Lead Tier 2 SOC Analyst

Posted 3 Days Ago
Be an Early Applicant
Washington, DC, USA
In-Office
110K-130K Annually
Senior level
Information Technology • Software • Cybersecurity • Defense
The Role
Lead Tier 2 SOC Analyst to manage end-to-end incident response, investigate and prioritize incidents, maintain playbooks, perform forensics, ingest threat intelligence, mentor analysts, and improve CSIRC capabilities using SIEM and ELK stack.
Summary Generated by Built In
About Agile Defense
 
At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next.
 
Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests.

Requisition #: 1763
Job Title: Lead Tier 2 SOC Analyst
Location: On-Site, Washington, D.C.
 

Job Description

    We are looking for a Tier 2 SOC Analyst that can lead the team. They must be able to provide: incident response process, threat intelligence review, incident investigation and reporting. The Tier 2 team is inherently responsible for the clients Cybersecurity Incident Response Capability(CSIRC) and Privacy incidents response.

Education and Background

    Bachelor's degree in Computer Science or IT related disciplines

Years of Experience

    5 years

Required Skills

  • Oversee and coordinate the end-to-end cybersecurity incident response lifecycle, including preparation, identification, containment, eradication, recovery, and lessons learned.
  • Analyze and prioritize security incidents escalated from Tier 1 SOC analysts, ensuring timely and effective response to mitigate risks.
  • Create, update, and maintain incident response playbooks, standard operating procedures (SOPs), and workflows to ensure consistency and efficiency in handling incidents.
  • Coordinate Response Activities: Collaborate with cross-functional teams (e.g., IT, legal, compliance, and external stakeholders) during incident response to ensure alignment and effective resolution.
  • Collect, review, and interpret threat intelligence from internal and external sources (e.g., open-source intelligence, commercial feeds, or industry reports) to identify potential threats and vulnerabilities.
  • Communicate relevant threat intelligence findings to Tier 1 and Tier 3 teams, as well as other stakeholders, to improve situational awareness and preparedness.
  • Use forensic tools and techniques to collect and preserve evidence, ensuring chain of custody for potential legal or regulatory purposes.
  • Leverage Security Information and Event Management (SIEM) systems and other tools to correlate events and identify patterns of malicious activity.
  • Serve as the primary point of contact for the organization’s Cybersecurity Incident Response Capability, ensuring the team is prepared to handle incidents effectively.
  • Guide and mentor Tier 1 and Tier 2 analysts, providing training on incident response techniques, tools, and best practices.
  • Continuously assess and enhance the CSIRC’s capabilities, including tools, processes, and team readiness, to address evolving threats.
  • ELK Stack (Elasticsearch, Logstash, Kibana)

Working Conditions

    On-site in Washington D.C. 4/5 times a week.

Our Core Values
 
Employees of Agile Defense are our number one priority, and the importance we place on our culture here is fundamental. Our culture is alive and evolving, but it always stays true to its roots. Here, you are valued as a family member, and we believe that we can accomplish great things together. Agile Defense has been highly successful in the past few years due to our employees and the culture we create together. 
 
What makes us Agile? We call it the 6Hs, the values that define our culture and guide everything we do. Together, these values infuse vibrancy, integrity, and a tireless work ethic into advancing the most important national security and critical civilian missions. It's how we show up every day. It's who we are.
 
  • Happy - Be Infectious. Happiness multiplies and creates a positive and connected environment where motivation and satisfaction have an outsized effect on everything we do.
  • Helpful - Be Supportive. Being helpful is the foundation of teamwork, resulting in a supportive atmosphere where collaboration flourishes, and collective success is celebrated.
  • Honest - Be Trustworthy. Honesty serves as our compass, ensuring transparent communication and ethical conduct, essential to who we are and the complex domains we support.
  • Humble - Be Grounded. Success is not achieved alone, humility ensures a culture of mutual respect, encouraging open communication, and a willingness to learn from one another and take on any task.
  • Hungry - Be Eager. Our hunger for excellence drives an insatiable appetite for innovation and continuous improvement, propelling us forward in the face of new and unprecedented challenges.
  • Hustle - Be Driven. Hustle is reflected in our relentless work ethic, where we are each committed to going above and beyond to advance the mission and achieve success.
 
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities

Skills Required

  • Bachelor's degree in Computer Science or IT related discipline
  • Minimum 5 years of relevant experience
  • Oversee and coordinate end-to-end incident response lifecycle (preparation, identification, containment, eradication, recovery, lessons learned)
  • Analyze and prioritize security incidents escalated from Tier 1 SOC analysts
  • Create, update, and maintain incident response playbooks, SOPs, and workflows
  • Coordinate response activities with IT, legal, compliance, and external stakeholders
  • Collect, review, and interpret threat intelligence from internal and external sources
  • Communicate threat intelligence findings to Tier 1/Tier 3 teams and stakeholders
  • Use forensic tools and techniques to collect and preserve evidence with chain of custody
  • Leverage SIEM systems to correlate events and identify malicious activity
  • Serve as primary point of contact for the organization's Cybersecurity Incident Response Capability (CSIRC)
  • Guide and mentor Tier 1 and Tier 2 analysts; provide training on response techniques and tools
  • Continuously assess and enhance CSIRC capabilities, tools, processes, and readiness
  • Experience with ELK Stack (Elasticsearch, Logstash, Kibana)
  • On-site presence in Washington, D.C., approximately 4/5 times per week
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: McLean, VA
2,000 Employees
Year Founded: 1998

What We Do

Agile Defense is a technology services company that provides advanced digital transformation, data analytics, and cybersecurity solutions to support critical national security and civilian government missions. With a global presence, the company focuses on delivering outcome-driven, AI-powered capabilities to solve complex mission challenges for federal and defense customers.

Similar Jobs

FourKites Logo FourKites

Enterprise Account Executive

Artificial Intelligence • Big Data • Logistics • Machine Learning • Software • Transportation
Easy Apply
Remote or Hybrid
USA
475 Employees
140K-170K Annually

Samsara Logo Samsara

Consultant

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United States
4000 Employees
101K-153K Annually

Samsara Logo Samsara

Consultant

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United States
4000 Employees
101K-153K Annually

Samsara Logo Samsara

Engagement Services Manager

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United States
4000 Employees
101K-153K Annually

Similar Companies Hiring

Outpost Space Thumbnail
Aerospace • Defense
US
24 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account