Security Operations Center; SOC Analyst II
Listed on 2026-07-22
-
IT/Tech
Cybersecurity, Information Security, Network Security, Security Management & Operations
19-076 – Security Operations Center (SOC) Analyst II
schriever air force base, United States | Posted on 07/16/2026
Sandy Mac Evolution LLC is a Veteran-Owned company dedicated to connecting top talent with meaningful opportunities.
Job DescriptionPosition Type: Full-Time
Security Clearance: Active Top Secret/SCI Clearance Required | SAP Eligibility Required | Must Be Willing to Undergo a Counterintelligence Polygraph
Position OverviewSandy Mac Evolution LLC is seeking a highly skilled Security Operations Center (SOC) Analyst II to provide comprehensive Computer Network Defense, cybersecurity monitoring, threat analysis, and incident response support at Schriever AFB, Colorado.
The selected candidate will support continuous 24×7×365 security monitoring and analysis of potential cyber threats targeting enterprise systems and networks. The SOC Analyst will conduct security event triage, advanced analytics, threat hunting, incident investigation, malware analysis, and response activities supporting the government’s mission.
This position supports Department of Defense Special Access Programs and organizations such as Headquarters Air Force, the Office of the Secretary of Defense, and Military Department compartmented programs. The SOC Analyst will provide day-to-day cybersecurity support for Collateral, Sensitive Compartmented Information, and Special Access Program environments.
Key Responsibilities- Monitor enterprise systems, networks, applications, and security platforms for suspicious or malicious activity.
- Analyze cybersecurity alerts and information technology security events to distinguish legitimate security incidents from false positives and non-incidents.
- Lead or support incident handling activities, including detection, analysis, triage, containment, eradication, recovery, and documentation.
- Conduct proactive threat hunting to identify anomalous behaviors, malicious patterns, compromised systems, and emerging threats.
- Perform malware analysis and evaluate malicious files, behaviors, indicators, and attack techniques.
- Investigate Windows event logs, network traffic, intrusion detection alerts, endpoint telemetry, Net Flow data, and packet capture data for evidence of malicious activity.
- Use Security Information and Event Management platforms and log management systems to collect, correlate, analyze, and alert on security events.
- Develop and maintain security monitoring rules, filters, dashboards, views, signatures, scripts, countermeasures, and detection content.
- Research emerging cyber threats, attack methodologies, threat actors, campaigns, tactics, techniques, procedures, and observables.
- Recommend and implement new monitoring content, mitigating controls, and countermeasures within enterprise security tools and network environments.
- Support the development and execution of incident response procedures and cybersecurity operational workflows.
- Maintain accurate documentation and track activities through security operations workflow and ticket management systems.
- Coordinate with cybersecurity personnel, network administrators, system administrators, Information System Security Officers, and Information System Security Managers.
- Analyze network communications, routing activity, protocols, enterprise operating systems, and common internet services for indicators of compromise.
- Support cybersecurity operations involving Collateral, SCI, and SAP systems and information.
- Prepare reports, incident documentation, technical findings, and recommendations for government and program leadership.
- Ensure cybersecurity activities comply with applicable Department of Defense security policies, directives, and program requirements.
- Five to seven years of related cybersecurity, information assurance, security operations, incident response, or computer network defense experience.
- Prior experience performing in an Information System Security Officer or Information System Security Manager role.
- Strong analytical and technical skills in computer network defense and security operations.
- Demonstrated experience with cybersecurity incident detection, event analysis, triage, investigation, response, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).