About the Role
Join the Security Operations team as a SOC Analyst II to defend against cyber threats. This role involves day-to-day monitoring, triage, investigation, and response across enterprise systems, endpoints, cloud infrastructure, and collaboration environments. The ideal candidate is a mid-career cybersecurity professional with a strong technical foundation, curiosity for threat analysis, and a desire to grow in a mission-focused defense technology environment. You will collaborate with senior security engineers, IT, and infrastructure teams to identify suspicious activity, investigate alerts, and protect sensitive company and government data. This position suits someone who thrives in a fast-paced startup and is passionate about operational cybersecurity.
Responsibilities
- Monitor and triage security alerts and events across enterprise systems, endpoints, cloud platforms, and networks.
- Investigate suspicious activity, indicators of compromise, phishing attempts, malware detections, and unauthorized access attempts.
- Escalate validated security incidents to senior analysts or engineering teams.
- Support containment, remediation, and recovery activities during cybersecurity incidents.
- Assist with root cause analysis and incident documentation.
- Support administration and monitoring of cybersecurity platforms including Microsoft GCC High, Crowdstrike and other EDR/XDRs, PIM/PAM Tools, various SIEMs, and Azure Sentinel.
- Monitor endpoint detection and response (EDR/XDR) alerts and telemetry.
- Assist with tuning alerting rules and reducing false positives.
- Support vulnerability management and remediation tracking activities.
- Help maintain endpoint, identity, and cloud security configurations.
- Review logs and security telemetry from SIEM, endpoint, network, and cloud security platforms.
- Identify anomalous or malicious behavior patterns.
- Assist with development and improvement of detection rules, playbooks, and response procedures.
- Participate in threat hunting and proactive security monitoring initiatives.
- Support cybersecurity compliance initiatives including CMMC, NIST 800-171, and DFARS requirements.
- Maintain accurate incident records, investigation notes, and operational documentation.
- Assist with audit preparation, evidence collection, and remediation tracking.
- Follow established security procedures and escalation processes.
- Collaborate with IT, Engineering, and business teams to improve organizational security posture.
- Assist with phishing response and user security awareness efforts.
- Contribute to continuous improvement of SOC processes and operational maturity.
Requirements
- 3–5+ years of experience in cybersecurity, IT support, systems administration, or SOC operations.
- Foundational understanding of cybersecurity concepts including networking, endpoint security, identity management, and incident response.
- Familiarity with security monitoring and alert triage processes.
- Experience working with Managed Security Service Providers (MSSPs).
- Experience or exposure to enterprise security platforms such as Microsoft GCC High, Crowdstrike and other EDR/XDRs, App Allow/Block-listing tools, PIM/PAM Tools, various SIEMs, and Azure Sentinel.
- Strong understanding of Windows, Linux, macOS, and cloud-based environments.
- Basic understanding of SIEM, EDR/XDR, phishing analysis, and log analysis.
- Strong analytical, troubleshooting, and problem-solving skills.
- Excellent written and verbal communication skills.
- Ability to prioritize and manage multiple tasks in a fast-paced environment.
- Must be a U.S. Citizen eligible for government facilities and sensitive information.
- Ability to obtain additional security clearances as required by contract.
- Active Security Clearance (Preferred).
- Experience supporting defense, aerospace, government contracting, or regulated technology environments (Preferred).
- Familiarity with Microsoft GCC High environments (Preferred).
- Familiarity with using AI and LLM tools within the SOC (Preferred).
- Familiarity with monitoring AI and LLM tools (Preferred).
- Exposure to compliance frameworks such as NIST 800-171, CMMC, CIS Controls, or ISO 27001 (Preferred).
- Experience with scripting or automation using PowerShell, Python, or Bash (Preferred).
- Familiarity with digital forensic process and chain of custody (Preferred).
- Knowledge of MITRE ATT&CK framework and common threat actor techniques (Preferred).
- Security certifications such as Security+, CySA+, SC-900, Network+, or equivalent (Preferred).
- Experience working in a 24/7 or operational security environment (Preferred).
Skills
- Cybersecurity concepts (networking, endpoint security, identity management, incident response)
- Security monitoring and alert triage
- Windows, Linux, macOS, and cloud-based environments
- SIEM, EDR/XDR, phishing analysis, and log analysis
- Analytical, troubleshooting, and problem-solving
- Written and verbal communication
- Task prioritization and management
- Microsoft GCC High environments
- Using AI and LLM tools within the SOC
- Monitoring AI and LLM tools
- Compliance frameworks (NIST 800-171, CMMC, CIS Controls, ISO 27001)
- Scripting or automation (PowerShell, Python, Bash)
- Digital forensic process and chain of custody
- MITRE ATT&CK framework and common threat actor techniques
Location
- Onsite
- Los Angeles, CA
Work Type
- Full-time
- Onsite
Experience Level
- Mid-career
- 3-5+ years of experience
Education Level
- Security certifications (Security+, CySA+, SC-900, Network+, or equivalent)
Salary/Compensations
- $110,000 - $160,000 (base compensation)
Benefits
- Medical, dental, and vision benefits (100% company-paid)
- 401k with 50% company match up to 6% of pay
- FSA
- HSA
- Life insurance
- Free daily lunch
- No meeting Fridays
- Unlimited PTO
- Casual dress code
- Generous pre-IPO stock option grants
- Relocation assistance
- Annual bonuses (coming soon)
About the Company
- CHAOS Industries redefines modern defense with a multi-product portfolio for domain dominance.
- Products are powered by Coherent Distributed Networks (CDN™), empowering warfighters, commercial air operators, and border protection teams.
- Founded in 2022, raised $1 billion in funding from 8VC, Accel, and Valor Equity Partners.
- Headquartered in Los Angeles, with offices in Washington, D.C., San Francisco, San Diego, Seattle, and London.
