Demo

CSOC Cyber Incident Response Tier II Analyst

PingWind
Hines, IL Full Time
POSTED ON 4/12/2025
AVAILABLE BEFORE 6/11/2025

Location: On-site in Hines, IL Martinsburg, WV, or Austin, TX

Required Clearance: Ability to obtain Tier 4 / High Risk Background Investigation

Required Education: Bachelor's degree in computer science, Cybersecurity, Information Technology, or a related field (or equivalent work experience)

Required Experience: 3 years of experience supporting incident response in an enterprise-level Security Operations Center (SOC)


Description


PingWind is seeking a Cyber Incident Response Tier II Analyst to support our VA customer at Hines, IL Martinsburg, WV, or Austin, TX.


Certifications: Must currently have or be willing to obtain one of the following certifications (or equivalent):


• GIAC Certified Incident Handler

• EC-Council’s Certified Incident Handler (ECIH)

• GIAC Certified Incident Handler (GCIH)

• Incident Handling & Response Professional (IHRP)

• Certified Computer Security Incident Handler (CSIH)

• Certified Incident Handling Engineer (CIHE)

• EC-Council’s Certified Ethical Hacker

 

Responsibilities


• Perform real-time monitoring and triage of security alerts in Cybersecurity toolsets including SIEM, and EDR

• Make accurate determination of what alerts are false positives or require further investigation and prioritization 

• Lead and actively participate in the investigation, analysis, and resolution of cybersecurity incidents. Analyze attack patterns, determine the root cause, and recommend appropriate remediation measures to prevent future occurrences

• Ensure accurate and detailed documentation of incident response activities, including analysis, actions taken, and lessons learned. Collaborate with knowledge management teams to maintain up-to-date incident response playbooks

• Collaborate effectively with cross-functional teams, including forensics, threat intelligence, IT, and network administrators. Clearly communicate technical information and incident-related updates to management and stakeholders

• Identify and action opportunities for tuning alerts to make the incident response team more efficient 

• Monitor the performance of security analytics and automation processes regularly, identifying areas for improvement and taking proactive measures to enhance their efficacy

• Leverage Security Orchestration, Automation, and Response (SOAR) platforms to streamline and automate incident response processes, including enrichment, containment, and remediation actions

• Support the mentoring and training of more junior IR staff

• Stay informed about the latest cybersecurity threats, trends, and best practices. Actively participate in cybersecurity exercises, drills, and simulations to improve incident response capabilities


Requirements


• Work 100% on-site Tuesday through Saturday

• A deep understanding of cybersecurity principles, incident response methodologies, and a proactive mindset to ensure our SOC operates effectively in a high-pressure environment

• Strong experience with security technologies, including SIEM, IDS/IPS, EDR, and network monitoring tools

• Experience with enterprise ticketing systems like ServiceNow

• Excellent analytical and problem-solving skills

• Ability to work independently and in a team environment to identify errors, pinpoint root causes, and devise solutions with minimal oversight

• Ability to learn and function in multiple capacities and learn quickly

• Strong verbal and written communication skills


Preferred Qualifications


• Ability to investigate Indicators of Compromise (IOCs) using Splunk by correlating logs from multiple sources to detect, trace, and assess threat activity across the enterprise

• Experience leveraging Microsoft Defender for Endpoint (MDE) to perform endpoint investigations, analyze process trees, and validate IOCs during active threat scenarios

• Ability to remediate phishing incidents, including analysis of email headers, links, and attachments, identifying impacted users, and executing containment actions such as user lockouts, email quarantine, and domain blacklisting

• Experience performing root cause analysis of malware leveraging PowerShell, using tools such as MDE advanced hunting (KQL) and Splunk to identify infection paths, attacker behavior, and persistence mechanisms


About PingWind

 

PingWind is focused on delivering outstanding services to the federal government. We have extensive experience in the fields of cybersecurity, development, IT infrastructure, supply chain management and other professional services such as system design and continuous improvement. PingWind is an SBA certified Service-Disabled Veteran-Owned Small Business (SDVOSB) with offices in Northern Virginia and Huntsville AL. www.PingWind.com

 

Our benefits include:


• Paid Federal Holidays

• Robust Health & Dental Insurance Options

• 401k with matching

• Paid vacation and sick leave

• Continuing education assistance

• Short Term / Long Term Disability & Life Insurance

• Employee Assistance Program through Sun Life Financial EAP Guidance Resources

 

Veterans are encouraged to apply

 

PingWind, Inc. does not discriminate in employment opportunities, terms, and conditions of employment, or practices on the basis of race, age, gender, religious or political beliefs, national origin or heritage, disability, sexual orientation, or any characteristic protected by law


\n


\n

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a CSOC Cyber Incident Response Tier II Analyst?

Sign up to receive alerts about other jobs on the CSOC Cyber Incident Response Tier II Analyst career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$125,027 - $157,872
Income Estimation: 
$149,432 - $188,965
Income Estimation: 
$87,466 - $114,731
Income Estimation: 
$114,790 - $146,930
Income Estimation: 
$115,647 - $153,495
Income Estimation: 
$114,790 - $146,930
Income Estimation: 
$142,618 - $183,267
Income Estimation: 
$115,647 - $153,495
Income Estimation: 
$115,647 - $153,495
Income Estimation: 
$186,685 - $265,377
Income Estimation: 
$71,440 - $92,105
Income Estimation: 
$87,466 - $114,731
Income Estimation: 
$115,647 - $153,495
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at PingWind

PingWind
Hired Organization Address Hilo, HI Full Time
Description PingWind is seeking a highly skilled and experienced Tier I / II Support to join our dynamic team. As Tier I...
PingWind
Hired Organization Address Hyattsville, MD Full Time
Location : Adelphi, MD Required Clearance : Top Secret Certifications : IAM II Level; Splunk Certified Administrator Req...
PingWind
Hired Organization Address Adelphi, MD Full Time
About Our Team PingWind is a trusted partner for the federal government, delivering outstanding services in cybersecurit...
PingWind
Hired Organization Address Adelphi, MD Full Time
Job Description We are seeking a Manager of Cyber Operations to join our team. As a key member of PingWind, you will be ...

Not the job you're looking for? Here are some other CSOC Cyber Incident Response Tier II Analyst jobs in the Hines, IL area that may be a better fit.

AI Assistant is available now!

Feel free to start your new journey!