SOC Analyst Level 2

2 days ago

Philippines Supply Chimp Full-time

About Us

Supply Chimp (Mono Machines LLC dba Supply Chimp) has spent two decades supporting the U.S. government with critical supplies and logistics solutions. Our mission is simple and focused: we serve those who serve us by providing customer-driven supply solutions that get the right products to the right place at the right time.

At Supply Chimp, how we work matters just as much as what we deliver. Our values, teamwork, accountability, action, and integrity, shape how we show up for our customers, support one another, and deliver with purpose, trust, and follow-through.

Our Values

  • Teamwork:
    • We treat people with respect and work as one team to serve our customers
  • Accountability:
    • We own it and follow through
  • Action:
    • We act with urgency & purpose
  • Integrity:
    • We do the right thing. Always.

About the Role

We are looking for a SOC Analyst Level 2 to independently execute and support Supply Chimp’s day-to-day security operations. This role is responsible for security monitoring and alert triage, recurring security and compliance activities, evidence and documentation, security maintenance, incident response support, risk assessment, and security testing. This is a hands‑on role for someone who can work effectively within established processes while also recognizing where processes, documentation, or tooling need to improve. Some of our security systems and workflows are still being developed, so success requires someone who can contribute useful operational input while reliably executing the work that already exists.

What Success Looks Like

  • You independently manage recurring security operations work and meet established cadences without needing reminders.
  • Security alerts and suspected events are investigated, documented, and escalated appropriately with useful supporting context.
  • Security reviews, compliance evidence, and operational records are accurate, complete, organized, and ready for review.
  • You demonstrate sound judgment when information is incomplete, know when to continue investigating, and know when escalation is needed.
  • You identify practical improvements to security processes, documentation, monitoring, or controls and help move those improvements forward.

Key Responsibilities

Security Monitoring & Incident Response

  • Monitor and triage security alerts and investigate suspected security events.
  • Assess available information to help determine scope, impact, priority, and appropriate next steps.
  • Document alert dispositions, findings, decisions, and actions clearly and accurately.
  • Escalate confirmed or suspected security events with relevant context and supporting information.
  • Coordinate approved containment, recovery, and follow‑up activities within defined authority and working hours.

Security Controls, Compliance & Evidence

  • Execute recurring security and compliance reviews across assigned controls and applicable frameworks.
  • Collect, review, organize, and maintain supporting evidence in accordance with established standards.
  • Identify control gaps, missing evidence, control drift, or potential findings and elevate them appropriately.
  • Track open findings and remediation commitments through completion or escalation.
  • Maintain review‑ready security plans, compliance records, assessment artifacts, and supporting documentation.

Security Maintenance, Access & Risk

  • Perform recurring vulnerability, endpoint, configuration, backup, access, and security‑tool reviews within assigned scope.
  • Review vulnerability findings, verify remediation status, and elevate unresolved material issues.
  • Evaluate access, authentication, permissions, shared or service accounts, and related security controls for appropriate use and least privilege.
  • Conduct or support security risk assessments for systems, applications, vendors, projects, integrations, and material changes.
  • Maintain risk and remediation records and follow up on material open items.

Security Documentation, Testing & Improvement

  • Create and maintain security procedures, runbooks, checklists, assessment tools, and triage guidance.
  • Keep security documentation aligned with current systems, configurations, and operating processes.
  • Design, configure, execute, and evaluate approved phishing simulations and related security testing.
  • Identify gaps in monitoring, processes, documentation, or control coverage and recommend practical improvements.
  • Collaborate with IT, Engineering, and other internal teams on security activities, findings, remediation, and user‑facing