1

Soc Analyst Tier One Jobs (NOW HIRING)

They are seeking a SOC Tier 1 Analyst to support security operations by monitoring security events, performing first-level alert triage, and escalating confirmed incidents as necessary.

Evolver is seeking a SOC Analyst (Tier 3) to join our growing team in support of a large Security ... Security + Certification * 1 year of experience with Adobe Pro * 3 years of incident assessment and ...

Evolver is seeking a SOC Analyst (Tier 3) to join our growing team in support of a large Security ... Security + Certification * 1 year of experience with Adobe Pro * 3 years of incident assessment and ...

SOC Analyst Tier 3

AL · On-site +1

$75K - $90K/yr

Escalation points for SOC Tier 2 in relation to triage, analysis and incident response ... Blue Team Security Level 1 Certification * Proficient in a python or PowerShell * EC-Council ...

Position Overview The Tier 1 Security Operations Center (SOC) Analyst contributes to the protection of client assets and information by monitoring security events and responding to incidents. The ...

SOC Analyst Tier 3

Huntsville, AL · Remote

$75K - $90K/yr

Escalation points for SOC Tier 2 in relation to triage, analysis and incident response ... Blue Team Security Level 1 Certification * Proficient in a python or PowerShell * EC-Council ...

The Tier 3 SOC Analyst serves as an escalation point for Tier 1 and Tier 2 Analysts within the SOC and provides advanced analytical and investigation support for complex incidents to assist in ...

The Tier 3 SOC Analyst serves as an escalation point for Tier 1 and Tier 2 Analysts within the SOC and provides advanced analytical and investigation support for complex incidents to assist in ...

Everforth ECS is seeking a SOC Tier 2 Analyst to work in our Portland, OR office. The SOC Analyst 2 ... Review and investigate alerts escalated by SOC Analyst 1 or automated SOC workflows to validate ...

SOC Analyst Tier 2

San Antonio, TX · On-site

$61K - $101K/yr

... SOC) and perform initial triage, analysis, and escalation as needed. * Investigate potential ... Minimum of one (1) + year of overall experience, preferably experience in cybersecurity ...

... SOC) and perform initial triage, analysis, and escalation as needed. * Investigate potential ... Minimum of one (1) + year of overall experience, preferably experience in cybersecurity ...

SOC Tier 3 Analyst

Portland, OR · On-site

$88K - $104K/yr

Review and resolve escalated findings from SOC Analyst 1 and SOC Analyst 2, including disputed ... tier analysts.

SOC Analyst Tier 2

Washington, DC · On-site

$61K - $101K/yr

... SOC) and perform initial triage, analysis, and escalation as needed. * Investigate potential ... Minimum of one (1) + year of overall experience, preferably experience in cybersecurity ...

... SOC) and perform initial triage, analysis, and escalation as needed. * Investigate potential ... Minimum of one (1) + year of overall experience, preferably experience in cybersecurity ...

next page

Showing results 1-20

Soc Analyst Tier One information

See salary details

$35.5K

$99.2K

$127K

How much do soc analyst tier one jobs pay per year?

As of Jun 13, 2026, the average yearly pay for soc analyst tier one in the United States is $99,157.00, according to ZipRecruiter salary data. Most workers in this role earn between $72,000.00 and $126,500.00 per year, depending on experience, location, and employer.

What is the difference between Soc Analyst Tier One vs Soc Analyst Tier Two?

AspectSoc Analyst Tier OneSoc Analyst Tier Two
CertificationsCompTIA Security+, CEH, or equivalentSame as Tier One, often with additional certifications
Work EnvironmentMonitoring security alerts, initial incident responseHandling escalated incidents, deeper analysis
ResponsibilitiesInitial detection and triage of security eventsIncident investigation and escalation

Soc Analyst Tier One focuses on monitoring and initial detection of security threats, while Soc Analyst Tier Two handles more complex incident analysis and escalation. Both roles require similar certifications and work in security operations centers, but Tier Two involves deeper investigation skills.

What are SOC Analyst Tier One roles?

SOC Analyst Tier One, also known as Level 1 SOC Analyst, is an entry-level cybersecurity professional responsible for monitoring and analyzing security alerts within a Security Operations Center (SOC). Their main duties include triaging alerts, identifying potential threats, and escalating incidents to higher-level analysts if necessary. They play a crucial role in the early detection and response to cyber threats, ensuring the organization's security posture is maintained. Tier One analysts use various security tools and follow established procedures to assess and document incidents. This position often serves as a stepping stone to more advanced cybersecurity roles.

Can you make $500,000 a year in cyber security?

Soc Analyst Tier One roles typically have salaries ranging from $50,000 to $80,000 annually, depending on experience and location. Earning $500,000 a year in cybersecurity generally requires advanced roles such as senior security executives, consultants, or specialists with extensive expertise, certifications, and leadership responsibilities. Entry-level positions like Tier One analysts are unlikely to reach that income level without significant career progression.

What are some common challenges faced by a SOC Analyst Tier One, and how can they be addressed?

SOC Analyst Tier One professionals often face the challenge of handling a high volume of security alerts, many of which may be false positives. Prioritizing alerts and developing efficient triage processes are essential for managing workload and ensuring that true threats are not overlooked. Building strong communication skills is also important, as Tier One analysts frequently collaborate with higher-tier analysts and IT teams to escalate incidents and share findings. Continuous learning and staying updated on evolving threats can help analysts stay effective in this fast-paced environment.

What are the key skills and qualifications needed to thrive as a SOC Analyst Tier One, and why are they important?

To thrive as a SOC Analyst Tier One, you need foundational knowledge of cybersecurity concepts, network protocols, and incident response, often supported by a relevant degree or certifications like CompTIA Security+. Familiarity with security information and event management (SIEM) tools, intrusion detection systems, and ticketing platforms is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify threats and escalate incidents appropriately. These skills are crucial for quickly detecting and mitigating security risks to protect organizational assets.

What is a Tier 1 SOC analyst?

A Tier 1 SOC analyst is an entry-level cybersecurity professional responsible for monitoring security alerts, analyzing potential threats, and escalating incidents as needed. They use security information and event management (SIEM) tools and typically work in a security operations center (SOC) environment, often requiring basic knowledge of networking and security principles.

What is a Level 1 SOC analyst?

A Level 1 SOC analyst is an entry-level cybersecurity professional responsible for monitoring security alerts, analyzing potential threats, and escalating incidents as needed. They typically use security information and event management (SIEM) tools and require foundational knowledge of network security and incident response procedures.

How much do Tier 1 SOC analysts make?

Tier 1 SOC analysts typically earn between $45,000 and $65,000 annually, depending on experience, location, and employer. Entry-level positions may start lower, while those with certifications like CompTIA Security+ or familiarity with SIEM tools can earn higher salaries.
More about Soc Analyst Tier One jobs
What cities are hiring for Soc Analyst Tier One jobs? Cities with the most Soc Analyst Tier One job openings:
What states have the most Soc Analyst Tier One jobs? States with the most job openings for Soc Analyst Tier One jobs include:
Infographic showing various Soc Analyst Tier One job openings in the United States as of June 2026, with employment types broken down into 50% As Needed, and 50% Full Time. Highlights an 81% Physical, 6% Hybrid, and 13% Remote job distribution, with an average salary of $99,157 per year, or $47.7 per hour.
SOC Tier 1 Analyst

SOC Tier 1 Analyst

ECS

Portland, OR • On-site

Full-time

Posted 24 days ago


Job description

Job Summary:
ECS is a $4B global organization specializing in advanced technology solutions in data and AI, cybersecurity, and enterprise transformation. They are seeking a SOC Tier 1 Analyst to support security operations by monitoring security events, performing first-level alert triage, and escalating confirmed incidents as necessary.
Responsibilities:
• Monitor security events and alerts across SIEM, EDR, IDS/IPS, cloud, network, identity, case management, and other approved security platforms.
• Perform first-level alert validation to determine whether activity is benign, suspicious, policy-related, or requires escalation.
• Assign initial severity, scope, affected assets, affected accounts, and potential impact using approved triage criteria and runbooks.
• Escalate confirmed, ambiguous, high-risk, or complex alerts to SOC Analyst 2, SOC Analyst 3, or SOC leadership according to established procedures.
• Create and update incident tickets with clear descriptions, timestamps, evidence references, preliminary findings, and actions taken.
• Document investigation steps, alert context, decisions, and escalation rationale clearly and accurately.
• Prepare shift handoff notes and status updates to ensure continuity of monitoring and incident follow-up.
• Maintain case management hygiene, including accurate categorization, status tracking, and closure documentation for routine alerts.
• Support standard incident response activities under direction of SOC Analyst 2, SOC Analyst 3, incident responders, or SOC leadership.
• Collect readily available logs, alert details, endpoint information, user information, and other operational evidence needed for escalation.
• Coordinate basic information requests with system owners, security engineers, and other technical teams as directed.
• Track escalations and provide status updates until ownership is accepted by the appropriate SOC or specialized role.
• Use SOC tools such as SIEM, SOAR, EDR, threat intelligence portals, case management systems, and vulnerability platforms in accordance with approved procedures.
• Follow playbooks, standard operating procedures, evidence-handling expectations, and escalation thresholds consistently.
• Report suspected data quality issues, missing telemetry, dashboard problems, or tool availability concerns to SOC Analyst 2/3, Splunk engineering, or security engineering teams.
• Participate in training, drills, tabletop exercises, and lessons-learned activities to improve monitoring and triage performance.
• Stay current with common cyber threats, phishing techniques, malware trends, vulnerabilities, user behavior risks, and security operations best practices.
• Apply feedback from senior analysts to improve alert validation, documentation quality, and escalation accuracy.
• Contribute operational observations and recurring alert patterns to process improvement discussions.
Qualifications:
Required:
• U.S. Citizenship with ability to obtain and maintain a DOE “L” clearance after start.
• 1-3 years of experience in cybersecurity, IT operations, help desk, networking, systems administration, or SOC monitoring.
• Basic experience using SIEM, EDR, ticketing, case management, or log-search tools to review security events or operational alerts.
• Foundational knowledge of Windows, Linux, networking, cloud, identity, endpoint, and common cyber threat concepts.
• Ability to follow runbooks, validate alerts, document findings, and escalate issues accurately and promptly.
• Familiarity with incident escalation procedures, shift handoff practices, and basic evidence-handling expectations.
• Strong attention to detail, written documentation skills, and ability to communicate clearly with technical teams.
Preferred:
• Experience working in a 24x7 SOC, managed security operations environment, government program, or regulated organization.
• Familiarity with frameworks and guidance such as MITRE ATT&CK, NIST CSF, NIST SP 800-61, CIS Controls, or Cyber Kill Chain.
• Experience with tools such as Splunk, Microsoft Sentinel, QRadar, CrowdStrike, Microsoft Defender, Palo Alto, SOAR platforms, or similar technologies.
• Certifications such as Security+, Network+, CySA+ (in progress), CEH (in progress), or equivalent experience.
• Experience with phishing triage, malware alert validation, endpoint alerts, user behavior alerts, or network security monitoring.
• Exposure to SOC playbooks, escalation workflows, and operational reporting expectations.
Company:
Everforth ECS is the federal segment of Everforth, a $4B global organization with over 10,000 employees. Founded in 2001, the company is headquartered in Fairfax, USA, with a team of 1001-5000 employees. The company is currently Late Stage.