> Markdown version of [/jobs/ext/1470961-soc-analyst-tier-2](https://www.wearedevelopers.com/jobs/ext/1470961-soc-analyst-tier-2). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SOC Analyst Tier 2 - **Company:** Jfl Consulting, Llc - **Location:** Springfield, VA, United States - **Experience:** Experienced - **Salary:** $90,000.0 - $140,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Query Languages, Event Logging, Pcap, Log Analysis, Kusto Query Language, Security Information and Event Management, Wireshark, Mitre Att&ck, SC Clearance, Information Technology, Cybercrime, 3-tier Architectures, SentinelOne Expertise - **Published:** July 28, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9060172/soc-analyst-tier-2 ## About the Role * 3+ years of SOC analyst experience with hands-on investigation or threat hunting experience * Bachelor's degree in Cyber Security, Information Technology, Computer Science, Information Security, or related field. In lieu of degree, four additional years of experience in a NOC, SOC, IT security, or network engineering role * One of the following certifications, equivalent or better: Sec+, CYSA+, GCIH, SecX, CEH, GCIA, GSOC, CISSP * Experience with SIEM platforms and log analysis * Experience with SIEM query languages - SPL, KQL, or equivalent * Experience with PCAP analysis tools (Wireshark, NetworkMiner, or equivalent) * Strong understanding of attacker TTPs and MITRE ATT&CK framework * Ability to work shifts including nights, weekends, and holidays on rotating shift schedule, * Active Secret clearance preferred but not required * Experience with EDR platforms (CrowdStrike Falcon, SentinelOne, or equivalent) * Memory forensics or malware triage experience ## Description We're looking for a SOC Analyst Tier 2 to serve as the primary investigation tier in the operations center. Tier 2 analysts receive escalations from Tier 1, conduct in-depth log correlation and threat analysis, perform PCAP review, and determine whether an incident requires Tier 3 or incident response escalation., * Monitor SIEM dashboards and security tooling alerts * Serve as the advanced triage for all incoming customer calls, alerts, emails, and tickets using established playbooks to categorize, prioritize, and route * Create and manage detailed tickets for all confirmed or suspected events * Receive, review, and investigate all Tier 1 escalations within SLA * Perform deep log correlation across multiple data sources such as endpoint, network, application, identity * Conduct PCAP analysis for network-based threat investigation * Conduct root cause analysis or determine scope of compromise and identify affected systems, lateral movement, data exfiltration indicators * Escalate confirmed incidents to Tier 3/IR with a complete documentation and investigation summary * Tune false positive alerts Tier 3 and Tier 4 engineers to reduce * Write clear and thorough investigation reports for all escalated incidents * Mentor T1 analysts such as reviewing their triage decisions and provide coaching through their analysis * Maintain and update playbooks based on new TTPs and lessons learned * Maintain the SOC Event log for all events during the shift * Maintain situational awareness of the threat landscape and active campaigns * Participate briefings and training sessions ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [How I saved 200K/yr in direct costs writing 0 code lines in K8s](https://www.wearedevelopers.com/videos/1055-how-i-saved-200k-yr-in-direct-costs-writing-0-code-lines-in-k8s) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [MySQL Protocol Features You Should Be Aware Of](https://www.wearedevelopers.com/videos/100267-mysql-protocol-features-you-should-be-aware-of) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)