> Markdown version of [/jobs/ext/3555138-soc-tier-two-analyst](https://www.wearedevelopers.com/jobs/ext/3555138-soc-tier-two-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SOC Tier Two Analyst - **Company:** Strategic Inc - **Location:** United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** CompTIA Security+, Intrusion Detection Systems, NetFlow, Network Forensics, Packet Analyzer, Comptia Pentest+ CE, Security Information and Event Management, SC Clearance, Information Technology, 3-tier Architectures, Cyber Warfare, Blue Team (Cyber Security) - **Published:** October 2, 2026 - **Apply:** https://www.thejobnetwork.com/job/9b454682-5a36-425d-a72d-849297177339/soc-tier-two-analyst ## About the Role · Minimum 3 years of documented relevant experience. Relevant cyber defense analysis and incident investigation experience, including SIEM, network traffic analysis, multi-source correlation, and incident documentation. · DoD Cyber Workforce Framework (DCWF) 511, Cyber Defense Analyst, Intermediate proficiency. · Meet DoDM 8140.03 qualification requirements for every assigned work role and proficiency through an approved education, training, certification, or authorized experience route before independent cyber work. Document work-role appointment and qualification; maintain required residential qualification and continuing learning. A higher-level approved option may qualify the same role at a lower level. · Current matrix-listed certification options for 511 Intermediate: CEH(P), Cloud+, FITSP-O, GCED, GDSA, GMON, GRID, GSEC, PenTest+, Security+. Knowledge, Skills and Abilities · Demonstrated knowledge of Multi-source correlation, network traffic analysis, incident investigation, evidence preservation, and standardized response. · Proficiency with SIEM, EDR, NetFlow, packet capture, IDS/IPS, and incident-management systems appropriate to assigned duties and approved access. · Ability to produce accurate records, explain findings and decisions, and follow approved procedures and security requirements. · Strong written and verbal communication skills and sound judgment when coordinating with technical staff and Government stakeholders. · Strong organizational skills, confidentiality, and ability to work independently and collaboratively in a mission-focused environment. Preferred Qualifications · Experience investigating incidents in a DoD or enterprise security operations center. · Relevant DoD or enterprise IT experience with mission tooling and operational reporting. Security Clearance Active SECRET clearance and ability to maintain assigned system access. U.S. citizenship is required. Supervisory Responsibilities No formal supervisory responsibilities; provides technical review and coaching to Tier 1 analysts. Work Environment and Physical Requirements Work is primarily performed on site in a secure Government facility using computer systems and standard office equipment. The employee must be able to perform sustained computer-based analysis or coordination, communicate effectively, and support operational activities outside standard business hours when assigned. Mission-essential watch roles may include shifts, weekends, and holidays. Reasonable accommodations may be made to enable qualified individuals with disabilities to perform the essential functions of the position. ## Description Strategic Operational Solutions (STOPSO) is seeking a SOC Tier 2 Analyst to support the U.S. Army Reserve Command (USARC) Defensive Cyberspace Operations Mission Support Services (DCOMSS) program at Fort Bragg, North Carolina. Investigate escalated cyber events, correlate multiple telemetry sources, maintain incident records, and recommend response actions. The Tier 2 Analyst provides deeper analysis and quality review within the Blue Team., · Investigate escalated alerts using SIEM, EDR, network flow, packet, firewall, authentication, proxy, and host data. · Develop event timelines, identify affected systems and indicators, and assess scope and potential mission impact. · Recommend containment and eradication steps to authorized Government personnel and track approved actions. · Maintain incident records and required portal updates through closure, with evidence and rationale for decisions. · Review Tier 1 tickets for completeness and coach analysts on investigation and documentation quality. · Escalate complex intrusions and suspected advanced activity to Tier 3; support shifts and exercises as assigned. · Perform other duties as assigned consistent with the position's responsibilities, qualifications, clearance, and authorized scope. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)