> Markdown version of [/jobs/ext/1224252-tier-ii-soc-analyst](https://www.wearedevelopers.com/jobs/ext/1224252-tier-ii-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Tier II SOC Analyst - **Company:** Zachary Piper - **Location:** Morrisville, NC, United States - **Experience:** Experienced - **Salary:** $130,000.0 - $145,000.0 - **Contract:** Permanent contract - **Skills:** Multitier Architecture, Microsoft Windows, Bash Shell, Cloud Computing, Cloud Computing Security, Cyber Security, Linux, Domain Name System (DNS), Hypertext Transfer Protocols (HTTP), Identity and Access Management, Intrusion Detection and Prevention, Intrusion Detection Systems, Python (Programming Language), Simple Mail Transfer Protocols, Packet Analyzer, Network Protocols, Windows PowerShell, Phishing, Security Information and Event Management, TCP/IP, Wireshark, Software Vulnerability Management, Scripting, Mitre Att&ck, QRadar, Malware, Cyber Threat Analysis, Information Technology, Microsoft Sentinel, CIS Benchmarks, Splunk, SentinelOne Expertise - **Published:** July 10, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9022476/tier-ii-soc-analyst ## About the Role * 3-5+ years of experience in a Security Operations Center (SOC), incident response, or cybersecurity operations role, with a strong Tier 2 analyst background * Active Secret Clearance required and ability to work onsite in Morrisville, NC five days per week * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent hands-on experience) * Proven experience investigating and responding to security incidents across enterprise environments, including triage, analysis, and remediation * Hands-on experience with SIEM platforms (e.g., Splunk, Microsoft Sentinel, QRadar, LogRhythm, Elastic) and EDR tools (e.g., CrowdStrike, Microsoft Defender, SentinelOne, Carbon Black) * Strong technical understanding of cybersecurity frameworks (NIST, MITRE ATT&CK, CIS Controls), network protocols (TCP/IP, DNS, HTTP/S, SMTP), operating systems (Windows/Linux), and identity/access management * Experience with detection engineering and advanced security tools, including SIEM tuning, correlation rule development, SOAR platforms, threat intelligence, packet analysis (Wireshark), vulnerability management, and scripting with Python, PowerShell, or Bash ## Description Piper Companies is looking to fill the role of for a Cloud and Technology company located in Morrisville, NC. The is responsible for advanced threat detection, incident investigation, containment, and remediation activities . * Monitor, analyze, and investigate security alerts across SIEM, EDR, IDS/IPS, firewalls, and cloud security platforms to identify and respond to potential threats * Triage escalated incidents from Tier 1 analysts, performing in-depth root cause analysis and leading containment, eradication, and recovery efforts * Correlate data across multiple security tools to identify indicators of compromise (IOCs) and attacker tactics, techniques, and procedures (TTPs) * Conduct proactive threat hunting and develop detection capabilities, including creating and refining SIEM use cases, correlation rules, and alerting logic * Perform malware analysis and investigate endpoint, network, cloud, and identity-based security events, including phishing, ransomware, insider threats, and account compromises * Support vulnerability management and incident response efforts by validating vulnerabilities, conducting forensic analysis, and maintaining detailed documentation, playbooks, and reporting * Collaborate cross-functionally with IT, cloud, and business teams while mentoring junior analysts and contributing to security operations enhancements and automation initiatives ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)