Tier 2 SOC Analyst

DRAGONFLI GROUP LLC
United States
25 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Shift work
Job source

Tech stack

Microsoft Windows Apple Mac Systems Cyber Security Linux Python (Programming Language) Windows PowerShell Runbook Security Information and Event Management Software Vulnerability Management Scripting Falcon Platform Microsoft Sentinel
+2 more
Splunk Security Orchestration, Automation & Response

Job description

  • Conduct deeper investigation of escalated SIEM and EDR alerts across client tenants
  • Investigate, contain within your authority, and escalate through the defined path with clear, documented handoffs
  • Develop and refine runbooks and standard operating procedures
  • Track and validate vulnerability findings (Tenable) and route them into the correct workflow
  • Meet strict response and resolution service levels on every event, every shift
  • Open, update, and close tickets with accurate, auditable notes, and maintain clean shift logs
  • Communicate clearly with clients and the on-call lead during overnight events
  • Support monthly reporting with accurate event and response data

Requirements

Dragonfli is hiring a Tier 2 SOC Analyst to join our overnight security operations team. In this role, you will own deeper investigation, containment, and response actions for escalated SIEM and EDR alerts across client tenants, while developing and refining runbooks and standard operating procedures. You will meet strict response and resolution SLAs, track vulnerability findings, and communicate clearly with clients and the on-call lead throughout overnight events. This position is well suited to candidates with 3-5 years of hands-on SOC investigation and response experience.

This is a contract position involving a large commercial enterprise in the transportation/logistics (critical infrastructure) sector. Candidates with previous consulting or contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S., Must-Have:

  • United States citizenship
  • Ability to pass a drug screening and a full background investigation, including verification of references, employment history, education, and certifications
  • 3-5 years of SOC or security operations experience, including hands-on incident investigation and response
  • Demonstrated experience with SIEM alerting and EDR alert triage and containment
  • Solid networking and operating-system fundamentals across Windows, macOS, and Linux
  • Understanding of the incident lifecycle: detection, triage, containment, and escalation
  • Ability to work overnight shifts reliably on a rotation that includes weekends & holidays
  • Clear written communication and disciplined documentation habits

Preferred / Nice-to-Have:

  • Experience with Microsoft Sentinel, Splunk, CrowdStrike or comparable EDR, and Tenable
  • Security+, CySA+, GCIH, GSEC, or a similar certification
  • Scripting for triage or automation (Python or PowerShell)
  • Prior managed security services or multi-tenant SOC experience
  • Exposure to critical-infrastructure environments
  • Residency in the Hampton Roads through Richmond, VA corridor

Skill(s):

Technical Skills:

  • Incident investigation and containment
  • SIEM and EDR triage
  • Runbook and SOP development
  • Vulnerability management (Tenable)
  • Scripting for security automation
  • Multi-tenant SOC operations

Soft Skills:

  • Investigative judgment
  • Ownership under SLA pressure
  • Clear, auditable documentation
  • Cross-team escalation communication
  • Readiness to mentor Tier 1 analysts

Benefits & conditions

Pulled from the full job description

  • AD&D insurance
  • 401(k) matching
  • Paid time off
  • Health savings account
  • Dental insurance
  • Life insurance
  • Disability insurance, Medical - Multiple POS health plan options including an HSA-compatible plan

Dental - PPO coverage for preventive, basic, and major services

Vision - Annual exam, frames, lenses, and contact lens allowance

401(k) - Employer match up to 5% of eligible compensation

Long-Term Disability - 100% employer-paid coverage at 50% of pre-disability earnings

Life Insurance & AD&D - 100% employer-paid coverage valued at $10,000 each

PTO - 15-25 days annually based on tenure

Paid Federal Holidays - All 11 federal holidays observed

About the company

Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:50 min

Introduction and the value of runbooks

Hila Fish · World Congress 2023

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

1:32 min

Structuring automated incident workflows between runbooks and raw models

Aram Hakobyan Aram Hakobyan +1 · World Congress 2026 Europe

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all