SOC Analyst Tier 2

Jfl Consulting, Llc
Springfield, VA, United States
14 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$90,000.0 - $140,000.0
Working hours
Shift work

Tech stack

Cyber Security Query Languages Event Logging Pcap Log Analysis Kusto Query Language Security Information and Event Management Wireshark Mitre Att&ck SC Clearance Information Technology Cybercrime
+2 more
3-tier Architectures SentinelOne Expertise

Job description

We’re looking for a SOC Analyst Tier 2 to serve as the primary investigation tier in the operations center. Tier 2 analysts receive escalations from Tier 1, conduct in-depth log correlation and threat analysis, perform PCAP review, and determine whether an incident requires Tier 3 or incident response escalation., * Monitor SIEM dashboards and security tooling alerts

  • Serve as the advanced triage for all incoming customer calls, alerts, emails, and tickets using established playbooks to categorize, prioritize, and route
  • Create and manage detailed tickets for all confirmed or suspected events
  • Receive, review, and investigate all Tier 1 escalations within SLA
  • Perform deep log correlation across multiple data sources such as endpoint, network, application, identity
  • Conduct PCAP analysis for network-based threat investigation
  • Conduct root cause analysis or determine scope of compromise and identify affected systems, lateral movement, data exfiltration indicators
  • Escalate confirmed incidents to Tier 3/IR with a complete documentation and investigation summary
  • Tune false positive alerts Tier 3 and Tier 4 engineers to reduce
  • Write clear and thorough investigation reports for all escalated incidents
  • Mentor T1 analysts such as reviewing their triage decisions and provide coaching through their analysis
  • Maintain and update playbooks based on new TTPs and lessons learned
  • Maintain the SOC Event log for all events during the shift
  • Maintain situational awareness of the threat landscape and active campaigns
  • Participate briefings and training sessions

Requirements

  • 3+ years of SOC analyst experience with hands-on investigation or threat hunting experience
  • Bachelor’s degree in Cyber Security, Information Technology, Computer Science, Information Security, or related field. In lieu of degree, four additional years of experience in a NOC, SOC, IT security, or network engineering role
  • One of the following certifications, equivalent or better: Sec+, CYSA+, GCIH, SecX, CEH, GCIA, GSOC, CISSP
  • Experience with SIEM platforms and log analysis
  • Experience with SIEM query languages - SPL, KQL, or equivalent
  • Experience with PCAP analysis tools (Wireshark, NetworkMiner, or equivalent)
  • Strong understanding of attacker TTPs and MITRE ATT&CK framework
  • Ability to work shifts including nights, weekends, and holidays on rotating shift schedule, * Active Secret clearance preferred but not required
  • Experience with EDR platforms (CrowdStrike Falcon, SentinelOne, or equivalent)
  • Memory forensics or malware triage experience

Benefits & conditions

  • Salary: $90k- $140k
  • 100% employer-paid medical, dental, and vision premiums for employees and dependents
  • Flexible Spending Accounts (healthcare, dependent care, and commuter)
  • Life insurance, short-term disability and long-term disability
  • 401(k) with immediate vesting of company contribution
  • Generous PTO policy (15 vacation, 5 sick, 2 personal days, 11 holidays)
  • We support your growth through certification reimbursement, dedicated professional development funding, and company-provided access to online learning platforms, $90k- $140k

About the company

With more than 20 years of securing some of the U.S. Department of Defense and the Intelligence Community’s most critical networks, JFL Consulting, LLC provides advanced network security solutions to a range of US Government and US commercial clients.

Our cybersecurity operators are experts at assessing and defending mission-critical data and the networks that facilitate their operation. We are focused on delivering advanced products and industry best practices that meet each customer’s unique requirements. Visit www.jflconsulting.com

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:19 min

Setting up a vulnerable test application and monitoring environment

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC 2024

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

14:14 min

Addressing audience inquiries on analytical implementation and career growth

Julian Joseph · LIVE

1:48 min

Analyzing network packets with database protocol tools

Daniël van Eeden Daniël van Eeden · WWC Europe 2026

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

Videos

See all

Related articles

See all