Summary
Dragonfli Group is a cybersecurity and IT consulting firm serving federal agencies and Fortune 100 enterprises by securing mission-critical systems. The company is hiring a Tier 2 SOC Analyst for its overnight security operations team to investigate, contain, and respond to escalated SIEM and EDR alerts, manage vulnerability findings, maintain runbooks, meet service-level agreements, and communicate with clients during security events.
Responsibilities
- Conduct deeper investigation of escalated SIEM and EDR alerts across client tenants
- Investigate, contain within your authority, and escalate through the defined path with clear, documented handoffs
- Develop and refine runbooks and standard operating procedures
- Track and validate vulnerability findings (Tenable) and route them into the correct workflow
- Meet strict response and resolution service levels on every event, every shift
- Open, update, and close tickets with accurate, auditable notes, and maintain clean shift logs
- Communicate clearly with clients and the on-call lead during overnight events
- Support monthly reporting with accurate event and response data
Skills
- United States citizenship
- Ability to pass a drug screening and a full background investigation, including verification of references, employment history, education, and certifications
- 3–5 years of SOC or security operations experience, including hands-on incident investigation and response
- Demonstrated experience with SIEM alerting and EDR alert triage and containment
- Solid networking and operating-system fundamentals across Windows, macOS, and Linux
- Understanding of the incident lifecycle: detection, triage, containment, and escalation
- Ability to work overnight shifts reliably on a rotation that includes weekends & holidays
- Clear written communication and disciplined documentation habits
- Experience with Microsoft Sentinel, Splunk, CrowdStrike or comparable EDR, and Tenable
- Security+, CySA+, GCIH, GSEC, or a similar certification
- Scripting for triage or automation (Python or PowerShell)
- Prior managed security services or multi-tenant SOC experience
- Exposure to critical-infrastructure environments
- Residency in the Hampton Roads through Richmond, VA corridor
Qualifications
Must Haves
- United States citizenship
- Ability to pass a drug screening and a full background investigation, including verification of references, employment history, education, and certifications
- 3–5 years of SOC or security operations experience, including hands-on incident investigation and response
- Demonstrated experience with SIEM alerting and EDR alert triage and containment
- Solid networking and operating-system fundamentals across Windows, macOS, and Linux
- Understanding of the incident lifecycle: detection, triage, containment, and escalation
- Ability to work overnight shifts reliably on a rotation that includes weekends & holidays
- Clear written communication and disciplined documentation habits
Nice to Haves
- Experience with Microsoft Sentinel, Splunk, CrowdStrike or comparable EDR, and Tenable
- Security+, CySA+, GCIH, GSEC, or a similar certification
- Scripting for triage or automation (Python or PowerShell)
- Prior managed security services or multi-tenant SOC experience
- Exposure to critical-infrastructure environments
- Residency in the Hampton Roads through Richmond, VA corridor
Benefits
- Medical – Multiple POS health plan options including an HSA-compatible plan
- Dental – PPO coverage for preventive, basic, and major services
- Vision – Annual exam, frames, lenses, and contact lens allowance
- 401(k) – Employer match up to 5% of eligible compensation
- Long-Term Disability – 100% employer-paid coverage at 50% of pre-disability earnings
- Life Insurance & AD&D – 100% employer-paid coverage valued at $10,000 each
- PTO – 15–25 days annually based on tenure
- Paid Federal Holidays – All 11 federal holidays observed