SOC Analyst Tier 2

JFL Consulting LLCSpringfield, VA
$90,000 - $140,000Onsite

About The Position

We're looking for a SOC Analyst Tier 2 to serve as the primary investigation tier in the operations center. Tier 2 analysts receive escalations from Tier 1, conduct in-depth log correlation and threat analysis, perform PCAP review, and determine whether an incident requires Tier 3 or incident response escalation.

Requirements

  • 3+ years of SOC analyst experience with hands-on investigation or threat hunting experience
  • Bachelor's degree in Cyber Security, Information Technology, Computer Science, Information Security, or related field. In lieu of degree, four additional years of experience in a NOC, SOC, IT security, or network engineering role
  • One of the following certifications, equivalent or better: Sec+, CYSA+, GCIH, SecX, CEH, GCIA, GSOC, CISSP
  • Experience with SIEM platforms and log analysis
  • Experience with SIEM query languages — SPL, KQL, or equivalent
  • Experience with PCAP analysis tools (Wireshark, NetworkMiner, or equivalent)
  • Strong understanding of attacker TTPs and MITRE ATT&CK framework
  • Ability to work shifts including nights, weekends, and holidays on rotating shift schedule

Nice To Haves

  • Active Secret clearance preferred but not required
  • Experience with EDR platforms (CrowdStrike Falcon, SentinelOne, or equivalent)
  • Memory forensics or malware triage experience

Responsibilities

  • Monitor SIEM dashboards and security tooling alerts
  • Serve as the advanced triage for all incoming customer calls, alerts, emails, and tickets using established playbooks to categorize, prioritize, and route
  • Create and manage detailed tickets for all confirmed or suspected events
  • Receive, review, and investigate all Tier 1 escalations within SLA
  • Perform deep log correlation across multiple data sources such as endpoint, network, application, identity
  • Conduct PCAP analysis for network-based threat investigation
  • Conduct root cause analysis or determine scope of compromise and identify affected systems, lateral movement, data exfiltration indicators
  • Escalate confirmed incidents to Tier 3/IR with a complete documentation and investigation summary
  • Tune false positive alerts Tier 3 and Tier 4 engineers to reduce
  • Write clear and thorough investigation reports for all escalated incidents
  • Mentor T1 analysts such as reviewing their triage decisions and provide coaching through their analysis
  • Maintain and update playbooks based on new TTPs and lessons learned
  • Maintain the SOC Event log for all events during the shift
  • Maintain situational awareness of the threat landscape and active campaigns
  • Participate briefings and training sessions

Benefits

  • 100% employer-paid medical, dental, and vision premiums for employees and dependents
  • Flexible Spending Accounts (healthcare, dependent care, and commuter)
  • Life insurance, short-term disability and long-term disability
  • 401(k) with immediate vesting of company contribution
  • Generous PTO policy (15 vacation, 5 sick, 2 personal days, 11 holidays)
  • Certification reimbursement
  • Dedicated professional development funding
  • Company-provided access to online learning platforms
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service