Tier 2 SOC Analyst — Contract, Part-Time, Remote
Summary
A part-time, contract-based SOC Tier 2 Analyst triages, investigates, and contains security incidents for a U.S. public-sector transportation agency’s security stack, using SIEM/SOAR, EDR, and Microsoft 365 tools to handle alerts, escalations, and forensic reviews while documenting cases for client review.
|
Engagement |
Contractor, Temporary - Ongoing |
|
Schedule |
Monday–Friday, approximately 09:00–14:00 ET or 14:00–19:00 ET. Start and end times can shift by about an hour either way; we'll agree to your exact window before you start. |
|
Weekend |
Sunday 09:00–13:00 ET, shared on a bi-weekly rotation |
|
Hours |
Approximately 20–30 per week, depending on coverage window and your availability. |
|
Rate |
$70–120 per hour depending on experience and shift/window. |
|
Location |
Fully remote, United States. Any time zone. |
|
Term |
Initial 90 days with intent to extend |
|
Start |
September 2026 or sooner. We're moving quickly and can accommodate an early start. |
About the role
We are a managed security services provider seeking an experienced Tier 2 analyst to cover a defined window on a dedicated client account — a public-sector transportation agency with a mature, well-instrumented security stack. You will work alongside our wider SOC team, owning triage, containment, and investigation during your coverage window.
Responsibilities
- Triage and disposition alerts and SOAR cases on the account queue, meeting agreed response targets by priority
- Execute containment and remediation actions in line with established playbooks
- Investigate escalated cases across endpoint, identity, email, and network telemetry, including forensic artifact review where warranted
- Apply threat intelligence and indicators of compromise during triage
- Identify false positives and submit tuning recommendations that reduce alert noise
- Produce case documentation to a standard suitable for client review
- Provide a written handoff at the close of your window
- Contribute to runbook and knowledge base content for the account environment
Platforms
- SIEM, SOAR case queue
- EDR / Identity
- Email Security
- Microsoft Defender for Cloud Apps, Defender for Office 365, and Entra ID
Requirements
- 3–5 years in a SOC or security operations role, with proven ability to work a queue and make disposition decisions independently
- Strong proficiency with EDR/XDR platforms and SIEM triage workflows
- Endpoint and network artifact analysis — registry entries, file system activity, event logs
- Malware triage and behavioral analysis, including sandbox tooling such as VirusTotal or Any.run
- Working knowledge of attacker tradecraft mapped to MITRE ATT&CK
- Sound escalation judgment, with the context to justify decisions
- Clear, structured written documentation — case notes are read by the client
Helpful, not required: direct experience with Google SecOps / Chronicle or CrowdStrike Identity Protection; scripting (PowerShell, Python, Bash, or SQL); detection tuning; prior MSSP or public sector experience.