Tier 2 SOC Analyst — Contract, Part-Time, Remote

Summary

Remote Tier 2 SOC Analyst for a managed security services provider, triaging and investigating alerts across endpoint, identity, email, and network telemetry using SIEM/SOAR and EDR/XDR platforms (Microsoft Defender suite, Entra ID) for a public-sector transportation client.

Engagement

Contractor, Temporary - Ongoing

Schedule

Monday–Friday, approximately 09:00–14:00 ET or 14:00–19:00 ET. Start and end times can shift by about an hour either way; we'll agree to your exact window before you start.

Weekend

Sunday 09:00–13:00 ET, shared on a bi-weekly rotation

Hours

Approximately 20–30 per week, depending on coverage window and your availability.

Rate

$70–120 per hour depending on experience and shift/window.

Location

Fully remote, United States. Any time zone.

Term

Initial 90 days with intent to extend

Start

September 2026 or sooner. We're moving quickly and can accommodate an early start.

About the role

We are a managed security services provider seeking an experienced Tier 2 analyst to cover a defined window on a dedicated client account — a public-sector transportation agency with a mature, well-instrumented security stack. You will work alongside our wider SOC team, owning triage, containment, and investigation during your coverage window.

Responsibilities

  • Triage and disposition alerts and SOAR cases on the account queue, meeting agreed response targets by priority
  • Execute containment and remediation actions in line with established playbooks
  • Investigate escalated cases across endpoint, identity, email, and network telemetry, including forensic artifact review where warranted
  • Apply threat intelligence and indicators of compromise during triage
  • Identify false positives and submit tuning recommendations that reduce alert noise
  • Produce case documentation to a standard suitable for client review
  • Provide a written handoff at the close of your window
  • Contribute to runbook and knowledge base content for the account environment

Platforms

  • SIEM, SOAR case queue
  • EDR / Identity
  • Email Security
  • Microsoft Defender for Cloud Apps, Defender for Office 365, and Entra ID

Requirements

  • 3–5 years in a SOC or security operations role, with proven ability to work a queue and make disposition decisions independently
  • Strong proficiency with EDR/XDR platforms and SIEM triage workflows
  • Endpoint and network artifact analysis — registry entries, file system activity, event logs
  • Malware triage and behavioral analysis, including sandbox tooling such as VirusTotal or Any.run
  • Working knowledge of attacker tradecraft mapped to MITRE ATT&CK
  • Sound escalation judgment, with the context to justify decisions
  • Clear, structured written documentation — case notes are read by the client

Helpful, not required: direct experience with Google SecOps / Chronicle or CrowdStrike Identity Protection; scripting (PowerShell, Python, Bash, or SQL); detection tuning; prior MSSP or public sector experience.

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available