> Markdown version of [/jobs/ext/2592976-tier-2-soc-analyst](https://www.wearedevelopers.com/jobs/ext/2592976-tier-2-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Tier 2 SOC Analyst - **Company:** DRAGONFLI GROUP LLC - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Apple Mac Systems, Cyber Security, Linux, Python (Programming Language), Windows PowerShell, Runbook, Security Information and Event Management, Software Vulnerability Management, Scripting, Falcon Platform, Microsoft Sentinel, Splunk, Security Orchestration, Automation & Response - **Published:** August 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=664be6435a12ccb7 ## About the Role Dragonfli is hiring a Tier 2 SOC Analyst to join our overnight security operations team. In this role, you will own deeper investigation, containment, and response actions for escalated SIEM and EDR alerts across client tenants, while developing and refining runbooks and standard operating procedures. You will meet strict response and resolution SLAs, track vulnerability findings, and communicate clearly with clients and the on-call lead throughout overnight events. This position is well suited to candidates with 3-5 years of hands-on SOC investigation and response experience. This is a contract position involving a large commercial enterprise in the transportation/logistics (critical infrastructure) sector. Candidates with previous consulting or contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S., Must-Have: * United States citizenship * Ability to pass a drug screening and a full background investigation, including verification of references, employment history, education, and certifications * 3-5 years of SOC or security operations experience, including hands-on incident investigation and response * Demonstrated experience with SIEM alerting and EDR alert triage and containment * Solid networking and operating-system fundamentals across Windows, macOS, and Linux * Understanding of the incident lifecycle: detection, triage, containment, and escalation * Ability to work overnight shifts reliably on a rotation that includes weekends & holidays * Clear written communication and disciplined documentation habits Preferred / Nice-to-Have: * Experience with Microsoft Sentinel, Splunk, CrowdStrike or comparable EDR, and Tenable * Security+, CySA+, GCIH, GSEC, or a similar certification * Scripting for triage or automation (Python or PowerShell) * Prior managed security services or multi-tenant SOC experience * Exposure to critical-infrastructure environments * Residency in the Hampton Roads through Richmond, VA corridor Skill(s): Technical Skills: * Incident investigation and containment * SIEM and EDR triage * Runbook and SOP development * Vulnerability management (Tenable) * Scripting for security automation * Multi-tenant SOC operations Soft Skills: * Investigative judgment * Ownership under SLA pressure * Clear, auditable documentation * Cross-team escalation communication * Readiness to mentor Tier 1 analysts ## Description * Conduct deeper investigation of escalated SIEM and EDR alerts across client tenants * Investigate, contain within your authority, and escalate through the defined path with clear, documented handoffs * Develop and refine runbooks and standard operating procedures * Track and validate vulnerability findings (Tenable) and route them into the correct workflow * Meet strict response and resolution service levels on every event, every shift * Open, update, and close tickets with accurate, auditable notes, and maintain clean shift logs * Communicate clearly with clients and the on-call lead during overnight events * Support monthly reporting with accurate event and response data ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)