Enter a job title or keyword

CSOC CIR Tier II Analyst

PingWind


Job Location:

Martinsburg, PA - USA

Monthly Salary: $ 79 - 110
Posted: 27 August 2026 (6 days ago)
Application Deadline: 24 November 2026
Vacancies: 1 Vacancy

Job Summary

Location: On-site in Hines IL Martinsburg WV or Austin TX
Required Clearance:
Ability to obtain Tier 4 / High Risk Background Investigation
Required Education:
Bachelors degree in computer science Cybersecurity Information Technology or a related field (or equivalent work experience)
Required Experience:
3 years of experience supporting incident response in an enterprise-level Security Operations Center (SOC)

Description

PingWind is seeking a Cyber Incident Response Tier II Analyst to support our VA customer at Hines IL Martinsburg WV or Austin TX.

Certifications: Must currently have or be willing to obtain one of the following certifications (or equivalent):

  • GIAC Certified Incident Handler
  • EC-Councils Certified Incident Handler (ECIH)
  • GIAC Certified Incident Handler (GCIH)
  • Incident Handling & Response Professional (IHRP)
  • Certified Computer Security Incident Handler (CSIH)
  • Certified Incident Handling Engineer (CIHE)
  • EC-Councils Certified Ethical Hacker

Responsibilities

  • Perform real-time monitoring and triage of security alerts in Cybersecurity toolsets including SIEM and EDR
  • Make accurate determination of what alerts are false positives or require further investigation and prioritization
  • Lead and actively participate in the investigation analysis and resolution of cybersecurity incidents. Analyze attack patterns determine the root cause and recommend appropriate remediation measures to prevent future occurrences
  • Ensure accurate and detailed documentation of incident response activities including analysis actions taken and lessons learned. Collaborate with knowledge management teams to maintain up-to-date incident response playbooks
  • Collaborate effectively with cross-functional teams including forensics threat intelligence IT and network administrators. Clearly communicate technical information and incident-related updates to management and stakeholders
  • Identify and action opportunities for tuning alerts to make the incident response team more efficient
  • Monitor the performance of security analytics and automation processes regularly identifying areas for improvement and taking proactive measures to enhance their efficacy
  • Leverage Security Orchestration Automation and Response (SOAR) platforms to streamline and automate incident response processes including enrichment containment and remediation actions
  • Support the mentoring and training of more junior IR staff
  • Stay informed about the latest cybersecurity threats trends and best practices. Actively participate in cybersecurity exercises drills and simulations to improve incident response capabilities

Requirements

  • Work 100% on-site Monday Friday from 11:00 PM to 7:00 AM.
  • A deep understanding of cybersecurity principles incident response methodologies and a proactive mindset to ensure our SOC operates effectively in a high-pressure environment
  • Strong experience with security technologies including SIEM IDS/IPS EDR and network monitoring tools
  • Experience with enterprise ticketing systems like ServiceNow
  • Excellent analytical and problem-solving skills
  • Ability to work independently and in a team environment to identify errors pinpoint root causes and devise solutions with minimal oversight
  • Ability to learn and function in multiple capacities and learn quickly
  • Strong verbal and written communication skills

Preferred Qualifications

  • Ability to investigate Indicators of Compromise (IOCs)using Splunk by correlating logs from multiple sources to detect trace and assess threat activity across the enterprise
  • Experience leveraging Microsoft Defender for Endpoint (MDE)to perform endpoint investigations analyze process trees and validate IOCs during active threat scenarios
  • Ability to remediate phishing incidents including analysis of email headers links and attachments identifying impacted users and executing containment actions such as user lockouts email quarantine and domain blacklisting
  • Experience performing root cause analysis of malware leveraging PowerShell using tools such as MDE advanced hunting (KQL) and Splunk to identify infection paths attacker behavior and persistence mechanisms

About PingWind

PingWind is focused on delivering outstanding services to the federal government. We have extensive experience in the fields of cybersecurity development IT infrastructure supply chain management and other professional services such as system design and continuous improvement. PingWind is an SBA certified Service-Disabled Veteran-Owned Small Business (SDVOSB) with offices in Northern Virginia and Huntsville AL.

Our benefits include:

Eleven Federal Holidays
Paid Time Off accrued each pay period
Parental Leave
Three medical plan choices with generous employer contribution
Dental and Vision Insurance
Company paid Short-Term and Long-Term Disability
Company paid Life and AD&D Insurance
401k with competitive matching and vesting schedule
Continuing education assistance
Short Term / Long Term Disability & Life Insurance
Medical Dependent Care and Commuter Flexible Spending Accounts
Employee Assistance Program
Wellness benefits include Calm Health app and WellHub gym subsidy (formerly GymPass)
529 College Savings Plan
Legal Insurance
Pet Insurance

Salary Range

$79k-$110k

The pay range for this job is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) job responsibilities education certifications experience as well as internal equity mapping and alignment with market data or other applicable laws.

Veterans are encouraged to apply

PingWind Inc. does not discriminate in employment opportunities terms and conditions of employment or practices on the basis of race age gender religious or political beliefs national origin or heritage disability sexual orientation or any characteristic protected by law.

We may use artificial intelligence (AI) tools to support parts of the hiring process such as reviewing applications analyzing resumes or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed please contact us.

Required Experience:

IC