Tier 2 SOC Analyst

Dragonfli Group

Washington (District of Columbia)

Hybrid

USD 85,000 - 130,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical plan with HSA options
Dental coverage
Vision coverage
401(k) employer match
Long-Term Disability
Life Insurance & AD&D
PTO 15–25 days yearly
Paid Federal Holidays

Job summary

Dragonfli Group, a Washington, DC-based cybersecurity and IT consulting firm, seeks a SOC Analyst to investigate escalated SIEM/EDR alerts, contain incidents, and drive runbooks and SOPs. The role covers on-site, hybrid, and remote environments, with overnight shifts on a rotation including weekends and holidays.

Qualified candidates have 3–5 years in SOC, strong Windows/macOS/Linux fundamentals, and relevant certifications; U.S. citizenship is required. Background checks will be performed.

Qualifications

  • United States citizenship is required.
  • Ability to pass a full background investigation and drug screening.
  • 3–5 years of SOC or security operations experience with hands-on incident response.
  • Experience with SIEM alerting and EDR triage/containment.

Responsibilities

  • Conduct deep investigations of escalated SIEM/EDR alerts across client tenants.
  • Contain within authority and escalate per defined process with clear handoffs.
  • Develop and refine runbooks and standard operating procedures.
  • Track vulnerabilities (Tenable) and route findings into workflows.
  • Meet strict SLA targets for incident response and resolution.
  • Open/update/close tickets with auditable notes and shift logs.
  • Communicate clearly with clients and on-call leads during overnight events.
  • Support monthly reporting with accurate event data.

Skills

Incident investigation & containment
SIEM & EDR triage
Runbook & SOP development
Vulnerability management (Tenable)
Security automation scripting
Multi-tenant SOC operations

Education

Security+, CySA+, GCIH, GSEC or equivalent certification

Tools

Microsoft Sentinel
Splunk
CrowdStrike / EDR
Tenable

Job description

Description

Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.

Responsibilities:
  • Conduct deeper investigation of escalated SIEM and EDR alerts across client tenants
  • Investigate, contain within your authority, and escalated through the defined path with clear, documented handoffs
  • Develop and refine runbooks and standard operating procedures
  • Track and validate vulnerability findings (Tenable) and route them into the correct workflow
  • Meet strict response and resolution service levels on every event, every shift
  • Open, update, and close tickets with accurate, auditable notes, and maintain clean shift logs
  • Communicate clearly with clients and the on-call lead during overnight events
  • Support monthly reporting with accurate event and response data
Requirements
Must-Have:
  • United States citizenship
  • Ability to pass a drug screening and a full background investigation, including verification of references, employment history, education, and certifications
  • 3-5 years of SOC or security operations experience, including hands-on incident investigation and response
  • Demonstrated experience with SIEM alerting and EDR alert triage and containment
  • Solid networking and operating-system fundamentals across Windows, macOS, and Linux
  • Understanding of the incident lifecycle: detection, triage, containment, and escalation
  • Ability to work overnight shifts reliably on a rotation that includes weekends & holidays
  • Clear written communication and disciplined documentation habits
Preferred / Nice-to-Have:
  • Experience with Microsoft Sentinel, Splunk, CrowdStrike or comparable EDR, and Tenable
  • Security+, CySA+, GCIH, GSEC, or a similar certification
  • Scripting for triage or automation (Python or PowerShell)
  • Prior managed security services or multi-tenant SOC experience
  • Exposure to critical-infrastructure environments
  • Residency in the Hampton Roads through Richmond, VA corridor
Skill(s)
Technical Skills:
  • Incident investigation and containment
  • SIEM and EDR triage
  • Runbook and SOP development
  • Vulnerability management (Tenable)
  • Scripting for security automation
  • Multi-tenant SOC operations
Soft Skills:
  • Investigative judgment
  • Ownership under SLA pressure
  • Clear, auditable documentation
  • Cross-team escalation communication
  • Readiness to mentor Tier 1 analysts
Benefits

Medical - Multiple POS health plan options including an HSA-compatible plan

Dental - PPO coverage for preventive, basic, and major services

Vision - Annual exam, frames, lenses, and contact lens allowance

401(k) - Employer match up to 5% of eligible compensation

Long-Term Disability - 100% employer-paid coverage at 50% of pre-disability earnings

Life Insurance & AD&D - 100% employer-paid coverage valued at $10,000 each

PTO - 15-25 days annually based on tenure

Paid Federal Holidays - All 11 federal holidays observed

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Tier 2 SOC Analyst: Incident Response & SIEM Expert
Tier 2 SOC Analyst: Incident Response & SIEM Expert

Dragonfli Group • Washington

Hybrid
USD 85,000 - 130,000
Medical plan with HSA options
Dental coverage
Vision coverage
+5
Mid-Level SOC Analyst
Mid-Level SOC Analyst

Adept Consulting Services, Inc. • Harrisburg

On-site
USD 70,000 - 100,000
Health Care Plan (Medical, Dental &amp
Vision Coverage
Retirement Plan (401k)
+1
Cybersecurity Analyst, Security Operations Center (SOC) Analyst
Cybersecurity Analyst, Security Operations Center (SOC) Analyst

Digital Global Connectors • McLean (VA)

Hybrid
USD 70,000 - 110,000
Cybersecurity Analyst, Security Operations Center (SOC) Analyst
Cybersecurity Analyst, Security Operations Center (SOC) Analyst

Digital-Global-Connectors • McLean (VA)

Hybrid
USD 90,000 - 130,000
SOC Tier 1 Analyst
SOC Tier 1 Analyst

ECS • Portland (OR)

On-site
USD 65,000 - 90,000
SOC Analyst - Tier 1
SOC Analyst - Tier 1

Evans & Chambers • Maryland

On-site
USD 88,000 - 118,000
SOC Analyst Tier 2 (Q Clearance)
SOC Analyst Tier 2 (Q Clearance)

ShorePoint, LLC • North Las Vegas (NV)

On-site
USD 80,000 - 100,000
18 days of PTO
11 holidays
85% of insurance premium covered
+2
SOC Analyst - Tier 1
SOC Analyst - Tier 1

Evans & Chambers • Fort Meade (MD)

On-site
USD 88,000 - 118,000
T1 Cyber Network Defense Analyst – Shift (w/ active TS)
T1 Cyber Network Defense Analyst – Shift (w/ active TS)

Critical Solutions • Washington

Hybrid
USD 58,000 - 74,000
Medical Insurance (100% Premium)
Dental Insurance (100% Premium)
Vision Insurance (100% Premium)
+4
Tier 1 SOC Analyst
Tier 1 SOC Analyst

Agile Defense • Washington

On-site
USD 70,000 - 80,000
Health Insurance
Life Insurance
Paid Time Off
+5