Leidos logo
Leidos
Posted 13 days agoVerified live 1d ago

Tier 2 Security Operations Center (SOC) Analyst

Brief overview

Remote
UndergradOr in progress
$70k–$126k/yrStated range
2+ yrsMinimum
263 H-1B approvalsDept. of Labor
55 green cardsCertified filings
Clearance requiredU.S. government
Cybersecurity Event AnalysisSecurity Operations Center OperationsSecurity MonitoringSecurity Alert CorrelationIncident Triage and ContainmentCybersecurity Incident ResponseEndpoint and Network SecurityUser-Activity AnalysisCybersecurity Attack TechniquesDigital Evidence PreservationSecurity Information and Event Management (SIEM)Active Secret Security Clearance

About the company

A global technology and defense contractor delivering innovative solutions for national security and health.

Visa sponsorship history

4 years sponsoring, last filed FY2026

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
263H-1B approved
98%approval rate
76new H-1B hires
55PERM certified
$139,285median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
202393
202476
202584
202610
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
202329
202414
202518
202616
Green Card (PERM) FilingsCertified green card filings: a long-term commitment to international hires.
202318
202412
202519
20266
Top sponsored roles
ServiceNow DeveloperSenior Software DeveloperPublic Health AnalystSenior Java DeveloperCatalyst Synthesis Research Scientist
Sponsored employees from
IndiaEthiopiaChinaNetherlandsCanada

Job description

Summary

Leidos is a technology and mission-services company supporting government and commercial customers, including the Defense Manpower Data Center CyberPRIMES program. The Tier 2 Security Operations Center Analyst performs advanced cybersecurity event analysis, incident triage and containment, evidence preservation, troubleshooting, reporting, and coordination with cybersecurity teams in a 24x7 security operations environment.

Responsibilities

  • Perform advanced analysis of cybersecurity events escalated from Tier 1 analysts or identified through endpoint, user-activity, network, and other enterprise monitoring capabilities
  • Correlate alerts, security telemetry, and supporting technical data to determine the nature, scope, severity, and potential impact of cybersecurity activity
  • Distinguish legitimate activity, false positives, policy violations, suspicious behavior, and potential cybersecurity incidents
  • Determine appropriate next actions based on approved SOC procedures, playbooks, and escalation criteria
  • Recommend or initiate authorized actions to contain or mitigate identified threats
  • Support cybersecurity incident triage, escalation, and containment in coordination with the incident-response team
  • Preserve relevant technical evidence and supporting information required for further investigation and incident response
  • Document investigative actions, analysis, findings, and conclusions in Government-approved systems
  • Maintain complete and accurate event records, tickets, timelines, and supporting evidence
  • Contribute to required SOC event reporting and operational status information
  • Perform Tier 2 troubleshooting of cybersecurity tools, alerts, security data, and related technical issues
  • Use approved Commercial-Off-The-Shelf (COTS) security-analysis tools to investigate cybersecurity events
  • Support security testing, mitigation activities, and cybersecurity compliance checking as required by SOC operations
  • Coordinate analysis with incident responders, network engineers, endpoint-security personnel, cybersecurity-tool teams, system administrators, and other cybersecurity stakeholders
  • Identify recurring false positives, detection gaps, or ineffective alerting and recommend improvements to monitoring and detection capabilities
  • Support tuning of cybersecurity monitoring capabilities to improve detection accuracy and analyst effectiveness
  • Contribute to SOC procedure, playbook, and process improvements based on operational experience and lessons learned
  • Support knowledge transfer across SOC analysts to improve consistent analysis and response within the 24x7 operating environment

Skills

  • • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical discipline and 2-4 years of relevant cybersecurity experience or a Masters with less than 2 years. Specific experience, education and training may be considered in lieu of degree
  • • Experience performing cybersecurity event analysis, SOC operations, cyber defense, incident triage, or security monitoring
  • • Experience analyzing and correlating alerts from multiple cybersecurity monitoring capabilities
  • • Experience investigating endpoint, network, user-activity, or other cybersecurity events
  • • Experience determining the scope, severity, and potential impact of suspicious cybersecurity activity
  • • Experience supporting cybersecurity incident escalation, containment, mitigation, or evidence preservation
  • • Experience using enterprise security-analysis or cybersecurity monitoring tools
  • • Experience performing Tier 2 cybersecurity troubleshooting
  • • Working knowledge of cybersecurity attack techniques, network-security concepts, endpoint security, event analysis, and incident-response processes
  • • Ability to document investigations, findings, actions, and conclusions clearly and accurately
  • • Ability to work effectively within a team-based 24x7 security operations environment
  • • U.S. Citizenship required
  • • Active Secret security clearance required at time of consideration
  • • Experience supporting a Department of Defense or Federal Security Operations Center
  • • Experience working in a 24x7 SOC or Cybersecurity Service Provider environment
  • • Experience with Security Information and Event Management (SIEM) platforms and enterprise cybersecurity monitoring tools
  • • Experience analyzing endpoint, network, identity, user-activity, intrusion-detection, or other cybersecurity telemetry
  • • Experience supporting cybersecurity incident response and digital-evidence preservation
  • • Experience tuning security alerts, detection logic, or monitoring capabilities to reduce false positives and improve detection quality
  • • Experience developing or refining SOC procedures, playbooks, or escalation criteria
  • • Experience with cybersecurity mitigation, compliance checking, or security testing
  • • Familiarity with Department of Defense cybersecurity requirements and Risk Management Framework processes
  • • Familiarity with DHRA, DMDC, or comparable Department of Defense enterprise environments

Qualifications

Must Haves

  • • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical discipline and 2-4 years of relevant cybersecurity experience or a Masters with less than 2 years. Specific experience, education and training may be considered in lieu of degree
  • • Experience performing cybersecurity event analysis, SOC operations, cyber defense, incident triage, or security monitoring
  • • Experience analyzing and correlating alerts from multiple cybersecurity monitoring capabilities
  • • Experience investigating endpoint, network, user-activity, or other cybersecurity events
  • • Experience determining the scope, severity, and potential impact of suspicious cybersecurity activity
  • • Experience supporting cybersecurity incident escalation, containment, mitigation, or evidence preservation
  • • Experience using enterprise security-analysis or cybersecurity monitoring tools
  • • Experience performing Tier 2 cybersecurity troubleshooting
  • • Working knowledge of cybersecurity attack techniques, network-security concepts, endpoint security, event analysis, and incident-response processes
  • • Ability to document investigations, findings, actions, and conclusions clearly and accurately
  • • Ability to work effectively within a team-based 24x7 security operations environment
  • • U.S. Citizenship required
  • • Active Secret security clearance required at time of consideration

Nice to Haves

  • • Experience supporting a Department of Defense or Federal Security Operations Center
  • • Experience working in a 24x7 SOC or Cybersecurity Service Provider environment
  • • Experience with Security Information and Event Management (SIEM) platforms and enterprise cybersecurity monitoring tools
  • • Experience analyzing endpoint, network, identity, user-activity, intrusion-detection, or other cybersecurity telemetry
  • • Experience supporting cybersecurity incident response and digital-evidence preservation
  • • Experience tuning security alerts, detection logic, or monitoring capabilities to reduce false positives and improve detection quality
  • • Experience developing or refining SOC procedures, playbooks, or escalation criteria
  • • Experience with cybersecurity mitigation, compliance checking, or security testing
  • • Familiarity with Department of Defense cybersecurity requirements and Risk Management Framework processes
  • • Familiarity with DHRA, DMDC, or comparable Department of Defense enterprise environments

Benefits

  • Health and Wellness programs
  • Income Protection
  • Paid Leave
  • Retirement

More jobs like this