Government Careers
  • CSOC CIR Tier II Analyst with Security Clearance

  • PingWind
  • Charmco, West Virginia 25958 United States View Map

LocationOn‑site in Hines, IL, Martinsburg, WV, or Austin, TXRequired ClearanceAbility to obtain Tier 4 / High Risk Background InvestigationRequired EducationBachelor's degree in computer science, Cybersecurity, Information Technology, or a related field (or equivalent work experience)Required Experience3+ years of experience supporting incident response in an enterprise-level Security Operations Center (SOC)CertificationsGIAC Certified Incident HandlerEC-Council's Certified Incident Handler (ECIH)GIAC Certified Incident Handler (GCIH)Incident Handling & Response Professional (IHRP)Certified Computer Security Incident Handler (CSIH)Certified Incident Handling Engineer (CIHE)EC-Council's Certified Ethical HackerResponsibilitiesPerform real‑time monitoring and triage of security alerts in cybersecurity toolsets including SIEM, and EDRDetermine accurately whether alerts are false positives or warrant further investigation and prioritizationLead and actively participate in the investigation, analysis, and resolution of cybersecurity incidents; analyze attack patterns, determine the root cause, and recommend appropriate remediation to prevent future occurrencesEnsure accurate and detailed documentation of incident‑response activities, including analysis, actions taken, and lessons learned; collaborate with knowledge‑management teams to maintain up‑to‑date playbooksCollaborate effectively with cross‑functional teams, including forensics, threat intelligence, IT, and network administrators; clearly communicate technical information and incident‑related updates to management and stakeholdersIdentify and act on opportunities to tune alerts, improving the efficiency of the incident‑response teamMonitor the performance of security analytics and automation processes, identifying improvement areas and taking proactive measuresLeverage Security Orchestration, Automation, and Response (SOAR) platforms to streamline and automate incident‑response processes, including enrichment, containment, and remediation actionsMentor and train junior IR staffStay informed about the latest cybersecurity threats, trends, and best practices; actively participate in exercises, drills, and simulations to enhance capabilitiesRequirementsWork 100% on‑site Monday - Friday from 11:00 PM to 7:00 AMDeep understanding of cybersecurity principles and incident‑response methodologies; proactive mindset in a high‑pressure SOC environmentStrong experience with security technologies, including SIEM, IDS/IPS, EDR, and network monitoring toolsExperience with enterprise ticketing systems like ServiceNowExcellent analytical and problem‑solving skillsAbility to work independently and in a team to identify errors, pinpoint root causes, and devise solutions with minimal oversightCapacity to learn quickly and function in multiple capacitiesStrong verbal and written communication skillsPreferred QualificationsInvestigate indicators of compromise (IOCs) using Splunk, correlating logs from multiple sources to detect, trace, and assess enterprise‑wide threat activityLeverage Microsoft Defender for Endpoint (MDE) for endpoint investigations, process‑tree analysis, and IOC validation during active threat scenariosRemediate phishing incidents, including analysis of email headers, links, and attachments; identify impacted users and execute containment actions such as user lockouts, email quarantine, and domain blacklistingPerform root‑cause analysis of malware using PowerShell, MDE advanced hunting (KQL), and Splunk to identify infection paths, attacker behavior, and persistence mechanismsBenefitsEleven Federal HolidaysPaid Time Off accrued each pay periodParental LeaveThree medical plan choices with generous employer contributionDental and Vision InsuranceCompany‑paid Short‑Term and Long‑Term DisabilityCompany‑paid Life and AD&D Insurance401(k) with competitive matching and vesting scheduleContinuing education assistanceShort Term / Long Term Disability & Life InsuranceMedical, Dependent Care and Commuter Flexible Spending AccountsEmployee Assistance ProgramWellness benefits include Calm Health app and WellHub gym subsidy (formerly GymPass)529 College Savings PlanLegal InsurancePet InsuranceSalary Range $79k–$110kEqual Opportunity EmploymentPingWind, Inc. does not discriminate in employment opportunities, terms, and conditions of employment, or practices on the basis of race, age, gender, religious or political beliefs, national origin or heritage, disability, sexual orientation, or any characteristic protected by law.#J-18808-Ljbffr

LocationOn‑site in Hines, IL, Martinsburg, WV, or Austin, TXRequired ClearanceAbility to obtain Tier 4 / High Risk Background InvestigationRequired EducationBachelor's degree in computer science, Cybersecurity, Information Technology, or a related field (or equivalent work experience)Required Experience3+ years of experience supporting incident response in an enterprise-level Security Operations Center (SOC)CertificationsGIAC Certified Incident HandlerEC-Council's Certified Incident Handler (ECIH)GIAC Certified Incident Handler (GCIH)Incident Handling & Response Professional (IHRP)Certified Computer Security Incident Handler (CSIH)Certified Incident Handling Engineer (CIHE)EC-Council's Certified Ethical HackerResponsibilitiesPerform real‑time monitoring and triage of security alerts in cybersecurity toolsets including SIEM, and EDRDetermine accurately whether alerts are false positives or warrant further investigation and prioritizationLead and actively participate in the investigation, analysis, and resolution of cybersecurity incidents; analyze attack patterns, determine the root cause, and recommend appropriate remediation to prevent future occurrencesEnsure accurate and detailed documentation of incident‑response activities, including analysis, actions taken, and lessons learned; collaborate with knowledge‑management teams to maintain up‑to‑date playbooksCollaborate effectively with cross‑functional teams, including forensics, threat intelligence, IT, and network administrators; clearly communicate technical information and incident‑related updates to management and stakeholdersIdentify and act on opportunities to tune alerts, improving the efficiency of the incident‑response teamMonitor the performance of security analytics and automation processes, identifying improvement areas and taking proactive measuresLeverage Security Orchestration, Automation, and Response (SOAR) platforms to streamline and automate incident‑response processes, including enrichment, containment, and remediation actionsMentor and train junior IR staffStay informed about the latest cybersecurity threats, trends, and best practices; actively participate in exercises, drills, and simulations to enhance capabilitiesRequirementsWork 100% on‑site Monday - Friday from 11:00 PM to 7:00 AMDeep understanding of cybersecurity principles and incident‑response methodologies; proactive mindset in a high‑pressure SOC environmentStrong experience with security technologies, including SIEM, IDS/IPS, EDR, and network monitoring toolsExperience with enterprise ticketing systems like ServiceNowExcellent analytical and problem‑solving skillsAbility to work independently and in a team to identify errors, pinpoint root causes, and devise solutions with minimal oversightCapacity to learn quickly and function in multiple capacitiesStrong verbal and written communication skillsPreferred QualificationsInvestigate indicators of compromise (IOCs) using Splunk, correlating logs from multiple sources to detect, trace, and assess enterprise‑wide threat activityLeverage Microsoft Defender for Endpoint (MDE) for endpoint investigations, process‑tree analysis, and IOC validation during active threat scenariosRemediate phishing incidents, including analysis of email headers, links, and attachments; identify impacted users and execute containment actions such as user lockouts, email quarantine, and domain blacklistingPerform root‑cause analysis of malware using PowerShell, MDE advanced hunting (KQL), and Splunk to identify infection paths, attacker behavior, and persistence mechanismsBenefitsEleven Federal HolidaysPaid Time Off accrued each pay periodParental LeaveThree medical plan choices with generous employer contributionDental and Vision InsuranceCompany‑paid Short‑Term and Long‑Term DisabilityCompany‑paid Life and AD&D Insurance401(k) with competitive matching and vesting scheduleContinuing education assistanceShort Term / Long Term Disability & Life InsuranceMedical, Dependent Care and Commuter Flexible Spending AccountsEmployee Assistance ProgramWellness benefits include Calm Health app and WellHub gym subsidy (formerly GymPass)529 College Savings PlanLegal InsurancePet InsuranceSalary Range $79k–$110kEqual Opportunity EmploymentPingWind, Inc. does not discriminate in employment opportunities, terms, and conditions of employment, or practices on the basis of race, age, gender, religious or political beliefs, national origin or heritage, disability, sexual orientation, or any characteristic protected by law.#J-18808-Ljbffr

Government Careers

Government Careers

Government jobs offer stability, competitive benefits, and the chance to make a meaningful impact on your community and country.

Whether you’re starting your career or seeking new opportunities, these roles provide pathways for growth, security, and service.

Explore positions across a wide range of fields and take the first step toward a rewarding future in public service.

Show more

MORE JOBS