Tier 2 SOC Analyst — Contract, Part-Time, Remote
Remote
Contractor
Engagement
Contractor, Temporary - Ongoing
Schedule
Monday–Friday, approximately 09:00–14:00 ET or 14:00–19:00 ET. Start and end times can shift by about an hour either way; we'll agree to your exact window before you start.
Weekend
Sunday 09:00–13:00 ET, shared on a bi-weekly rotation
Hours
Approximately 20–30 per week, depending on coverage window and your availability.
Rate
$70–120 per hour depending on experience and shift/window.
Location
Fully remote, United States. Any time zone.
Term
Initial 90 days with intent to extend
Start
September 2026 or sooner. We're moving quickly and can accommodate an early start.
About the role
We are a managed security services provider seeking an experienced Tier 2 analyst to cover a defined window on a dedicated client account — a public-sector transportation agency with a mature, well-instrumented security stack. You will work alongside our wider SOC team, owning triage, containment, and investigation during your coverage window.
Responsibilities
- Triage and disposition alerts and SOAR cases on the account queue, meeting agreed response targets by priority
- Execute containment and remediation actions in line with established playbooks
- Investigate escalated cases across endpoint, identity, email, and network telemetry, including forensic artifact review where warranted
- Apply threat intelligence and indicators of compromise during triage
- Identify false positives and submit tuning recommendations that reduce alert noise
- Produce case documentation to a standard suitable for client review
- Provide a written handoff at the close of your window
- Contribute to runbook and knowledge base content for the account environment
Platforms
- SIEM, SOAR case queue
- EDR / Identity
- Email Security
- Microsoft Defender for Cloud Apps, Defender for Office 365, and Entra ID
Requirements
- 3–5 years in a SOC or security operations role, with proven ability to work a queue and make disposition decisions independently
- Strong proficiency with EDR/XDR platforms and SIEM triage workflows
- Endpoint and network artifact analysis — registry entries, file system activity, event logs
- Malware triage and behavioral analysis, including sandbox tooling such as VirusTotal or Any.run
- Working knowledge of attacker tradecraft mapped to MITRE ATT&CK
- Sound escalation judgment, with the context to justify decisions
- Clear, structured written documentation — case notes are read by the client
Helpful, not required: direct experience with Google SecOps / Chronicle or CrowdStrike Identity Protection; scripting (PowerShell, Python, Bash, or SQL); detection tuning; prior MSSP or public sector experience.
Loading Job Application......