Skip to content

Open nowPosted today

Tier 2 Security Operations Center (SOC) Analyst

Leidos993 open roles

Where
Alexandria, VA
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowTier 2 Security Operations Center (SOC) AnalystLeidos · Alexandria, VA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Leidos's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Leidos postings stay open a median of 4 days.

Share of postings closed within
  1. 1.9%1 day
  2. 3.8%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.1%30 days
This job: posted today

Leidos median: 4 days open

The posting

Leidos is seeking experienced Tier 2 Security Operations Center (SOC) Analysts to support the Defense Manpower Data Center (DMDC) CyberPRIMES program. Leidos is a major partner on the contract and will provide a substantial portion of the cybersecurity workforce supporting the Defense Human Resources Activity (DHRA) and DMDC.

The Tier 2 SOC Analyst will perform advanced analysis of cybersecurity events escalated from Tier 1 or identified through enterprise monitoring capabilities. This position will correlate security data, determine the scope and potential impact of suspicious activity, support incident triage and containment, preserve evidence, and coordinate with incident responders and other cybersecurity teams to protect DHRA systems and networks.

Work Locations:

Mission Environment

DMDC supports the Defense Human Resources Activity within the Office of the Under Secretary of Defense for Personnel and Readiness (OUSD(P&R)) and maintains the Department of Defense’s largest and most comprehensive central repository of personnel, manpower, casualty, pay, entitlement, personnel security, identity, readiness, training, and related data. The DHRA Information Technology (IT) environment includes approximately 15,000 network and endpoint devices supporting more than 600 Government-Off-The-Shelf (GOTS) applications and approximately 100 Risk Management Framework (RMF) authorization boundaries managed through the Enterprise Mission Assurance Support Service (eMASS).

The Tier 2 SOC Analysts operate within a 24x7 security operations environment responsible for detecting, analyzing, escalating, and supporting response to cybersecurity activity affecting DHRA systems and networks. Tier 2 analysts provide the deeper technical analysis required when events cannot be resolved through I

Initial Tier 1 triage.

Primary Responsibilities

  • Perform advanced analysis of cybersecurity events escalated from Tier 1 analysts or identified through endpoint, user-activity, network, and other enterprise monitoring capabilities.
  • Correlate alerts, security telemetry, and supporting technical data to determine the nature, scope, severity, and potential impact of cybersecurity activity.
  • Distinguish legitimate activity, false positives, policy violations, suspicious behavior, and potential cybersecurity incidents.
  • Determine appropriate next actions based on approved SOC procedures, playbooks, and escalation criteria.
  • Recommend or initiate authorized actions to contain or mitigate identified threats.
  • Support cybersecurity incident triage, escalation, and containment in coordination with the incident-response team.
  • Preserve relevant technical evidence and supporting information required for further investigation and incident response.
  • Document investigative actions, analysis, findings, and conclusions in Government-approved systems.
  • Maintain complete and accurate event records, tickets, timelines, and supporting evidence.
  • Contribute to required SOC event reporting and operational status information.
  • Perform Tier 2 troubleshooting of cybersecurity tools, alerts, security data, and related technical issues.
  • Use approved Commercial-Off-The-Shelf (COTS) security-analysis tools to investigate cybersecurity events.
  • Support security testing, mitigation activities, and cybersecurity compliance checking as required by SOC operations.
  • Coordinate analysis with incident responders, network engineers, endpoint-security personnel, cybersecurity-tool teams, system administrators, and other cybersecurity stakeholders.
  • Identify recurring false positives, detection gaps, or ineffective alerting and recommend improvements to monitoring and detection capabilities.
  • Support tuning of cybersecurity monitoring capabilities to improve detection accuracy and analyst effectiveness.
  • Contribute to SOC procedure, playbook, and process improvements based on operational experience and lessons learned.
  • Support knowledge transfer across SOC analysts to improve consistent analysis and response within the 24x7 operating environment.

Basic Qualifications

  • BS degree or equivalent and 2+ years of prior relevant experience, or a Masters with less than 2 years prior relevant experience. In lieu of degree, additional experience may be required.
  • Experience performing cybersecurity event analysis, SOC operations, cyber defense, incident triage, or security monitoring.
  • Experience analyzing and correlating alerts from multiple cybersecurity monitoring capabilities.
  • Experience investigating endpoint, network, user-activity, or other cybersecurity events.
  • Experience determining the scope, severity, and potential impact of suspicious cybersecurity activity.
  • Experience supporting cybersecurity incident escalation, containment, mitigation, or evidence preservation.
  • Experience using enterprise security-analysis or cybersecurity monitoring tools.
  • Experience performing Tier 2 cybersecurity troubleshooting.
  • Working knowledge of cybersecurity attack techniques, network-security concepts, endpoint security, event analysis, and incident-response processes.
  • Ability to document investigations, findings, actions, and conclusions clearly and accurately.
  • Ability to work effectively within a team-based 24x7 security operations environment.
  • U.S. Citizenship required.
  • Active Secret security clearance required.

Preferred Qualifications

  • Experience supporting a Department of Defense or Federal Security Operations Center.
  • Experience working in a 24x7 SOC or Cybersecurity Service Provider environment.
  • Experience with Security Information and Event Management (SIEM) platforms and enterprise cybersecurity monitoring tools.
  • Experience analyzing endpoint, network, identity, user-activity, intrusion-detection, or other cybersecurity telemetry.
  • Experience supporting cybersecurity incident response and digital-evidence preservation.
  • Experience tuning security alerts, detection logic, or monitoring capabilities to reduce false positives and improve detection quality.
  • Experience developing or refining SOC procedures, playbooks, or escalation criteria.
  • Experience with cybersecurity mitigation, compliance checking, or security testing.
  • Familiarity with Department of Defense cybersecurity requirements and Risk Management Framework processes.
  • Familiarity with DHRA, DMDC, or comparable Department of Defense enterprise environments.

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.

Original Posting:

October 9, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:

Pay Range $69,550.00 - $125,725.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Leidos's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Leidos's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Leidos's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.