About the Role
We are seeking a SOC Analyst II to join our growing Security Operations team and help defend the organization against evolving cyber threats. This role will support day-to-day monitoring, triage, investigation, and response activities across enterprise systems, endpoints, cloud infrastructure, and collaboration environments. The ideal candidate is a mid-career cybersecurity professional with a strong technical foundation, curiosity for threat analysis, and a desire to grow within a mission-focused defense technology environment.
Responsibilities
- Monitor and triage security alerts and events across enterprise systems, endpoints, cloud platforms, and networks
- Investigate suspicious activity, indicators of compromise, phishing attempts, malware detections, and unauthorized access attempts
- Escalate validated security incidents to senior analysts or engineering teams as appropriate
- Support containment, remediation, and recovery activities during cybersecurity incidents
- Assist with root cause analysis and incident documentation
- Support administration and monitoring of cybersecurity platforms including Microsoft GCC High, Crowdstrike and other EDR/XDRs, PIM/PAM Tools, Various SIEMs, and Azure Sentinel
- Monitor endpoint detection and response (EDR/XDR) alerts and telemetry
- Assist with tuning alerting rules and reducing false positives
- Support vulnerability management and remediation tracking activities
- Help maintain endpoint, identity, and cloud security configurations
- Review logs and security telemetry from SIEM, endpoint, network, and cloud security platforms
- Identify anomalous or malicious behavior patterns
- Assist with development and improvement of detection rules, playbooks, and response procedures
- Participate in threat hunting and proactive security monitoring initiatives
- Support cybersecurity compliance initiatives including UK CE/CE+, ISO 27001 and UK-specific requirements
- Maintain accurate incident records, investigation notes, and operational documentation
- Assist with audit preparation, evidence collection, and remediation tracking
- Follow established security procedures and escalation processes
- Collaborate with IT, Engineering, and business teams to improve organizational security posture
- Assist with phishing response and user security awareness efforts
- Contribute to continuous improvement of SOC processes and operational maturity
Requirements
- 3–5+ years of experience in Cybersecurity, IT support, systems administration, or SOC operations
- Foundational understanding of cybersecurity concepts including networking, endpoint security, identity management, and incident response
- Familiarity with security monitoring and alert triage processes
- Experience working with Managed Security Service Providers (MSSPs) and external vendors
- Experience or exposure to enterprise security platforms such as Microsoft GCC High, Crowdstrike and other EDR/XDRs, App Allow/Block-listing tools, PIM/PAM Tools, Various SIEMs, and Azure Sentinel
- Strong understanding of Windows, Linux, macOS, and cloud-based environments
- Understanding of SIEM, EDR/XDR, phishing analysis, and log analysis
- Strong analytical, troubleshooting, and problem-solving skills
- Excellent written and verbal communication skills
- Ability to prioritize and manage multiple tasks in a fast-paced environment
- Experience supporting defense, aerospace, government contracting, or regulated technology environments
- Familiarity with Microsoft GCC High environments
- Familiarity with using AI and LLM tools within the SOC
- Familiarity with monitoring the use of AI and LLM tools
- Exposure to compliance frameworks such as UK CE,/CE+, UK CSM, CIS Controls, or ISO 27001
- Experience with scripting or automation using PowerShell, Python, or Bash
- Familiarity with digital forensic process and chain of custody
- Knowledge of MITRE ATT&CK framework and common threat actor techniques
- Security certifications such as Security+, CySA+, SC-900, Network+, or equivalent
- Experience working in a 24/7 or operational security environment preferred
Skills
- Cybersecurity
- IT support
- Systems administration
- SOC operations
- Networking
- Endpoint security
- Identity management
- Incident response
- Security monitoring
- Alert triage
- Microsoft GCC High
- Crowdstrike
- EDR/XDR
- App Allow/Block-listing tools
- PIM/PAM Tools
- SIEMs
- Azure Sentinel
- Windows
- Linux
- macOS
- Cloud environments
- Phishing analysis
- Log analysis
- Analytical skills
- Troubleshooting
- Problem-solving
- Communication skills
- Task prioritization
- Time management
- PowerShell
- Python
- Bash
- Digital forensics
- MITRE ATT&CK framework
- Security+
Location
- Los Angeles
- Washington, D.C.
- San Francisco
- San Diego
- Seattle
- London
- Hybrid
Work Type
- Hybrid
Experience Level
- Mid-career
- 3-5+ years
Salary/Compensations
- Competitive base salaries
Benefits
- Private medical, dental and vision benefits (for employees & dependents) will be 100% paid for by the company
- 5% pension match
- Generous pre-IPO stock option grants
- Relocation assistance
- Annual bonuses (coming soon!)
About the Company
- CHAOS Industries is redefining modern defense with a multi-product portfolio that gives the ultimate advantage—domain dominance.
- The company's products are powered by Coherent Distributed Networks (CDN™), empowering warfighters, commercial air operators, and border protection teams to act faster, adapt rapidly, and stay ahead of evolving threats.
- CHAOS Industries was founded in 2022 and has raised a total of $1 billion in funding from leading investors, including 8VC, Accel, and Valor Equity Partners.
- The company is headquartered in Los Angeles, with offices in Washington, D.C., San Francisco, San Diego, Seattle, and London.
- Fast-paced, high-growth defense technology startup environment
- Collaborative and highly cross-functional culture with direct access to leadership
- 350 employees and counting across 5 global offices
