Description
Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.
Responsibilities:
- Conduct deeper investigation of escalated SIEM and EDR alerts across client tenants
- Investigate, contain within your authority, and escalated through the defined path with clear, documented handoffs
- Develop and refine runbooks and standard operating procedures
- Track and validate vulnerability findings (Tenable) and route them into the correct workflow
- Meet strict response and resolution service levels on every event, every shift
- Open, update, and close tickets with accurate, auditable notes, and maintain clean shift logs
- Communicate clearly with clients and the on-call lead during overnight events
- Support monthly reporting with accurate event and response data
Requirements
Must-Have:
- United States citizenship
- Ability to pass a drug screening and a full background investigation, including verification of references, employment history, education, and certifications
- 3-5 years of SOC or security operations experience, including hands-on incident investigation and response
- Demonstrated experience with SIEM alerting and EDR alert triage and containment
- Solid networking and operating-system fundamentals across Windows, macOS, and Linux
- Understanding of the incident lifecycle: detection, triage, containment, and escalation
- Ability to work overnight shifts reliably on a rotation that includes weekends & holidays
- Clear written communication and disciplined documentation habits
Preferred / Nice-to-Have:
- Experience with Microsoft Sentinel, Splunk, CrowdStrike or comparable EDR, and Tenable
- Security+, CySA+, GCIH, GSEC, or a similar certification
- Scripting for triage or automation (Python or PowerShell)
- Prior managed security services or multi-tenant SOC experience
- Exposure to critical-infrastructure environments
- Residency in the Hampton Roads through Richmond, VA corridor
Skill(s)
Technical Skills:
- Incident investigation and containment
- SIEM and EDR triage
- Runbook and SOP development
- Vulnerability management (Tenable)
- Scripting for security automation
- Multi-tenant SOC operations
Soft Skills:
- Investigative judgment
- Ownership under SLA pressure
- Clear, auditable documentation
- Cross-team escalation communication
- Readiness to mentor Tier 1 analysts
Benefits
Medical - Multiple POS health plan options including an HSA-compatible plan
Dental - PPO coverage for preventive, basic, and major services
Vision - Annual exam, frames, lenses, and contact lens allowance
401(k) - Employer match up to 5% of eligible compensation
Long-Term Disability - 100% employer-paid coverage at 50% of pre-disability earnings
Life Insurance & AD&D - 100% employer-paid coverage valued at $10,000 each
PTO - 15-25 days annually based on tenure
Paid Federal Holidays - All 11 federal holidays observed