Full-Time

CSOC CIR Tier II Analyst

Posted on 10/30/2025

PingWind

PingWind

51-200 employees

Cybersecurity, IT, and supply chain services

No salary listed

Austin, TX, USA + 2 more

More locations: Brookfield, IL, USA | Martinsburg, WV, USA

In Person

On-site schedule: Monday–Friday, 11:00 PM–7:00 AM.

Category
IT & Security (4)
, , ,
Required Skills
ServiceNow
Requirements
  • Bachelor's degree in computer science, Cybersecurity, Information Technology, or a related field (or equivalent work experience)
  • 3+ years of experience supporting incident response in an enterprise-level Security Operations Center (SOC)
  • Ability to obtain Tier 4 / High Risk Background Investigation
  • Work 100% on-site Monday – Friday from 11:00 PM to 7:00 AM.
  • A deep understanding of cybersecurity principles, incident response methodologies, and a proactive mindset to ensure our SOC operates effectively in a high-pressure environment
  • Strong experience with security technologies, including SIEM, IDS/IPS, EDR, and network monitoring tools
  • Experience with enterprise ticketing systems like ServiceNow
  • Excellent analytical and problem-solving skills
  • Ability to work independently and in a team environment to identify errors, pinpoint root causes, and devise solutions with minimal oversight
  • Ability to learn and function in multiple capacities and learn quickly
  • Strong verbal and written communication skills
  • On-site location requirements as listed (Hines, IL; Martinsburg, WV; or Austin, TX)
Responsibilities
  • Perform real-time monitoring and triage of security alerts in Cybersecurity toolsets including SIEM, and EDR
  • Make accurate determination of what alerts are false positives or require further investigation and prioritization
  • Lead and actively participate in the investigation, analysis, and resolution of cybersecurity incidents. Analyze attack patterns, determine the root cause, and recommend appropriate remediation measures to prevent future occurrences
  • Ensure accurate and detailed documentation of incident response activities, including analysis, actions taken, and lessons learned. Collaborate with knowledge management teams to maintain up-to-date incident response playbooks
  • Collaborate effectively with cross-functional teams, including forensics, threat intelligence, IT, and network administrators. Clearly communicate technical information and incident-related updates to management and stakeholders
  • Identify and action opportunities for tuning alerts to make the incident response team more efficient
  • Monitor the performance of security analytics and automation processes regularly, identifying areas for improvement and taking proactive measures to enhance their efficacy
  • Leverage Security Orchestration, Automation, and Response (SOAR) platforms to streamline and automate incident response processes, including enrichment, containment, and remediation actions
  • Support the mentoring and training of more junior IR staff
  • Stay informed about the latest cybersecurity threats, trends, and best practices. Actively participate in cybersecurity exercises, drills, and simulations to improve incident response capabilities
Desired Qualifications
  • Ability to investigate Indicators of Compromise (IOCs) using Splunk by correlating logs from multiple sources to detect, trace, and assess threat activity across the enterprise
  • Experience leveraging Microsoft Defender for Endpoint (MDE) to perform endpoint investigations, analyze process trees, and validate IOCs during active threat scenarios
  • Ability to remediate phishing incidents, including analysis of email headers, links, and attachments, identifying impacted users, and executing containment actions such as user lockouts, email quarantine, and domain blacklisting
  • Experience performing root cause analysis of malware leveraging PowerShell, using tools such as MDE advanced hunting (KQL) and Splunk to identify infection paths, attacker behavior, and persistence mechanisms

PingWind is a service provider that combines cybersecurity, information technology, and supply chain services to help clients secure information, modernize systems, and optimize performance. It offers services rather than a single product, applying its CVE certification to security work. The company’s solutions work by assessing and protecting information systems, upgrading and integrating IT infrastructure, and improving supply chain resilience, with a focus on reducing risk and increasing efficiency. PingWind differentiates itself through its SDVOSB and HUBZone certifications, signaling veteran-owned status and eligibility for government contracts, along with a specialized blend of cybersecurity, IT, and supply chain expertise. The company’s goal is to help clients secure information, modernize their technology environments, and optimize operational performance.

Company Size

51-200

Company Stage

N/A

Total Funding

N/A

Headquarters

Washington DC, District of Columbia

Founded

2012

Simplify Jobs

Simplify's Take

What believers are saying

  • Secured 3-year $4M VA task order on January 15, 2022, for IT systems integration.
  • Jerome June Jr. joined Talent Acquisition, boosting cybersecurity hiring.
  • 97% employee satisfaction rating enhances talent retention in federal IT.

What critics are saying

  • $4M VA contract expires 2025, collapsing revenue under $5 million.
  • Leidos undercuts on VA renewals using scale in systems integration.
  • CACI displaces cybersecurity services with superior Zero Trust implementations.

What makes PingWind unique

  • PingWind combines cybersecurity, IT, and supply chain services for federal agencies.
  • CVE-certified SDVOSB and HUBZone status secures set-aside government contracts.
  • Luis Ibarra named Top 10 CTO to Watch in 2024 by International Business Times.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Paid Federal Holidays

Health Insurance

Dental Insurance

401(k) Company Match

Paid Vacation

Paid Sick Leave

Continuing education assistance

Short Term / Long Term Disability & Life Insurance

Employee Assistance Program

Company News

EIN Presswire
Nov 17th, 2023
PingWind Inc Luis Ibarra Recognized as One of the Top 10 CTOs to Watch in 2024 by International Business Times

ANNANDALE, VA, USA, November 17, 2023 / EINPresswire.com / -- PingWind Inc., a leading provider of cyber, IT, software development, and management consulting solutions for federal agencies, is proud to announce that its Chief Technology Officer, Luis Ibarra, has been recognized as one of the " Top 10 CTOs to Watch in 2024 " by the prestigious International Business Times.

PingWind
Dec 1st, 2022
PingWind adds Talent Acquisition Leader — Pingwind

Jerome June Jr. recently joined PingWind’s Talent Acquisition team.

PingWind
Nov 14th, 2022
2022 HIRE Vets Medallion Award — Pingwind

PingWind earned the gold award after applying earlier this year.

PingWind
Apr 4th, 2022
PingWind Inc. recognized as finalist at 14th Annual Small and Emerging Contractors Advisory Forum (SECAF) Awards on Apr 4th 22'.

PingWind today announced that it was selected as a finalist for the 14th Annual Small and Emerging Contractors Advisory Forum (SECAF) Awards.

PingWind
Feb 15th, 2022
PingWind Inc. signed new client Department of Veterans’ Affairs on Jan 15th 22'.

PingWind was recently awarded a 3-year, $4M task with the Department of Veterans Affairs to provide Information Technology Systems Integration (ITSI) Operations and Maintenance (O&M) services.

INACTIVE