1

Level 2 Soc Analyst Jobs (NOW HIRING)

Provide expert-level guidance to Tier 1 and Tier 2 SOC analysts; coach and mentor to raise team capabilities. * Correlate threat intelligence with incident data to understand adversary behavior and ...

The SOC Analyst executes and helps to create operational processes for consistent monitoring of ... CompTIA CySA+ certification/ or a CompTIA Security+ (or other relevant IAT Level II/III ...

The SOC Analyst executes and helps to create operational processes for consistent monitoring of ... CompTIA CySA+ certification/ or a CompTIA Security+ (or other relevant IAT Level II/III ...

Provide expert-level guidance to Tier 1 and Tier 2 SOC analysts; coach and mentor to raise team capabilities. * Correlate threat intelligence with incident data to understand adversary behavior and ...

The SOC Analyst executes and helps to create operational processes for consistent monitoring of ... CompTIA CySA+ certification/ or a CompTIA Security+ (or other relevant IAT Level II/III ...

SOC Analyst

Alexandria, VA · On-site

$150K - $165K/yr

The SOC Analyst will be responsible for monitoring, analyzing, investigating, and responding to ... DoD 8570 IAT Level II (or higher) certifications prior to start date (CompTIA Sec+, SSCP etc)

Candidate must have a minimum of 1-2 years of experience as an analyst in a SOC or similar environment. * Working knowledge of various SOC tools and their usage for detecting intrusion attempts.

SOC Analyst

Alexandria, VA · On-site

$150K - $165K/yr

The SOC Analyst will be responsible for monitoring, analyzing, investigating, and responding to ... DoD 8570 IAT Level II (or higher) certifications prior to start date (CompTIA Sec+, SSCP etc)

Candidate must have a minimum of 1-2 years of experience as an analyst in a SOC or similar environment. * Working knowledge of various SOC tools and their usage for detecting intrusion attempts.

Candidate must have a minimum of 1-2 years of experience as an analyst in a SOC or similar environment. * Working knowledge of various SOC tools and their usage for detecting intrusion attempts.

SOC Analyst

Buffalo, NY · On-site +1

$68K - $80K/yr

We are in search of a talented SOC Analyst to join Cegeka's Modern SOC As SOC Analyst you are a key ... Security related certifications (such as GIAC, CompTIA, CEH, Blue Team Level 1/2) are a plus. * You ...

Candidate must have a minimum of 2-4 years of experience as an analyst in a SOC or similar environment. * Working knowledge of SOC tools and their usage for detecting intrusion attempts.

SOC Analyst

Buffalo, NY · On-site +1

$68K - $85K/yr

We are in search of a talented SOC Analyst to join Cegeka's Modern SOC As SOC Analyst you are a key ... Security related certifications (such as GIAC, CompTIA, CEH, Blue Team Level 1/2) are a plus. * You ...

Candidate must have a minimum of 2-4 years of experience as an analyst in a SOC or similar environment. * Working knowledge of SOC tools and their usage for detecting intrusion attempts.

SOC Analyst

Denver, CO · On-site

$31.25 - $40/hr

Candidate must have a minimum of 2-4 years of experience as an analyst in a SOC or similar environment. * Working knowledge of SOC tools and their usage for detecting intrusion attempts.

SOC Analyst

Baltimore, MD · On-site

$31.25 - $40.87/hr

Candidate must have a minimum of 2-4 years of experience as an analyst in a SOC or similar environment. * Working knowledge of SOC tools and their usage for detecting intrusion attempts.

Candidate must have a minimum of 2-4 years of experience as an analyst in a SOC or similar environment. * Working knowledge of SOC tools and their usage for detecting intrusion attempts.

next page

Showing results 1-20

Level 2 Soc Analyst information

See salary details

$33K

$76.3K

$124K

How much do level 2 soc analyst jobs pay per year?

As of Jun 14, 2026, the average yearly pay for level 2 soc analyst in the United States is $76,273.00, according to ZipRecruiter salary data. Most workers in this role earn between $57,500.00 and $90,000.00 per year, depending on experience, location, and employer.

What is the difference between Level 2 Soc Analyst vs Level 1 Soc Analyst?

AspectLevel 2 Soc AnalystLevel 1 Soc Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+ or equivalent
Work EnvironmentAdvanced security operations center, handling complex incidentsEntry-level monitoring and alert analysis
ResponsibilitiesAnalyzing security alerts, escalating incidents, and providing guidanceMonitoring alerts, initial triage, and basic incident response

The main difference between a Level 2 Soc Analyst and a Level 1 Soc Analyst lies in experience, responsibilities, and complexity of tasks. Level 2 analysts handle more complex security incidents, perform detailed analysis, and often guide Level 1 analysts. They typically hold additional certifications and have a deeper understanding of security tools and procedures.

What are the key skills and qualifications needed to thrive as a Level 2 SOC Analyst, and why are they important?

To thrive as a Level 2 SOC Analyst, you need strong analytical skills, a solid understanding of cybersecurity principles, and experience with incident detection and response, typically supported by a relevant degree or certifications like CompTIA Security+ or CISSP. Familiarity with SIEM platforms (such as Splunk or QRadar), intrusion detection systems, and ticketing tools is crucial for efficient threat monitoring and investigation. Attention to detail, problem-solving abilities, and effective communication are essential soft skills for collaborating with IT teams and escalating security incidents. These skills ensure timely identification, analysis, and mitigation of security threats to protect organizational assets.

What are the main challenges Level 2 SOC Analysts face when prioritizing and escalating security incidents?

Level 2 SOC Analysts often encounter challenges in differentiating between true security threats and benign anomalies, especially when dealing with high volumes of alerts. Prioritizing incidents requires strong analytical skills and a deep understanding of the organization’s environment to assess potential impact. Effective escalation involves clear communication with both internal teams and external stakeholders, ensuring that critical incidents are addressed promptly while minimizing false positives. Continuous learning and situational awareness are key to managing these responsibilities efficiently.

What are Level 2 SOC Analysts?

Level 2 SOC Analysts are cybersecurity professionals who monitor, analyze, and respond to security incidents within an organization's Security Operations Center (SOC). They handle more complex threats and escalated incidents that require deeper investigation compared to entry-level analysts. Their responsibilities include performing in-depth analysis of security alerts, conducting root cause investigations, and coordinating with other teams to remediate threats. Level 2 analysts also support continuous improvement of security monitoring processes and may mentor junior analysts.

How much does a L2 SOC analyst make?

A Level 2 SOC analyst typically earns between $60,000 and $90,000 annually, depending on experience, certifications, and location. They often work with security tools like SIEM platforms and require strong analytical skills to monitor and respond to security incidents.

What is a level 2 SOC analyst?

A Level 2 SOC analyst is a cybersecurity professional responsible for monitoring security alerts, analyzing threats, and responding to incidents within a Security Operations Center. They typically use security tools like SIEM systems and have skills in threat detection, incident response, and basic forensic analysis. This role often requires experience with security protocols and may involve working in shifts to ensure 24/7 coverage.

What jobs in the US pay 300,000 a year?

For a Level 2 SOC Analyst, earning $300,000 annually is uncommon; such salaries are typically associated with executive roles or specialized positions in cybersecurity, finance, or technology sectors. High-paying cybersecurity roles often require extensive experience, advanced certifications, and leadership responsibilities, and salaries can vary based on location and organization size.

Can you make $500,000 a year in cyber security?

A Level 2 SOC Analyst typically earns between $60,000 and $100,000 annually, depending on experience and location. Reaching a $500,000 salary usually requires advanced roles such as senior security managers, architects, or executives, often combined with bonuses, stock options, or consulting work. High salaries in cybersecurity generally involve specialized skills, certifications, and leadership responsibilities.
More about Level 2 Soc Analyst jobs
What cities are hiring for Level 2 Soc Analyst jobs? Cities with the most Level 2 Soc Analyst job openings:
What states have the most Level 2 Soc Analyst jobs? States with the most job openings for Level 2 Soc Analyst jobs include:
SOC Analyst & Incident Response Lead

SOC Analyst & Incident Response Lead

Avaya

OR • Hybrid

Other

Posted 7 days ago


Job description

About Avaya

Avaya is an enterprise software leader that helps the world's largest organizations and government agencies forge unbreakable connections.

The Avaya Infinity platform unifies fragmented customer experiences, connecting the channels, insights, technologies, and workflows that together create enduring customer and employee relationships.

We believe success is built through strong connections - with each other, with our work, and with our mission. At Avaya, you'll find a community that values your contributions and supports your growth every step of the way.

Learn more at https://www.avaya.com

Job Information

Job Code: 00270114

Job Family: Information Technology

Job Function: Information Security

Job Description

We are seeking a highly skilled and experienced Tier 3 SOC Analyst who will also function as the Incident Response Lead. This is a hybrid technical-leadership position focused on managing critical security events, conducting forensic investigations, and continuously enhancing the incident response program. As a senior member of the SOC, you will be the escalation point for complex and high-impact security incidents, support forensic analysis, lead root cause investigations, and contribute to detection engineering efforts. 

Key Responsibilities 

Tier 3 SOC Analyst Duties 

  • Act as the final escalation point for complex security alerts and incidents identified through Azure Sentinel and other security monitoring tools. 

  • Conduct in-depth digital forensic investigations across endpoints, networks, and cloud infrastructure (Azure, M365, Microsoft Dynamics etc.). 

  • Perform malware analysis, reverse engineering, and memory/disk analysis to support incident triage and response. 

  • Provide expert-level guidance to Tier 1 and Tier 2 SOC analysts; coach and mentor to raise team capabilities. 

  • Correlate threat intelligence with incident data to understand adversary behavior and campaign objectives. 

  • Collaborate with SIEM engineers to tune, develop, and optimize detection use cases, particularly for emerging threats. 

  • Maintain documentation of playbooks, threat scenarios, and incident patterns. 

  • Assist in management of suite of security tools. 

Incident Response Lead Duties 

  • Lead and coordinate the end-to-end incident response lifecycle, from detection through containment, eradication, and recovery. 

  • Own and maintain IR documentation including incident tracking, timelines, RCA, and after-action reports. 

  • Liaise with the CSIRT team and relevant business stakeholders during critical incidents. 

  • Lead post-incident reviews and facilitate lessons learned workshops, contributing to policy, procedure, and control improvements. 

  • Drive continuous process improvement across SOC and IR operations, ensuring integration with change and problem management. 

  • Ensure executive-level incident reporting and briefings are prepared and delivered as needed. 


Qualifications

Required 

  • 5+ years of experience in a Security Operations Center or Incident Response role. 

  • Proven experience leading major incident response efforts (e.g., ransomware, APT, data breaches). 

  • Strong forensic analysis skills (disk, memory, log, and network forensics). 

  • Advanced proficiency in SIEM platforms (preferably Microsoft Sentinel), EDR tools (Defender for Endpoint), and forensic toolsets. 

  • Understanding of attacker TTPs mapped to MITRE ATT&CK and threat hunting methodologies. 

  • Hands-on experience with scripting and automation (e.g., PowerShell, Python) to streamline investigations and response. 

  • Knowledge of security controls, network protocols, operating systems, and cloud environments (Azure). 

  • U.S. citizenship is required for this position.
  • Strong communication skills and ability to present technical findings to non-technical stakeholders. 

  • Must be available to work outside of working hours when necessary.

Desirable Certifications 

  • GIAC Certified Forensic Analyst (GCFA) or GIAC Certified Incident Handler (GCIH) 

  • CISSP, OSCP, GCIA, or equivalent 

  • Microsoft certifications: SC-200, SC-300, AZ-500 

Key Competencies 

  • Calm and decisive under pressure 

  • Analytical and detail-oriented 

  • Strong leadership and collaboration skills 

  • Proactive approach to process optimization and threat mitigation 

  • Passion for continuous learning and capability development

The pay range for this opportunity is from $93,000 to $125,500 + bonus potential + benefits.  This range represents the anticipated low and high end of the salary for this position. Actual salaries will vary and are based on factors such as a candidate's qualifications, skills, competencies.

#LI-CS1

Experience
3 - 6 Years of Experience
Education
Bachelor degree or equivalent experience
Footer

Applicants must be currently authorized to work in the United States without the need for visa sponsorship now or in the future.

Avaya is an Equal Opportunity employer and a U.S. Federal Contractor. Our commitment to equality is a core value of Avaya. All qualified applicants and employees receive equal treatment without consideration for race, religion, sex, age, sexual orientation, gender identity, national origin, disability, status as a protected veteran or any other protected characteristic. In general, positions at Avaya require the ability to communicate and use office technology effectively. Physical requirements may vary by assigned work location. This job brief/description is subject to change. Nothing in this job description restricts Avaya right to alter the duties and responsibilities of this position at any time for any reason.