Cybersecurity Analyst – Tier 2; On-Site
Listed on 2026-02-12
-
IT/Tech
Cybersecurity
The following states/districts are excluded from this job ad: AK, CA, CO, CT, DC, HI, LA, MA, MN, MO, NE, NV, NH, NJ, NM, NY, ND, OR, PR, RI, VT, WA, WY
Location(s)Hines Information Technology Center (ITC) Building 215, 1st Avenue, North of 22nd Street, Hines, Illinois 60141
OverviewAre you ready to defend critical systems against today's most advanced cyber threats? We are seeking a Cybersecurity Analyst - Tier 2 to monitor alerts, investigate incidents, and ensure swift, effective responses to protect data and systems.
Position DescriptionThe Cybersecurity Analyst - Tier 2 safeguards the Department of Veterans Affairs (VA) digital assets and responds to, investigates, and mitigates potential cyber threats.
Minimum/General Experience3 years of experience supporting incident response in an enterprise-level Security Operations Center (SOC)
Minimum EducationBachelors degree in computer science, cybersecurity, information technology or related field;
Must have or be willing to obtain one of the following certifications: GIAC Certified Incident Handler, EC-Council's Certified Incident Handler (E|CIH), GIAC Certified Incident Handler (GCIH), Incident Handling & Response Professional (IHRP), Certified Computer Security Incident Handler (CSIH), Certified Incident Handling Engineer (CIHE), EC-Council's Certified Ethical Hacker
- Above average understanding of cybersecurity principles and incident response methodologies
- Strong experience with security technologies (e.g., Security Information and Event Management (SIEM), Intrusion Detection System/Intrusion Prevention System (IDS/IPS), Endpoint Detection and Response (EDR), network monitoring tools)
- Experience with enterprise ticketing systems (e.g., Service Now)
- Ability to work independently and in a team environment to identify errors, pinpoint root causes, and devise solutions
- Ability to learn and function in multiple capacities
- Ability to be proactive in a high-pressure environment to ensure SOC operates effectively
- Excellent analytical and problem-solving skills
- Excellent verbal and written communication skills
- Ability to work third shift (10:30PM ET - 7:00AM ET) to support 24/7 cybersecurity operations
Physical Requirements
- Assignment Location(s) - Hines Information Technology Center (ITC) Building 215, 1st Avenue, North of 22nd Street, Hines, Illinois 60141
- Sedentary Work - Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects.
- Typing, communicating, repetitive motions.
- Close visual acuity to prepare and analyze data, view computer monitors and read. May need to view presentation screens and other visual aids in a virtual setting.
- Inside environmental conditions with protection from outside elements.
Ability to obtain/maintain a Federal Civilian Public Trust
- U.S. Citizenship or Permanent Resident that has lived in the United States for at least 3 years
Consists of a review of up to but not limited to:
- Covers 10 year period and in some instances lifetime events
- OPM Security Investigations Index (SII)
- DOD Defense Central Investigations Index (DCII)
- National Agency Check (NAC) records
- FBI name check
- FBI fingerprint check
- Credit report check
- Written inquiries to previous employers and references listed on the application for employment
- Potential interviews with the subject, spouse, neighbors, supervisor, coworkers
- Law enforcement check
- Court records check
- Education check
- Attendance and Degrees
- Performs real-time monitoring and triage of security alerts in Cybersecurity toolsets including SIEM and EDR
- Makes accurate determination of what alerts are false positives or require further investigation and prioritization
- Leads and actively participates in the investigation, analysis, and resolution of cybersecurity incidents
- Analyzes attack patterns, determines the root cause, and recommends appropriate remediation measures to prevent future occurrences
- Ensures accurate and detailed documentation of incident response activities, including analysis, actions taken, and lessons learned
- Collaborates…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).