579,193open jobs
24,952companies
79,803added this week
Browse all
Salary
$67k – $148k per year (Estimated)
Location
In office (McKinney)
Seniority
Junior · 2+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match

Netrio is a leading MSP in North America, specializing in IT solutions for small- to mid-market enterprises. We serve over 1,000 clients across industries with services including managed IT, cybersecurity, cloud, connectivity, voice, and custom application development.

Position Summary

The SOC Analyst II is a mid-level, hands-on investigative role responsible for deep-dive analysis, incident response, and mentorship of Tier 1 analysts within Netrio's Government SOC. This role aligns to the DoD 8140/DCWF Cyber Defense Analyst (511) work role at an intermediate proficiency level and serves as the primary escalation point for confirmed or suspected security incidents across federal and Defense Industrial Base (DIB) client environments hosted in government-authorized cloud platforms.

Key Responsibilities

  • Perform in-depth investigation of escalated alerts and incidents using SIEM/XDR and EDR platforms
  • Conduct root-cause analysis, threat correlation, and impact assessment across multi-tenant government client environments
  • Lead containment, eradication, and recovery actions for confirmed incidents per incident response playbooks
  • Own DFARS 252.204-7012 incident reporting workflow, including 72-hour DIBNet reporting coordination and 90-day data preservation requirements
  • Perform threat hunting activities across EDR, SIEM, and identity telemetry (conditional access alerts, sign-in logs)
  • Mentor and validate escalations from Tier 1 analysts; provide on-shift coaching and quality review of Tier 1 triage decisions
  • Refine and author detection use cases, correlation rules, and playbooks based on investigation findings
  • Coordinate with client points of contact during active incidents, within defined communication protocols
  • Support endpoint management (RMM) and email security investigations as they intersect with broader incidents
  • Maintain and validate chain-of-custody and evidence-handling procedures for CUI-related investigations under CMMC Level 2 / NIST SP 800-171
  • Participate in tabletop exercises, incident response plan reviews, and audit/assessment support (C3PAO readiness activities)

Required Qualifications

  • 2-5 years of experience in a SOC analyst, incident response, or threat hunting role
  • Demonstrated experience with at least one SIEM/XDR platform and one EDR platform in a production capacity
  • Solid understanding of the cyber kill chain, MITRE ATT&CK framework, and common adversary TTPs
  • Experience with log analysis, network traffic analysis, and basic malware/artifact triage
  • Strong incident documentation and client communication skills, including under time pressure
  • U.S. Citizenship (required for access to government client environments)
  • Ability to pass a background investigation as required by client contracts

Required Certifications (DoD 8140/DCWF Alignment)

CompTIA CySA+ and/or GIAC GCIH (Certified Incident Handler). GIAC GCFA (Certified Forensic Analyst) preferred, especially for candidates focused on investigation/forensics depth.

If not held at hire, required certification(s) must be obtained within the first 6 months of employment as a condition of continued assignment to government client accounts (DoD 8140 intermediate-level certification requirement).

Preferred Qualifications

  • Prior experience supporting CMMC, FedRAMP, or NIST 800-171/800-53 controlled environments
  • Experience in a multi-tenant MSSP or managed detection and response (MDR) setting
  • Scripting/automation experience (PowerShell, Python) for detection engineering or response automation
  • Familiarity with government cloud administrative constructs (e.g., GCC High, Azure Government, or equivalent)
  • Experience mentoring or leading junior analysts

Work Environment & Physical Requirements

  • Extended periods at a workstation monitoring multiple screens/dashboards and investigation tooling
  • Ability to work rotating shifts, including nights, weekends, and holidays
  • Ability to respond to off-hours pages/alerts during on-call rotation, including leading response for active incidents outside normal working hours
  • This is a 24/7 operational function - reliable attendance and shift punctuality are essential job functions

This job requisition is intended to describe the general nature of the work performed. It is not an exhaustive list of all duties, responsibilities, and qualification

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
579,193 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
McKinney
Sr SOC Analyst 1 day ago
$127k – $227k per year (Estimated) • Remote • Full-Time • 2+ years exp
Python
PowerShell
AI/ML
Prompt Engineering
AI Agents
LLM
Cybersecurity
MITRE ATT&CK
CVE
Apply
$17k – $44k per year (Estimated) • Equity • Remote/Hybrid • Full-Time • 1+ year exp • Bachelor's Degree • Bengaluru
Python
AI/ML
LLM
Red Teaming
Cybersecurity
MITRE ATT&CK
OWASP Top 10
PCI DSS
SOC 2
Apply
$86k – $197k per year (Estimated) • Remote/Hybrid • Full-Time • Melbourne
Python
PowerShell
DevOps
CI/CD
Cybersecurity
Microsoft Sentinel
Microsoft Defender
MITRE ATT&CK
Apply
$94k – $231k per year (Estimated) • Remote/Hybrid • Full-Time • Australia
Cybersecurity
MITRE ATT&CK
Apply
$75k – $114k per year • In office • Top Secret • Full-Time • 3+ years exp • Bachelor's Degree • Albuquerque • Dayton • Simi Valley • Herndon • Arlington
Python
PowerShell
Cybersecurity
Microsoft Sentinel
VirusTotal
MITRE ATT&CK
Cyber Kill Chain
KEV
Tanium
Microsoft Entra ID
Apply
$117k – $196k per year (Estimated) • Remote • Full-Time • 8+ years exp
SQL
Databases
PostgreSQL
MS SQL
Azure SQL Database
DevOps
AWS
Apply
$72k – $163k per year (Estimated) • Remote • Full-Time
Python
PowerShell
Bash
Cybersecurity
Burp Suite
Metasploit
Nmap
Nessus
Impacket
BloodHound
Hashcat
Apply
$42k – $103k per year (Estimated) • In office • Full-Time • McKinney
Apply
$58k – $139k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • McKinney
Apply
End User Engineer 27 days ago
$55k – $100k per year (Estimated) • In office • Full-Time • 5+ years exp • Belfast
DevOps
Puppet
Ansible
Chef
Azure
Cybersecurity
SOC 2
HIPAA
Microsoft Entra ID
Management
SharePoint
Apply
$32k per year • In office • Full-Time • High School Diploma • McKinney
Apply
$150k – $300k per year • In office • Full-Time • High School Diploma • McKinney
Apply
$44k – $54k per year • In office • Full-Time • McKinney
Apply
BCaBA 2 days ago
$80k – $85k per year • In office • Full-Time • McKinney
Apply
$36k – $42k per year • In office • Full-Time • McKinney
Apply
See all jobs
This is one of many
579,193 more open roles from verified company boards, updated every day.