Enable job alerts via email!

SOC Analyst (Tier 2/3) – Splunk / Endpoint Security

Blue Cyber

Washington (District of Columbia)

Hybrid

USD 90,000

Full time

Yesterday
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a skilled SOC Analyst (Tier 2) to enhance its security operations team. This hybrid role focuses on analyzing threat activity and investigating endpoint security events during evening shifts. Ideal candidates will thrive in fast-paced environments, enjoy resolving security incidents, and aspire to grow into leadership roles. The position offers a supportive team-oriented environment with opportunities for mentorship and professional development. If you're passionate about cybersecurity and eager to make an impact, this role is perfect for you.

Qualifications

  • 2-5 years in SOC or cybersecurity operations role required.
  • Proficiency in Splunk and endpoint security tools essential.

Responsibilities

  • Monitor and triage Splunk notables for investigation.
  • Produce actionable end-of-shift reports and present findings.

Skills

Splunk
Endpoint Security Tools
Incident Reporting
Threat Behavior Analysis
Communication Skills

Education

CompTIA Security+
Network+
Splunk Certification

Tools

Microsoft Defender
Cisco Firepower
Sysmon

Job description

SOC Analyst (Tier 2/3) – Splunk / Endpoint Security

3 days ago Be among the first 25 applicants

Get AI-powered advice on this job and more exclusive features.

SOC Analyst (Tier 2) – Splunk / Endpoint Security

Evening Shift | 3:00 PM – 11:00 PM EST

Salary: $90,000

About the Role

Blue Cyber is seeking a skilled SOC Analyst (Tier 2) to join our security operations team. This hybrid role involves analyzing threat activity, triaging Splunk notables, and investigating endpoint security events during the evening shift. Success involves identifying threats, correlating behaviors, and contributing insights to daily reports.

This position is ideal for cybersecurity professionals who thrive in fast-paced environments, enjoy resolving security incidents, and are interested in growth into leadership or shift-lead roles.

Responsibilities
  • Monitor and triage Splunk notables, identifying events for further investigation
  • Use tools like Microsoft Defender, Apex, and Cisco Firepower to assess and contain threats
  • Analyze Sysmon logs and endpoint activity to understand process behavior and root causes
  • Produce clear, actionable end-of-shift reports and present findings during daily turnover calls
  • Support team coordination and incident documentation as a backup to the shift lead
  • Stay updated on cyber threat trends and suggest process improvements
Qualifications

Required:

  • 2–5 years in a SOC, incident response, or cybersecurity operations role
  • Proficiency in Splunk, endpoint security tools, and investigative workflows
  • Familiarity with Sysmon logging, process trees, and threat behavior analysis
  • Ability to perform IOC hunting, detect lateral movement, and respond to behavioral anomalies
  • Excellent communication skills, including incident reporting

Preferred:

  • Certifications such as CompTIA Security+, Network+, or Splunk
  • Knowledge of the MITRE ATT&CK framework
  • Experience working second shift or independently during off-hours
  • Hybrid work model: 4 days on-site, 1 day remote
  • Team-oriented environment with growth and mentorship opportunities
  • U.S. work authorization; security clearance is a plus but not mandatory
Additional Details
  • Seniority level: Mid-Senior level
  • Employment type: Full-time
  • Job function: Information Technology
  • Industries: IT Services and IT Consulting
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior SOC Security Analyst / US Citizenship / 100% ONSITE

VISUAL SOFT, INC

Washington

Hybrid

USD 70,000 - 110,000

Today
Be an early applicant

Senior SOC Security Analyst - US Citizenship - 100% ONSITE

VISUAL SOFT, INC

Washington

Hybrid

USD 80,000 - 110,000

Yesterday
Be an early applicant

SOC Analyst with Security Clearance

NasTech Global, Inc.

Arlington

On-site

USD 70,000 - 100,000

5 days ago
Be an early applicant

Senior Splunk Engineer

Omm IT Solutions

Annapolis

On-site

USD 80,000 - 120,000

3 days ago
Be an early applicant

Enterprise Jamf Engineer

Sev1Tech

Arlington

Hybrid

USD 70,000 - 110,000

12 days ago

Enterprise Jamf Engineer

Sev1Tech LLC

Arlington

Hybrid

USD 60,000 - 95,000

12 days ago

Sys Admin (MS Endpoint Config Mngr)

Leidos

Washington

On-site

USD 72,000 - 131,000

10 days ago

Sys Admin (MS Endpoint Config Mngr)

Via Logic LLC

Cypress

On-site

USD 72,000 - 131,000

5 days ago
Be an early applicant

SOC Analyst - Tier 1 (ONSITE)

Serigor Inc

Washington

On-site

USD 60,000 - 100,000

30+ days ago