> Markdown version of [/jobs/ext/1955703-soc-analyst-tier-ii](https://www.wearedevelopers.com/jobs/ext/1955703-soc-analyst-tier-ii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SOC Analyst Tier II - **Company:** Blu Omega - **Location:** Sully Square, VA, United States - **Experience:** Experienced - **Salary:** $75,000.0 - $115,000.0 - **Contract:** Permanent contract - **Skills:** Multitier Architecture, Cloud Computing, Cyber Security, Query Languages, Domain Name System (DNS), Hypertext Transfer Protocols (HTTP), Networking Hardware, Intrusion Detection Systems, Python (Programming Language), Log Analysis, Simple Mail Transfer Protocols, Network Protocols, Windows PowerShell, Security Information and Event Management, TCP/IP, Scripting, Firewalls (Computer Science), Tanium Platform Expertise, Fireeye, 3-tier Architectures, Splunk - **Published:** August 6, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9010766/soc-analyst-tier-ii ## About the Role * 2+ years of experience in a SOC, NOC, or security monitoring environment (or equivalent hands-on security operations experience). * Experience triaging alerts and investigating security events using a SIEM (Splunk experience strongly preferred). * Familiarity with endpoint security/EDR tooling and basic incident response concepts (identify, contain, remediate, recover). * Working knowledge of Windows fundamentals and common enterprise/network protocols (TCP/IP, DNS, HTTP/HTTPS, SMTP). * Ability to write clear, detailed documentation and communicate effectively during escalations. * Ability to work onsite in a shift-based environment., * Experience supporting a federal/government SOC environment. * Exposure to any of the following: Tanium, Trellix, Zscaler, Microsoft Defender, FireEye. * Security certifications (nice to have): Security+, CySA+, SSCP, or similar. * Experience with basic scripting or query languages for investigation (PowerShell, Python, SPL) a plus., High School Diploma required; higher education preferred. ## Description Schedule: Shift-based environment. Initial day shift during onboarding, transitioning to assigned shifts (Back Half Days Wed-Sat, 6am-6pm; Back Half Nights Wed-Sat, 6pm-6am). Overview Blu Omega is seeking a SOC Analyst Tier 2 to support a federal cybersecurity program in a 24/7 Security Operations Center (SOC) environment. In this role, you will focus on monitoring and triaging security alerts, conducting initial investigations, documenting findings, and escalating confirmed or complex incidents to senior analysts and incident responders. This is a great opportunity for analysts who want to deepen their incident response and threat analysis skills while working with modern enterprise tooling. Program overview Mission: Support cybersecurity operations through 24/7 SOC monitoring, incident handling, and continuous improvement of detection and response processes. Environment/tooling (not all required): Splunk, Tanium, Trellix, Zscaler, Microsoft Defender, FireEye., * Monitor and triage security events and alerts generated by SIEM and security tools in a 24/7 SOC environment. * Perform initial incident investigation: validate alerts, gather evidence, enrich events, and determine severity and next steps. * Analyze logs and telemetry from endpoints, network devices, firewalls, IDS/IPS, and cloud/security platforms. * Document findings clearly in ticketing/case systems, including timelines, affected assets, and recommended actions. * Escalate confirmed incidents and complex investigations to Tier 3/IR personnel with complete context and supporting evidence. * Follow playbooks and standard operating procedures; recommend improvements based on trends, false positives, and observed gaps. * Participate in shift handoffs and contribute to daily operational reporting. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Debunking the Top 10 Myths about Web 3](https://www.wearedevelopers.com/videos/634-debunking-the-top-10-myths-about-web-3) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)