Skip to content
← Back to job listings

Lead Tier 2 SOC Analyst

agile-defense · Washington, DC, United States

Electronics EngineeringLeadQuick applyfull-timeabout 13 hours ago

About The Role

About Agile Defense

At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next.

Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests.

Job Description

We are looking for a Tier 2 SOC Analyst that can lead the team. They must be able to provide: incident response process, threat intelligence review, incident investigation and reporting. The Tier 2 team is inherently responsible for the clients Cybersecurity Incident Response Capability(CSIRC) and Privacy incidents response.

Education and Background

Bachelor's degree in Computer Science or IT related disciplines

Years of Experience

5 years

Required Skills

  • Oversee and coordinate the end-to-end cybersecurity incident response lifecycle, including preparation, identification, containment, eradication, recovery, and lessons learned.
  • Analyze and prioritize security incidents escalated from Tier 1 SOC analysts, ensuring timely and effective response to mitigate risks.
  • Create, update, and maintain incident response playbooks, standard operating procedures (SOPs), and workflows to ensure consistency and efficiency in handling incidents.
  • Coordinate Response Activities: Collaborate with cross-functional teams (e.g., IT, legal, compliance, and external stakeholders) during incident response to ensure alignment and effective resolution.
  • Collect, review, and interpret threat intelligence from internal and external sources (e.g., open-source intelligence, commercial feeds, or industry reports) to identify potential threats and vulnerabilities.
  • Communicate relevant threat intelligence findings to Tier 1 and Tier 3 teams, as well as other stakeholders, to improve situational awareness and preparedness.
  • Use forensic tools and techniques to collect and preserve evidence, ensuring chain of custody for potential legal or regulatory purposes.
  • Leverage Security Information and Event Management (SIEM) systems and other tools to correlate events and identify patterns of malicious activity.
  • Serve as the primary point of contact for the organization’s Cybersecurity Incident Response Capability, ensuring the team is prepared to handle incidents effectively.
  • Guide and mentor Tier 1 and Tier 2 analysts, providing training on incident response techniques, tools, and best practices.
  • Continuously assess and enhance the CSIRC’s capabilities, including tools, processes, and team readiness, to address evolving threats.
  • ELK Stack (Elasticsearch, Logstash, Kibana)

Working Conditions

On-site in Washington D.C. 4/5 times a week.

This listing was posted by a verified recruiter at agile-defense. Report this listing