Job Title: SOC Analyst Tier 2
Place of Performance: Springfield, VA
Experience Level: 3+ years of experience
Job Overview:We're looking for a
SOC Analyst Tier 2 to serve as the primary investigation tier in the operations center. Tier 2 analysts receive escalations from Tier 1, conduct in-depth log correlation and threat analysis, perform PCAP review, and determine whether an incident requires Tier 3 or incident response escalation.
Key Responsibilities:- Monitor SIEM dashboards and security tooling alerts
- Serve as the advanced triage for all incoming customer calls, alerts, emails, and tickets using established playbooks to categorize, prioritize, and route
- Create and manage detailed tickets for all confirmed or suspected events
- Receive, review, and investigate all Tier 1 escalations within SLA
- Perform deep log correlation across multiple data sources such as endpoint, network, application, identity
- Conduct PCAP analysis for network-based threat investigation
- Conduct root cause analysis or determine scope of compromise and identify affected systems, lateral movement, data exfiltration indicators
- Escalate confirmed incidents to Tier 3/IR with a complete documentation and investigation summary
- Tune false positive alerts Tier 3 and Tier 4 engineers to reduce
- Write clear and thorough investigation reports for all escalated incidents
- Mentor T1 analysts such as reviewing their triage decisions and provide coaching through their analysis
- Maintain and update playbooks based on new TTPs and lessons learned
- Maintain the SOC Event log for all events during the shift
- Maintain situational awareness of the threat landscape and active campaigns
- Participate briefings and training sessions
Requirements
Required Qualifications- 3+ years of SOC analyst experience with hands-on investigation or threat hunting experience
- Bachelor's degree in Cyber Security, Information Technology, Computer Science, Information Security, or related field. In lieu of degree, four additional years of experience in a NOC, SOC, IT security, or network engineering role
- One of the following certifications, equivalent or better: Sec+, CYSA+, GCIH, SecX, CEH, GCIA, GSOC, CISSP
- Experience with SIEM platforms and log analysis
- Experience with SIEM query languages - SPL, KQL, or equivalent
- Experience with PCAP analysis tools (Wireshark, NetworkMiner, or equivalent)
- Strong understanding of attacker TTPs and MITRE ATT&CK framework
- Ability to work shifts including nights, weekends, and holidays on rotating shift schedule
Preferred Qualifications- Active Secret clearance preferred but not required
- Experience with EDR platforms (CrowdStrike Falcon, SentinelOne, or equivalent)
- Memory forensics or malware triage experience
Salary Description $90k- $140k