security concepts.
  • Working knowledge of common attack techniques, incident response lifecycle activities, escalation procedures, playbooks, and evidence-handling practices.
  • Ability to correlate evidence across multiple tools, develop incident timelines, and determine recommended response actions.
  • Strong analytical, written documentation, communication, and collaboration skills, including the ability to guide SOC Analyst 1 personnel.
ECS

About ECS

ECS is a fast-growing 4,000-person, $1.2B provider of advanced technology solutions for federal civilian, defense, intelligence, and commercial customers. We tackle complex client challenges with smart, scalable solutions in data and AI, cybersecurity, and digital transformation. Our collective work empowers customers’ missions, strengthens our partners, inspires our employees, and grows our company.

To achieve our purpose — to tackle the missions that matter most and create a lasting impact on our customers, employees, and community — we are committed to excellence in growth, customer delivery, technology innovation, and employee engagement.  

We believe in:

• Attracting, developing, and retaining top talent

• Building high-performing teams

• Creating an engaging employee environment

• Acting with social responsibility

• Having a positive impact on our community

Our core values: Excellence, Drive, Grit, and Community. We keep these values at the heart of all we do. We’re looking for driven individuals who want to solve meaningful challenges and help shape the future of national security and public service. If you’re ready to make a difference, you’ll find your team here.

Industry
IT & Software
Company Size
1,001-5,000 employees
Headquarters
Fairfax, VA
Year Founded
1993
Social Media