SOC Analyst Tier 2
JFL CONSULTING, LLC · Springfield, VA · 4 days ago
On-siteInformation Technology$90k–$140k/yrFull-time
Key Responsibilities
- Monitor SIEM dashboards and security tooling alerts
- Serve as the advanced triage for all incoming customer calls, alerts, emails, and tickets using established playbooks to categorize, prioritize, and route
- Create and manage detailed tickets for all confirmed or suspected events
- Receive, review, and investigate all Tier 1 escalations within SLA
- Perform deep log correlation across multiple data sources such as endpoint, network, application, identity
- Conduct PCAP analysis for network-based threat investigation
- Conduct root cause analysis or determine scope of compromise and identify affected systems, lateral movement, data exfiltration indicators
- Escalate confirmed incidents to Tier 3/IR with a complete documentation and investigation summary
- Tune false positive alerts
- Write clear and thorough investigation reports for all escalated incidents
- Mentor T1 analysts such as reviewing their triage decisions and provide coaching through their analysis
- Maintain and update playbooks based on new TTPs and lessons learned
- Maintain the SOC Event log for all events during the shift
- Maintain situational awareness of the threat landscape and active campaigns
- Participate briefings and training sessions
Requirements
- 3+ years of SOC analyst experience with hands-on investigation or threat hunting experience
- Bachelor's degree in Cyber Security, Information Technology, Computer Science, Information Security, or related field. In lieu of degree, four additional years of experience in a NOC, SOC, IT security, or network engineering role
- One of the following certifications, equivalent or better: Sec+, CYSA+, GCIH, SecX, CEH, GCIA, GSOC, CISSP
- Experience with SIEM platforms and log analysis
- Experience with SIEM query languages — SPL, KQL, or equivalent
- Experience with PCAP analysis tools (Wireshark, NetworkMiner, or equivalent)
- Strong understanding of attacker TTPs and MITRE ATT&CK framework
- Ability to work shifts including nights, weekends, and holidays on rotating shift schedule
Preferred Qualifications
- Active Secret clearance preferred but not required
- Experience with EDR platforms (CrowdStrike Falcon, SentinelOne, or equivalent)
- Memory forensics or malware triage experience