> Markdown version of [/jobs/ext/2433257-tier-1-soc-analyst](https://www.wearedevelopers.com/jobs/ext/2433257-tier-1-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Tier 1 SOC Analyst - **Company:** DRAGONFLI GROUP LLC - **Location:** United States (Remote available) - **Experience:** Starter - **Contract:** Internship / Graduate position - **Skills:** Microsoft Windows, Apple Mac Systems, Cyber Security, Linux, Python (Programming Language), Networking Basics, Windows PowerShell, Security Information and Event Management, Falcon Platform, Information Technology, Microsoft Sentinel, Splunk - **Published:** August 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=da5703933c916ad8 ## About the Role Dragonfli is hiring a Tier 1 SOC Analyst to join our overnight security operations team. In this role, you will monitor SIEM alerting (Microsoft Sentinel or Splunk) and EDR detections across client tenants, triage events against established runbooks, and escalate through a clear, documented path. You will track and validate vulnerability findings, keep auditable ticket notes and shift logs, and help flag detection gaps and tuning opportunities. This position is well suited to candidates with 0-2 years of security operations or IT experience who are ready to build a strong foundation in SOC monitoring and incident triage. This is a contract position involving a large commercial enterprise in the transportation/logistics (critical infrastructure) sector. Candidates with previous consulting or contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S., Must-Have: * Ability to pass a drug screening and a full background investigation, including verification of references, employment history, education, and certifications * 0-2 years of experience in security operations, IT, or a related technical field * Working knowledge of SIEM alerting and EDR alert triage concepts * Solid networking and operating-system fundamentals across Windows, macOS, and Linux * Understanding of the incident lifecycle: detection, triage, containment, and escalation * Ability to work overnight shifts reliably on a rotation that includes weekends * Clear written communication and disciplined documentation habits Preferred / Nice-to-Have: * Hands-on exposure to Microsoft Sentinel, Splunk, CrowdStrike or comparable EDR, and Tenable * Security+ or a similar entry-level security certification * Basic scripting for triage or automation (Python or PowerShell) * Coursework, internship, or lab experience in a SOC or IT security environment * Residency in the Hampton Roads through Richmond, VA corridor Skill(s): Technical Skills: * SIEM monitoring (Microsoft Sentinel, Splunk) * EDR alert triage * Vulnerability tracking (Tenable) * Ticketing and shift documentation * Windows, macOS, and Linux fundamentals * Networking fundamentals * Incident lifecycle knowledge Soft Skills: * Attention to detail * Clear written communication * Reliability on an overnight/weekend rotation * Discipline under SLA pressure * Collaboration with on-call leads ## Description * Monitor SIEM alerting (for example Microsoft Sentinel or Splunk) and triage events by severity against established runbooks * Review and action endpoint detection and response (EDR) alerts across client tenants * Track and validate vulnerability findings (Tenable) and route them into the correct workflow * Escalate incidents through the defined path with clear, documented handoffs * Open, update, and close tickets with accurate, auditable notes, and maintain clean shift logs * Communicate clearly with clients and the on-call lead during overnight events * Follow and help improve standard operating procedures, and flag detection gaps and tuning opportunities * Support monthly reporting with accurate event and response data ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)