description Job Description
<p>CHAOS Industries is redefining modern defense with a multi-product portfolio that gives the ultimate advantage—domain dominance. The company's products are powered by Coherent Distributed Networks (CDN™), empowering warfighters, commercial air operators, and border protection teams to act faster, adapt rapidly, and stay ahead of evolving threats. </p>
<p>CHAOS Industries was founded in 2022 and has raised a total of $1 billion in funding from leading investors, including 8VC, Accel, and Valor Equity Partners. The company is headquartered in Los Angeles, with offices in Washington, D.C., San Francisco, San Diego, Seattle, and London. For more information, please visit <a href="https://www.chaosinc.com">www.chaosinc.com</a>.</p>
<p><strong>Role Overview:</strong></p>
<p><span data-contrast="auto">We are seeking a SOC Analyst II to join our growing Security Operations team and help defend the organization against evolving cyber threats. This role will support day-to-day monitoring, triage, investigation, and response activities across enterprise systems, endpoints, cloud infrastructure, and collaboration environments.</span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"> </span></p>
<p><span data-contrast="auto">The ideal candidate is a mid-career cybersecurity professional with a strong technical foundation, curiosity for threat analysis, and a desire to grow within a mission-focused defense technology environment. This individual will work closely with senior security engineers, IT, and infrastructure teams to identify suspicious activity, investigate alerts, and support the protection of sensitive company and government-related data.</span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"> </span></p>
<p><span data-contrast="auto">This position is ideal for someone who thrives in a fast-paced startup environment and is passionate about operational cybersecurity.</span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":240,"335559739":240}"> </span></p>
<p><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 1">Responsibilities:</span></span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335559738":322,"335559739":322}"> </span></p>
<ul>
<li><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 2">Security Monitoring & Incident Response</span></span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335559738":299,"335559739":299}"> </span>
<ul>
<li><span data-contrast="auto">Monitor and triage security alerts and events across enterprise systems, endpoints, cloud platforms, and networks </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Investigate suspicious activity, indicators of compromise, phishing attempts, malware detections, and unauthorized access attempts </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Escalate validated security incidents to senior analysts or engineering teams as appropriate </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Support containment, remediation, and recovery activities during cybersecurity incidents </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Assist with root cause analysis and incident documentation </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
</ul>
</li>
<li><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 2">Security Operations & Tool Administration</span></span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335559738":299,"335559739":299}"> </span>
<ul>
<li><span data-contrast="auto">Support administration and monitoring of cybersecurity platforms including: </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Microsoft GCC High </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Crowdstrike and other EDR/XDRs</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335551550":1,"335551620":1,"335559685":1440,"335559737":0,"335559738":0,"335559739":0,"335559740":276,"335559991":360}"> </span></li>
<li><span data-contrast="auto">PIM/PAM Tools</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335551550":1,"335551620":1,"335559685":1440,"335559737":0,"335559738":0,"335559739":0,"335559740":276,"335559991":360}"> </span></li>
<li><span data-contrast="auto">Various SIEMs</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335551550":1,"335551620":1,"335559685":1440,"335559737":0,"335559738":0,"335559739":0,"335559740":276,"335559991":360}"> </span></li>
<li><span data-contrast="auto">Azure Sentinel</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335551550":1,"335551620":1,"335559685":1440,"335559737":0,"335559738":0,"335559739":0,"335559740":276,"335559991":360}"> </span></li>
<li><span data-contrast="auto">Monitor endpoint detection and response (EDR/XDR) alerts and telemetry </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Assist with tuning alerting rules and reducing false positives </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Support vulnerability management and remediation tracking activities </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Help maintain endpoint, identity, and cloud security configurations </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
</ul>
</li>
<li><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 2">Threat Detection & Analysis</span></span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335559738":299,"335559739":299}"> </span>
<ul>
<li><span data-contrast="auto">Review logs and security telemetry from SIEM, endpoint, network, and cloud security platforms </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Identify anomalous or malicious behavior patterns </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Assist with development and improvement of detection rules, playbooks, and response procedures </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Participate in threat hunting and proactive security monitoring initiatives </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
</ul>
</li>
<li><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 2">Compliance & Documentation</span></span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335559738":299,"335559739":299}"> </span>
<ul>
<li><span data-contrast="auto">Support cybersecurity compliance initiatives including UK CE/CE+, ISO 27001 and UK-specific requirements </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Maintain accurate incident records, investigation notes, and operational documentation </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Assist with audit preparation, evidence collection, and remediation tracking </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Follow established security procedures and escalation processes </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
</ul>
</li>
<li><strong><span data-contrast="auto"><span data-ccp-parastyle="heading 2">Security Awareness & Collaboration</span></span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"134245418":true,"134245529":true,"335559738":299,"335559739":299}"> </span>
<ul>
<li><span data-contrast="auto">Collaborate with IT, Engineering, and business teams to improve organizational security posture </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Assist with phishing response and user security awareness efforts </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Contribute to continuous improvement of SOC processes and operational maturity </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
</ul>
</li>
</ul>
<p><strong>Minimum Requirements:</strong></p>
<ul>
<li><span data-contrast="auto">3–5+ years of experience in Cybersecurity, IT support, systems administration, or SOC operations </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Foundational understanding of cybersecurity concepts including networking, endpoint security, identity management, and incident response </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Familiarity with security monitoring and alert triage processes </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Experience working with Managed Security Service Providers (MSSPs) and external vendors</span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Experience or exposure to enterprise security platforms such as: </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Microsoft GCC High </span><span data-ccp-props="{"134233117":false,"134233118":false,"335559738":0,"335559739":0}"> </span></li>
<li><span data-contrast="auto">Crowdstrike and other EDR/XDRs</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335551550":1,"335551620":1,"335559737":0,"335559738":0,"335559739":0,"335559740":276}"> </span></li>
<li><span data-contrast="auto">App Allow/Block-listing tools</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335551550":1,"335551620":1,"335559737":0,"335559738":0,"335559739":0,"335559740":276}"> </span></li>
<li><span data-contrast="auto">PIM/PAM Tools</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335551550":1,"335551620":1,"335559737":0,"335559738":0,"335559739":0,"335559740":276}"> </span></li>
<li><span data-contrast="auto">Various SIEMs</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335551550":1,"335551620":1,"335559737":0,"