Enter a job title or keyword

Tier 2 Security Operations Center (SOC) Analyst

Leidos


Job Location:

Seaside, OR - USA

Yearly Salary: USD 87100 - 157450
Posted: 4 September 2026 (15 hours ago)
Application Deadline: 2 December 2026
Vacancies: 1 Vacancy

Job Summary

Leidos is seeking an experienced Tier 2 Security Operations Center (SOC) Analyst to support the Defense Manpower Data Center (DMDC)CyberPRIMESprogram. Leidos is a major partner on the contract and will provide a substantialportionof the cybersecurity workforce supporting the Defense Human Resources Activity (DHRA) and DMDC.

The Tier 2 SOC Analyst will perform advanced analysis of cybersecurity events escalated from Tier 1 oridentifiedthrough enterprise monitoring capabilities. This position will correlate security datadeterminethe scope and potential impact of suspicious activity support incident triage and containment preserve evidence and coordinate with incident responders and other cybersecurity teams to protect DHRA systems and networks.

Work Locations:

  • Mark Center Alexandria Virginia 3 positions

  • Department of Defense Center Monterey Bay Seaside California 3 positions

Clearance: Active Secret security clearance required at time of consideration. U.S. Citizen is a must.

Mission Environment

DMDC supports the Defense Human Resources Activity within the Office of the Under Secretary of Defense for Personnel and Readiness (OUSD(P&R)) and maintains the Department of Defenses largest and most comprehensive central repository of personnel manpower casualty pay entitlement personnel security identity readiness training and related data. The DHRA Information Technology (IT) environment includes approximately 15000 network and endpoint devices supporting more than 600 Government-Off-The-Shelf (GOTS) applications and approximately 100 Risk Management Framework (RMF) authorization boundaries managed through the Enterprise Mission Assurance Support Service (eMASS). The Tier 2 SOC Analystsoperatewithin a 24x7 security operations environment responsible for detecting analyzing escalating and supporting response to cybersecurity activity affecting DHRA systems and networks. Tier 2 analysts provide the deeper technical analysiswhen events cannot be resolved throughinitialTier 1 triage.

Primary Responsibilities:

  • Perform advanced analysis of cybersecurity events escalated from Tier 1 analysts oridentifiedthrough endpoint user-activity network and other enterprise monitoring capabilities.

  • Correlate alerts security telemetry and supporting technical data todeterminethe nature scope severity and potential impact of cybersecurity activity.

  • Distinguish legitimate activity false positives policy violations suspicious behavior and potential cybersecurity incidents.

  • Determineappropriate nextactions based on approved SOC procedures playbooks and escalation criteria.

  • Recommend orinitiateauthorized actions tocontainor mitigateidentifiedthreats.

  • Support cybersecurity incident triage escalation and containment in coordination with the incident-response team.

  • Preserve relevant technical evidence and supporting information required for further investigation and incident response.

  • Document investigative actions analysis findings and conclusions in Government-approved systems.

  • Maintain complete andaccurateevent records tickets timelines and supporting evidence.

  • Contribute to required SOC event reporting and operational status information.

  • Perform Tier 2 troubleshooting of cybersecurity tools alerts security data and related technical issues.

  • Use approved Commercial-Off-The-Shelf (COTS) security-analysis tools to investigate cybersecurity events.

  • Support security testing mitigation activities and cybersecurity compliance checking as required by SOC operations.

  • Coordinate analysis with incident responders network engineers endpoint-security personnel cybersecurity-tool teams system administrators and other cybersecurity stakeholders.

  • Identifyrecurring false positives detection gaps or ineffective alerting and recommend improvements tomonitoringand detection capabilities.

  • Support tuning of cybersecurity monitoring capabilities to improve detection accuracy and analyst effectiveness.

  • Contribute to SOC procedure playbook and process improvements based on operational experience and lessons learned.

  • Support knowledge transfer across SOC analysts to improve consistent analysis and response within the 24x7 operating environment.

Basic Qualifications:

  • Bachelors degree in Cybersecurity Computer Science Information Technology Engineering or a related technical discipline and 5 or more years of relevant cybersecurity experience. Specific experience education and training may be considered in lieu of degree.

  • Experience performing cybersecurity event analysis SOC operations cyber defense incident triage or security monitoring.

  • Experience analyzing and correlating alerts from multiple cybersecurity monitoring capabilities.

  • Experience investigating endpoint network user-activity or other cybersecurity events.

  • Experiencedeterminingthe scope severity and potential impact of suspicious cybersecurity activity.

  • Experience supporting cybersecurity incident escalation containment mitigation or evidence preservation.

  • Experience using enterprise security-analysis or cybersecurity monitoring tools.

  • Experience performing Tier 2 cybersecurity troubleshooting.

  • Working knowledge of cybersecurity attack techniques network-security concepts endpoint security event analysis and incident-response processes.

  • Ability to document investigations findings actions and conclusions clearly and accurately.

  • Ability to work effectively within a team-based 24x7 security operations environment.

  • U.S. Citizenshiprequired.

  • Active Secret security clearancerequired.

Preferred Qualifications:

  • Experience supporting a Department of Defense or Federal Security Operations Center.

  • Experience working in a 24x7 SOC or Cybersecurity Service Provider environment.

  • Experience with Security Information and Event Management (SIEM) platforms and enterprise cybersecurity monitoring tools.

  • Experience analyzing endpoint network identity user-activity intrusion-detection or other cybersecurity telemetry.

  • Experience supporting cybersecurity incident response and digital-evidence preservation.

  • Experience tuning security alerts detection logic or monitoring capabilities to reduce false positives and improve detection quality.

  • Experience developing or refining SOC procedures playbooks or escalation criteria.

  • Experience with cybersecurity mitigation compliance checking or security testing.

  • Familiarity with Department of Defense cybersecurity requirements and Risk Management Framework processes.

  • Familiarity with DHRA DMDC or comparable Department of Defense enterprise environments.

If youre looking for comfort keep scrolling. At Leidos we outthink outbuild and outpace the status quo because the mission demands it. Were not hiring followers. Were recruiting the ones who disrupt provoke and refuse to fail. Step 10 is ancient history. Were already at step 30 and moving faster than anyone else dares.

Original Posting:
September 2 2026

For U.S. Positions: While subject to change based on business needs Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:
Pay Range $87100.00 - $157450.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job education experience knowledge skills and abilities as well as internal equity alignment with market data applicable bargaining agreement (if any) or other law.


Required Experience:

IC


About Company

Company Logo

Leidos is an innovation company rapidly addressing the world's most vexing challenges in national security and health. Our 47,000 employees collaborate to create smarter technology solutions for customers in these critical markets.

View Profile View Profile