Dragonfly AI Logo

Dragonfly AI

Tier 2 SOC Analyst

Posted 6 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in GBR
Mid level
Remote
Hiring Remotely in GBR
Mid level
Overnight Tier 2 SOC Analyst responsible for deep investigation, containment, and escalation of SIEM and EDR alerts, developing runbooks/SOPs, tracking vulnerabilities (Tenable), meeting SLA response/resolution targets, maintaining auditable tickets and shift logs, and communicating with clients and on-call leads.
The summary above was generated by AI
Description

Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.

Dragonfli is hiring a Tier 2 SOC Analyst to join our overnight security operations team. In this role, you will own deeper investigation, containment, and response actions for escalated SIEM and EDR alerts across client tenants, while developing and refining runbooks and standard operating procedures. You will meet strict response and resolution SLAs, track vulnerability findings, and communicate clearly with clients and the on-call lead throughout overnight events. This position is well suited to candidates with 3–5 years of hands-on SOC investigation and response experience.

This is a contract position involving a large commercial enterprise in the transportation/logistics (critical infrastructure) sector. Candidates with previous consulting or contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.

Responsibilities:

  • Conduct deeper investigation of escalated SIEM and EDR alerts across client tenants
  • Investigate, contain within your authority, and escalate through the defined path with clear, documented handoffs
  • Develop and refine runbooks and standard operating procedures
  • Track and validate vulnerability findings (Tenable) and route them into the correct workflow
  • Meet strict response and resolution service levels on every event, every shift
  • Open, update, and close tickets with accurate, auditable notes, and maintain clean shift logs
  • Communicate clearly with clients and the on-call lead during overnight events
  • Support monthly reporting with accurate event and response data
Requirements

Must-Have:

  • United States citizenship
  • Ability to pass a drug screening and a full background investigation, including verification of references, employment history, education, and certifications
  • 3–5 years of SOC or security operations experience, including hands-on incident investigation and response
  • Demonstrated experience with SIEM alerting and EDR alert triage and containment
  • Solid networking and operating-system fundamentals across Windows, macOS, and Linux
  • Understanding of the incident lifecycle: detection, triage, containment, and escalation
  • Ability to work overnight shifts reliably on a rotation that includes weekends & holidays
  • Clear written communication and disciplined documentation habits

Preferred / Nice-to-Have:

  • Experience with Microsoft Sentinel, Splunk, CrowdStrike or comparable EDR, and Tenable
  • Security+, CySA+, GCIH, GSEC, or a similar certification
  • Scripting for triage or automation (Python or PowerShell)
  • Prior managed security services or multi-tenant SOC experience
  • Exposure to critical-infrastructure environments
  • Residency in the Hampton Roads through Richmond, VA corridor
Skill(s)

Technical Skills:

  • Incident investigation and containment
  • SIEM and EDR triage
  • Runbook and SOP development
  • Vulnerability management (Tenable)
  • Scripting for security automation
  • Multi-tenant SOC operations

Soft Skills:

  • Investigative judgment
  • Ownership under SLA pressure
  • Clear, auditable documentation
  • Cross-team escalation communication
  • Readiness to mentor Tier 1 analysts
Benefits

Medical – Multiple POS health plan options including an HSA-compatible plan

Dental – PPO coverage for preventive, basic, and major services

Vision – Annual exam, frames, lenses, and contact lens allowance

401(k) – Employer match up to 5% of eligible compensation

Long-Term Disability – 100% employer-paid coverage at 50% of pre-disability earnings

Life Insurance & AD&D – 100% employer-paid coverage valued at $10,000 each

PTO – 15–25 days annually based on tenure

Paid Federal Holidays – All 11 federal holidays observed

Similar Jobs

2 Hours Ago
In-Office or Remote
Senior level
Senior level
Blockchain • Fintech • Payments • Financial Services • Cryptocurrency • Web3
The Senior Solutions Engineer II will lead technical solutions for Capital Markets, working with Business Development and clients to design and implement scalable solutions, provide market feedback, and support integrations.
Top Skills: APIsBlockchainDatabasesFintechSaaSWeb3
11 Hours Ago
Remote or Hybrid
Senior level
Senior level
AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
Lead strategic sourcing and procurement across the organisation: develop category strategies, manage supplier relationships and contracts, drive cost savings and risk mitigation, ensure governance and compliance (UK), champion sustainability/ESG and digital procurement, and lead and mentor procurement teams while partnering with senior stakeholders.
Top Skills: AribaJaggaerOracleSAP
12 Hours Ago
Remote
United Kingdom
Senior level
Senior level
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Manage enterprise customer relationships to drive adoption, expansion, and value realization across Atlassian products. Develop Success Plans, run QBRs, mitigate churn, collaborate with account teams, and provide customer feedback to internal teams to support product and business outcomes.
Top Skills: AIBi ToolsConfluenceGainsightJIRASaaSSalesforceTableau

What you need to know about the Belfast Tech Scene

If asked to name the birthplace of the RMS Titanic, you might not say Belfast. Similarly, if asked to name Europe's leading destination for foreign direct investment in new software development, Belfast might not come to mind. Yet, both are true. The city has emerged as a tech powerhouse, recently ranked among the best in the U.K. for tech careers — especially for software developers. It also leads the U.K. with the highest percentage of software development jobs advertised.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account