> Markdown version of [/jobs/ext/591350-tier-2-soc-analyst](https://www.wearedevelopers.com/jobs/ext/591350-tier-2-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Tier 2 SOC Analyst - **Company:** CGI Technologies and Solutions, Inc. - **Location:** Knoxville, TN, United States - **Experience:** Experienced - **Salary:** $63,700.0 - $139,300.0 - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Microsoft Windows, Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cyber Security, Computer Programming, Query Languages, Linux, Monitoring of Systems, Intrusion Detection and Prevention, Python (Programming Language), Networking Basics, Network Protocols, Red Hat Enterprise Linux, Kusto Query Language, Security Information and Event Management, Working Model 2D, Malware, Cyber Threat Analysis, Falcon Platform, Information Technology, Cybercrime, Microsoft Sentinel, Splunk - **Published:** June 12, 2026 - **Apply:** https://www.juju.com/job/00000000g7ff4a ## About the Role A strong background in cybersecurity, information security, or information technology. . 2-5 years SOC monitoring, incident response or threat analysis . Understanding of network fundamentals, Windows/Linux systems and security tools . Familiarity with SIEM, EDR/XDR or cloud security monitoring tools. . Deep understanding of network protocols, operating systems (Windows/Linux), malware behavior, and common attack tactics (TTPs) . Excellent verbal and written communication skills. . Ability to remain calm and effective in a fast-paced, team-oriented environment. . Demonstrated analytical and problem-solving skills. . US Citizenship, with eligibility to obtain a public trust clearance. Desired qualifications: . Proficiency at least one security tool query language (SPL, KQL, XQL) . Proficiency in at least one programing language, such as Python or JavaScript. . Technical Knowledge: Deep understanding of network protocols, operating systems (Windows/Linux), malware behavior, and common attack tactics (TTPs). . Certifications such as GCIH, ECIH, or CySA+. Due to the nature of this government contract, US Citizenship and the ability to obtain a Public Trust clearance is required., + Operational Security + Security Analysis + Cyber + Security Architecture + Threat Risk Assessment ## Description CGI Federal is expanding its Security Operations Center (SOC) capabilities in Knoxville, TN. As cyber threats become more advanced, our analysts play a critical role in protecting federal systems and sensitive information. This opportunity is ideal for early-career to mid-level cybersecurity professionals seeking hands-on SOC experience, access to modern detection and response technologies, and a clear pathway to specializations such as threat intelligence, incident response, automation, and cloud security. Candidates will join a collaborative, mission-focused environment supported by experienced analysts and operational playbooks to ensure consistent service delivery. This position is located in our Knoxville, TN office; however, a hybrid working model is acceptable. This role requires shift work, operating on 12-hour shifts on the Panama 2-2-3 Rotation: Teams work 2 days, off 2 days, work 3 days, off 2 days, work 2 days, off 3 days. Your future duties and responsibilities: . Monitor and triage security events using playbooks, SIEM tools, and case management systems. . Respond to alerts, escalations, identify false positives, and escalate incidents for deeper analysis and resolution. . Collaborate with senior analysts and subject matter experts to resolve incidents and enhance detection capabilities. . Contribute to the creation and continuous improvement of security runbooks and operational procedures. . Support monthly reporting and contribute to threat and trend analysis. . Stay current with emerging threats and participate in team training initiatives to expand your technical skills. . Gain hands-on experience across a range of security technologies including Splunk, Microsoft Sentinel, Defender, CrowdStrike, Red Hat, AWS and Azure security services, and SOAR platforms. ## Related Videos - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)