Tier 2 SOC Analyst
Dragonfli Group · United States · 2 days ago
RemoteRemoteInformation TechnologyFull-time
Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments. Dragonfli is hiring a Tier 2 SOC Analyst to join our overnight security operations team. In this role, you will own deeper investigation, containment, and response actions for escalated SIEM and EDR alerts across client tenants, while developing and refining runbooks and standard operating procedures. You will meet strict response and resolution SLAs, track vulnerability findings, and communicate clearly with clients and the on-call lead throughout overnight events. This position is well suited to candidates with 3–5 years of hands-on SOC investigation and response experience. This is a contract position involving a large commercial enterprise in the transportation/logistics (critical infrastructure) sector. Candidates with previous consulting or contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S. Responsibilities:Conduct deeper investigation of escalated SIEM and EDR alerts across client tenantsInvestigate, contain within your authority, and escalate through the defined path with clear, documented handoffsDevelop and refine runbooks and standard operating proceduresTrack and validate vulnerability findings (Tenable) and route them into the correct workflowMeet strict response and resolution service levels on every event, every shiftOpen, update, and close tickets with accurate, auditable notes, and maintain clean shift logsCommunicate clearly with clients and the on-call lead during overnight eventsSupport monthly reporting with accurate event and response data Requirements: Must-Have:United States citizenshipAbility to pass a drug screening and a full background investigation, including verification of references, employment history, education, and certifications3–5 years of SOC or security operations experience, including hands-on incident investigation and responseDemonstrated experience with SIEM alerting and EDR alert triage and containmentSolid networking and operating-system fundamentals across Windows, macOS, and LinuxUnderstanding of the incident lifecycle: detection, triage, containment, and escalationAbility to work overnight shifts reliably on a rotation that includes weekends & holidaysClear written communication and disciplined documentation habits Preferred / Nice-to-Have:Experience with Microsoft Sentinel, Splunk, CrowdStrike or comparable EDR, and TenableSecurity+, CySA+, GCIH, GSEC, or a similar certificationScripting for triage or automation (Python or PowerShell)Prior managed security services or multi-tenant SOC experienceExposure to critical-infrastructure environmentsResidency in the Hampton Roads through Richmond, VA corridor Skill(s): Technical Skills:Incident investigation and containmentSIEM and EDR triageRunbook and SOP developmentVulnerability management (Tenable)Scripting for security automationMulti-tenant SOC operationsSoft Skills:Investigative judgmentOwnership under SLA pressureClear, auditable documentationCross-team escalation communicationReadiness to mentor Tier 1 analysts Benefits: Medical – Multiple POS health plan options including an HSA-compatible planDental – PPO coverage for preventive, basic, and major servicesVision – Annual exam, frames, lenses, and contact lens allowance401(k) – Employer match up to 5% of eligible compensationLong-Term Disability – 100% employer-paid coverage at 50% of pre-disability earningsLife Insurance & AD&D – 100% employer-paid coverage valued at $10,000 eachPTO – 15–25 days annually based on tenurePaid Federal Holidays – All 11 federal holidays observed