Tier 2 SOC Analyst — Contract, Part-Time, Remote

Remote
Contractor

Engagement

Contractor, Temporary - Ongoing

Schedule

Monday–Friday, approximately 09:00–14:00 ET or 14:00–19:00 ET. Start and end times can shift by about an hour either way; we'll agree to your exact window before you start.

Weekend

Sunday 09:00–13:00 ET, shared on a bi-weekly rotation

Hours

Approximately 20–30 per week, depending on coverage window and your availability.

Rate

$70–120 per hour depending on experience and shift/window.

Location

Fully remote, United States. Any time zone.

Term

Initial 90 days with intent to extend

Start

September 2026 or sooner. We're moving quickly and can accommodate an early start.

About the role

We are a managed security services provider seeking an experienced Tier 2 analyst to cover a defined window on a dedicated client account — a public-sector transportation agency with a mature, well-instrumented security stack. You will work alongside our wider SOC team, owning triage, containment, and investigation during your coverage window.

Responsibilities

  • Triage and disposition alerts and SOAR cases on the account queue, meeting agreed response targets by priority
  • Execute containment and remediation actions in line with established playbooks
  • Investigate escalated cases across endpoint, identity, email, and network telemetry, including forensic artifact review where warranted
  • Apply threat intelligence and indicators of compromise during triage
  • Identify false positives and submit tuning recommendations that reduce alert noise
  • Produce case documentation to a standard suitable for client review
  • Provide a written handoff at the close of your window
  • Contribute to runbook and knowledge base content for the account environment

Platforms

  • SIEM, SOAR case queue
  • EDR / Identity
  • Email Security
  • Microsoft Defender for Cloud Apps, Defender for Office 365, and Entra ID

 

 

Requirements

  • 3–5 years in a SOC or security operations role, with proven ability to work a queue and make disposition decisions independently
  • Strong proficiency with EDR/XDR platforms and SIEM triage workflows
  • Endpoint and network artifact analysis — registry entries, file system activity, event logs
  • Malware triage and behavioral analysis, including sandbox tooling such as VirusTotal or Any.run
  • Working knowledge of attacker tradecraft mapped to MITRE ATT&CK
  • Sound escalation judgment, with the context to justify decisions
  • Clear, structured written documentation — case notes are read by the client

Helpful, not required: direct experience with Google SecOps / Chronicle or CrowdStrike Identity Protection; scripting (PowerShell, Python, Bash, or SQL); detection tuning; prior MSSP or public sector experience.

Loading Job Application......

If you have questions, please contact careers@stig.net