1

Soc 2 Analyst Jobs (NOW HIRING)

SOC Analyst Tier 3

Springfield, VA ยท On-site

$140K - $180K/yr

Generous PTO policy (15 vacation, 5 sick, 2 personal days, 11 holidays) * We support your growth ... SOC Analyst Tier 3 and Incident Responder , a senior analyst role in the SOC. This role leads the ...

SOC Analyst Tier 3

Springfield, VA ยท On-site

$140K - $180K/yr

Generous PTO policy (15 vacation, 5 sick, 2 personal days, 11 holidays) * We support your growth ... SOC Analyst Tier 3 and Incident Responder , a senior analyst role in the SOC. This role leads the ...

SOC Analyst II

Monterey, CA ยท On-site

$39 - $44/hr

As the SOC Analyst II, you will provide tier II cybersecurity support in a Security Operations Center "SOC" environment. Daily responsibilities of the SOC are ever changing, however, you can expect ...

Lead Security & Compliance Analyst

OR ยท On-site +1

$80K - $135K/yr

Own SOC 1, SOC 2, HITRUST CSF, and HITRUST AI audits end-to-end: scoping, evidence collection ... Support security incident response: log analysis, forensic evidence collection, and containment

Job Title: IT Compliance Analyst Location: Tempe, AZ Division: Operations Department: IT Operations ... SOC 2, CMMC, etc.). Duties and Responsibilities โ— IT Security Risk and Privacy Assessments ...

SR. CYBER ASSURANCE ANALYST, FINANCE Cyber Assurance is the practice of providing confidence that ... Lead and support ITGC testing, SOC 1, SOC 2, SOX-related IT controls, and other relevant audits ...

Sr. Cyber Assurance Analyst, Finance

Hawthorne, CA ยท On-site

$101K - $130K/yr

... CYBER ASSURANCE ANALYST, FINANCE Cyber Assurance is the practice of providing confidence that ... Lead and support ITtesting, SOC 1, SOC 2, SOX-related IT controls, and other relevant audits ...

Senior GRC Analyst

Pittsburgh, PA ยท On-site

$114K - $163K/yr

Senior GRC Analyst Department: Compliance & Fraud Employment Type: Full Time Location: Pittsburgh ... Run our annual PCI DSS v4.0.1 Level 1 service provider assessment and SOC 2 Type II examination end ...

Sr. Cyber Assurance Analyst, Finance

Redmond, WA ยท On-site

$112K - $144K/yr

... CYBER ASSURANCE ANALYST, FINANCE Cyber Assurance is the practice of providing confidence that ... Lead and support ITtesting, SOC 1, SOC 2, SOX-related IT controls, and other relevant audits ...

NY ยท On-site

$100.78/hr

Serve as the primary coordinator for SOC 1, SOC 2, and SOX audits -- managing PBC (Provided-by ... Data Analytics or automated control testing experience. * Familiarity with data privacy and ...

SOC Analyst Tier 3

Springfield, VA ยท On-site

$140 - $180/hr

Generous PTO policy (15 vacation, 5 sick, 2 personal days, 11 holidays) * We support your growth ... SOC Analyst Tier 3 and Incident Responder , a senior analyst role in the SOC. This role leads the ...

Sr. Cyber Assurance Analyst, Finance

Hawthorne, CA ยท On-site

$101K - $131K/yr

... CYBER ASSURANCE ANALYST, FINANCE Cyber Assurance is the practice of providing confidence that ... Lead and support ITGC testing, SOC 1, SOC 2, SOX-related IT controls, and other relevant audits ...

Showing results 41-60

Soc 2 Analyst information

See salary details

$32K

$84.2K

$133.5K

How much do soc 2 analyst jobs pay per year?

As of Aug 22, 2026, the average yearly pay for soc 2 analyst in the United States is $84,207.00, according to ZipRecruiter salary data. Most workers in this role earn between $65,000.00 and $98,500.00 per year, depending on experience, location, and employer.

What is a SOC 2 analyst?

A SOC 2 Analyst is a professional who specializes in helping organizations achieve and maintain SOC 2 compliance, which is a widely recognized standard for managing customer data based on five trust service criteria: security, availability, processing integrity, confidentiality, and privacy. They assess internal controls, identify potential risks, and ensure that processes meet the requirements for a SOC 2 audit. SOC 2 Analysts also assist with preparing documentation, conducting risk assessments, and working with auditors to address any gaps or findings. Their work is essential for companies that handle sensitive client data and need to demonstrate trustworthiness to clients and partners.

What are the key skills and qualifications needed to thrive as a SOC 2 analyst?

To thrive as a SOC 2 Analyst, you need a solid understanding of information security principles, risk assessment methodologies, and relevant compliance frameworks, usually supported by a degree in information security or a related field. Familiarity with audit tools, governance, risk, and compliance (GRC) platforms, and certifications such as CISA or CISSP are commonly required. Attention to detail, analytical thinking, and strong communication skills help SOC 2 Analysts effectively interpret controls and coordinate with stakeholders. These competencies are crucial for ensuring organizations meet SOC 2 requirements and maintain trust with clients and regulatory bodies.

What are some common challenges faced by SOC 2 analysts when preparing for an audit?

SOC 2 Analysts often encounter challenges such as ensuring all relevant security controls are properly documented and consistently followed across departments. Coordinating with various teams to gather evidence and remediate gaps within tight deadlines can also be demanding. Additionally, staying updated on evolving compliance requirements and translating technical controls into auditor-friendly documentation requires strong communication and organizational skills. Proactively addressing these challenges helps ensure a smoother audit process and ongoing compliance.

What is the difference between Soc 2 Analyst vs Security Analyst?

AspectSoc 2 AnalystSecurity Analyst
CertificationsSOC 2, CISSP, CISACISSP, Security+, CEH
Work EnvironmentAuditing, compliance, risk assessmentThreat detection, incident response, security monitoring
Industry UsageIT service providers, SaaS companiesAny organization with cybersecurity needs

While both roles focus on security, a Soc 2 Analyst primarily ensures compliance with SOC 2 standards through audits and assessments, whereas a Security Analyst concentrates on protecting systems from threats and managing security incidents. The Soc 2 Analyst's work is more compliance and audit-oriented, often within service providers, while Security Analysts work across various industries to safeguard digital assets.

Is a SOC 2 analyst still in demand?

Yes, SOC 2 analysts are in demand due to increasing cybersecurity and data privacy concerns. Organizations seek professionals with expertise in security frameworks, compliance standards, and audit processes to ensure their systems meet SOC 2 requirements.
More about Soc 2 Analyst jobs

What are the most commonly searched types of Soc 2 Analyst jobs?

The most popular types of Soc 2 Analyst jobs are:

Infographic showing various Soc 2 Analyst job openings in the United States as of August 2026, with employment types broken down into 75% Full Time, 20% Contract, and 5% Nights. Highlights an 85% In-person, 5% Hybrid, and 10% Remote job distribution, with an average salary of $84,207 per year, or $40.5 per hour.

SOC Analyst Tier 3

JFL Consulting, LLC

Springfield, VA โ€ข On-site

$140K - $180K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 27 days ago


Job description

Job Title: SOC Analyst Tier 3
Place of Performance: Springfield, VA
Experience Level: 5-8 years of experience
About JFL Consulting:
With more than 20 years of securing some of the U.S. Department of Defense and the Intelligence Community's most critical networks, JFL Consulting, LLC provides advanced network security solutions to a range of US Government and US commercial clients.
Our cybersecurity operators are experts at assessing and defending mission-critical data and the networks that facilitate their operation. We are focused on delivering advanced products and industry best practices that meet each customer's unique requirements. Visit www.jflconsulting.com
What We Offer:
  • Salary: $140k- $180k
  • 100% employer-paid medical, dental, and vision premiums for employees and dependents
  • Flexible Spending Accounts (healthcare, dependent care, and commuter)
  • Life insurance, short-term disability and long-term disability
  • 401(k) with immediate vesting of company contribution
  • Generous PTO policy (15 vacation, 5 sick, 2 personal days, 11 holidays)
  • We support your growth through certification reimbursement, dedicated professional development funding, and company-provided access to online learning platforms

Job Overview:
We're looking for a SOC Analyst Tier 3 and Incident Responder, a senior analyst role in the SOC. This role leads the response to confirmed security incidents, conducts threat hunting operations, and provides deep technical analysis capability in the operations center. Tier 3/IR analysts are activated for severe incidents and are the primary interface to the Tier 4 SME and external response resources when needed.
Key Responsibilities:
  • Provide Tier 3 escalation and resolution for the most complex incidents and outages escalating to the Tier 4 SME as needed with appropriate documentation
  • Lead the response to Priority 1 and complex Priority 2 security incidents from detection through remediation
  • Conduct proactive threat hunting operations to identify threats that have bypassed automated detection
  • Perform advanced PCAP analysis, log analysis, memory forensics, and malware triage
  • Contain and eradicate threats while coordinating with engineers for isolation and remediation
  • Produce formal incident response reports for Priority 1 and Priority 2 incidents
  • Develop and maintain threat hunting TTPs and playbooks
  • Build new detection use cases from threat hunting findings and submit to SIEM engineer
  • Serve as on-call incident responder
  • Brief senior leadership during active high priority incidents
  • Mentor Tier 1 and 2 analysts in investigation techniques and escalation decision-making
  • Manage and own the SOC Event log for all events during the shifts
  • Maintain situational awareness of the threat landscape and active campaigns
  • Participate briefings and training sessions

Requirements
Required Qualifications:
  • 5+ years of SOC, threat hunting or incident response type experience
  • Bachelor's degree in Cyber Security, Information Technology, Computer Science, Information Security, or related field. In lieu of degree, four additional years of experience in a NOC, SOC, IT security, or network engineering role
  • Two of the following certifications, equivalent or better: Sec+, CYSA+, GCIH, SecX, CEH, GCIA, GSOC, CISSP
  • Demonstrated hands-on incident response experience including containment, eradication, and recovery
  • Proficiency with SIEM platforms and log analysis
  • Proficiency with SIEM query languages - SPL, KQL, or equivalent
  • Proficiency with PCAP analysis tools (Wireshark, NetworkMiner, or equivalent)
  • Experience with EDR, endpoint forensics, memory analysis, and network forensics tools
  • Deep understanding of attacker TTPs, kill chain methodology, and MITRE ATT&CK
  • Ability to work shifts including nights, weekends, and holidays on rotating shift schedule

Preferred Qualifications
  • GCFA or GCFE certification or other forensic certifications
  • Active Secret clearance preferred but not required
  • Experience with threat hunting frameworks and platforms
  • Reverse engineering experience (IDA Pro, Ghidra)
  • Prior experience on a DFIR team or incident response retainer
  • Experience with malware analysis (static and dynamic)

JFL Consulting, LLC is an Equal Opportunity Employer.
We do not discriminate against any applicant for employment on any legally recognized basis including, but not limited to: race, religion or creed, color, national origin, sex, age, disability, marital status, sexual orientation, genetic information, veteran status, status with regard to public assistance or any other protected class under federal, state or local statute. It is also the policy of JFL Consulting, LLC to provide reasonable accommodations for qualified individuals with disabilities.
Salary Description
$140k- $180k