Lead Tier 2 SOC Analyst

Agile Defense

Washington (District of Columbia)

On-site

USD 110,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health Insurance
Life Insurance
Paid Time Off
Holiday Pay
Disability Insurance
Retirement Plan
Learning and Development

Job summary

Agile Defense is seeking a Lead Tier 2 SOC Analyst to guide incident response and drive CSIRC readiness on-site in Washington, D.C. The role requires coordinating end-to-end response, mentoring Tier 1/2 analysts, and collaborating with IT, legal, and compliance to protect critical missions.

You will develop and maintain incident response playbooks, use SIEM tools including ELK Stack, analyze threat intelligence, and ensure evidence integrity.

Qualifications

  • Bachelor's degree in Computer Science or IT related discipline.
  • 5 years of experience in security operations or incident response.

Responsibilities

  • Oversee end-to-end cybersecurity incident response lifecycle.
  • Analyze and prioritize security incidents escalated from Tier 1.
  • Create and maintain incident response playbooks and SOPs.
  • Coordinate response activities with IT, legal, compliance, and external stakeholders.
  • Collect and interpret threat intelligence from internal/external sources.
  • Communicate threat findings to Tier 1 and Tier 3 teams.
  • Use forensic tools to collect and preserve evidence with chain of custody.
  • Leverage SIEM systems to correlate events and identify patterns.
  • Serve as primary contact for CSIRC readiness.
  • Mentor Tier 1 and Tier 2 analysts on incident response.
  • Continuously enhance CSIRC capabilities, tools, and processes.
  • ELK Stack (Elasticsearch, Logstash, Kibana)

Skills

Incident response leadership
Threat intel analysis
SOPs & playbooks
Mentoring analysts
Cross-functional collaboration
ELK Stack usage

Education

Bachelor's degree in Computer Science or IT related disciplines

Tools

ELK Stack (Elasticsearch, Logstash, Kibana)
SIEM tools

Job description

About Agile Defense

At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next.

Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests.

Requisition #: 1763

Job Title: Lead Tier 2 SOC Analyst

Location: On-Site, Washington, D.C.

Job Description

We are looking for a Tier 2 SOC Analyst that can lead the team. They must be able to provide: incident response process, threat intelligence review, incident investigation and reporting. The Tier 2 team is inherently responsible for the clients Cybersecurity Incident Response Capability(CSIRC) and Privacy incidents response.

Education and Background

Bachelor's degree in Computer Science or IT related disciplines

Years of Experience

5 years

Required Skills

  • Oversee and coordinate the end-to-end cybersecurity incident response lifecycle, including preparation, identification, containment, eradication, recovery, and lessons learned.
  • Analyze and prioritize security incidents escalated from Tier 1 SOC analysts, ensuring timely and effective response to mitigate risks.
  • Create, update, and maintain incident response playbooks, standard operating procedures (SOPs), and workflows to ensure consistency and efficiency in handling incidents.
  • Coordinate Response Activities: Collaborate with cross-functional teams (e.g., IT, legal, compliance, and external stakeholders) during incident response to ensure alignment and effective resolution.
  • Collect, review, and interpret threat intelligence from internal and external sources (e.g., open-source intelligence, commercial feeds, or industry reports) to identify potential threats and vulnerabilities.
  • Communicate relevant threat intelligence findings to Tier 1 and Tier 3 teams, as well as other stakeholders, to improve situational awareness and preparedness.
  • Use forensic tools and techniques to collect and preserve evidence, ensuring chain of custody for potential legal or regulatory purposes.
  • Leverage Security Information and Event Management (SIEM) systems and other tools to correlate events and identify patterns of malicious activity.
  • Serve as the primary point of contact for the organization’s Cybersecurity Incident Response Capability, ensuring the team is prepared to handle incidents effectively.
  • Guide and mentor Tier 1 and Tier 2 analysts, providing training on incident response techniques, tools, and best practices.
  • Continuously assess and enhance the CSIRC’s capabilities, including tools, processes, and team readiness, to address evolving threats.
  • ELK Stack (Elasticsearch, Logstash, Kibana)

Working Conditions

On-site in Washington D.C. 4/5 times a week.

$110,000 - $130,000 a year

In addition, Agile Defense invests in its employees beyond just compensation. Agile’s benefits offerings include, dependent upon position, Health Insurance, Life Insurance, Paid Time Off, Holiday Pay, short-term and long-term Disability, Retirement and Learning and Development opportunities as well as other optional benefit elections.

Our Core Values

Employees of Agile Defense are our number one priority, and the importance we place on our culture here is fundamental. Our culture is alive and evolving, but it always stays true to its roots. Here, you are valued as a family member, and we believe that we can accomplish great things together. Agile Defense has been highly successful in the past few years due to our employees and the culture we create together.

What makes us Agile? We call it the 6Hs, the values that define our culture and guide everything we do. Together, these values infuse vibrancy, integrity, and a tireless work ethic into advancing the most important national security and critical civilian missions. It’s how we show up every day. It’s who we are.

  • Happy - Be Infectious. Happiness multiplies and creates a positive and connected environment where motivation and satisfaction have an outsized effect on everything we do.
  • Helpful - Be Supportive. Being helpful is the foundation of teamwork, resulting in a supportive atmosphere where collaboration flourishes, and collective success is celebrated.
  • Honest - Be Trustworthy. Honesty serves as our compass, ensuring transparent communication and ethical conduct, essential to who we are and the complex domains we support.
  • Humble - Be Grounded. Success is not achieved alone, humility ensures a culture of mutual respect, encouraging open communication, and a willingness to learn from one another and take on any task.
  • Hungry - Be Eager. Our hunger for excellence drives an insatiable appetite for innovation and continuous improvement, propelling us forward in the face of new and unprecedented challenges.
  • Hustle - Be Driven. Hustle is reflected in our relentless work ethic, where we are each committed to going above and beyond to advance the mission and achieve success.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Tier 1 SOC Analyst
Tier 1 SOC Analyst

Agile Defense, LLC • Washington

On-site
USD 70,000 - 80,000
Health Insurance
Life Insurance
Paid Time Off
+4
Tier 1 SOC Analyst
Tier 1 SOC Analyst

Agile Defense • Washington

On-site
USD 70,000 - 80,000
Health Insurance
Life Insurance
Paid Time Off
+5
Cyber Threat Intelligence Lead
Cyber Threat Intelligence Lead

Agile Defense, LLC • Reston (VA)

Hybrid
USD 155,000 - 180,000
Security Engineering Lead
Security Engineering Lead

Agile Defense, LLC • Reston (VA)

Hybrid
USD 165,000 - 201,000
Deputy Program Manager
Deputy Program Manager

Agile Defense • Ashburn (VA)

Hybrid
USD 120,000 - 180,000
Security Operations Center Manager
Security Operations Center Manager

Agile Defense • Reston (VA)

Hybrid
USD 120,000 - 150,000
Competitive benefits package
Supportive work culture
Mentorship opportunities
Incident Response Team Lead
Incident Response Team Lead

Agile Defense, LLC • Reston (VA)

Hybrid
USD 155,000 - 180,000
Security Engineering Lead
Security Engineering Lead

Agile Defense • Reston (VA)

On-site
USD 120,000 - 150,000
Competitive benefits package
Hybrid work environment
Cyber Threat Intelligence Analyst
Cyber Threat Intelligence Analyst

Agile Defense, LLC • Arlington (VA)

Hybrid
USD 120,000 - 145,000
Cyber Threat Intelligence Lead
Cyber Threat Intelligence Lead

Agile Defense • Reston (VA)

On-site
USD 120,000 - 150,000