1

Soc Analyst Tier One Jobs (NOW HIRING)

... 1 and SOC Analyst 2, including disputed severity, inconclusive evidence, or multi-source ... tier analysts. Preferred : • Experience working in a 24x7 SOC, managed security operations ...

They are seeking a SOC Tier 2 Analyst to support security operations by investigating escalated ... Responsibilities : • Review and investigate alerts escalated by SOC Analyst 1 or automated SOC ...

next page

Showing results 1-20

Soc Analyst Tier One information

See salary details

$35.5K

$99.2K

$127K

How much do soc analyst tier one jobs pay per year?

As of Jun 13, 2026, the average yearly pay for soc analyst tier one in the United States is $99,157.00, according to ZipRecruiter salary data. Most workers in this role earn between $72,000.00 and $126,500.00 per year, depending on experience, location, and employer.

What is the difference between Soc Analyst Tier One vs Soc Analyst Tier Two?

AspectSoc Analyst Tier OneSoc Analyst Tier Two
CertificationsCompTIA Security+, CEH, or equivalentSame as Tier One, often with additional certifications
Work EnvironmentMonitoring security alerts, initial incident responseHandling escalated incidents, deeper analysis
ResponsibilitiesInitial detection and triage of security eventsIncident investigation and escalation

Soc Analyst Tier One focuses on monitoring and initial detection of security threats, while Soc Analyst Tier Two handles more complex incident analysis and escalation. Both roles require similar certifications and work in security operations centers, but Tier Two involves deeper investigation skills.

What are SOC Analyst Tier One roles?

SOC Analyst Tier One, also known as Level 1 SOC Analyst, is an entry-level cybersecurity professional responsible for monitoring and analyzing security alerts within a Security Operations Center (SOC). Their main duties include triaging alerts, identifying potential threats, and escalating incidents to higher-level analysts if necessary. They play a crucial role in the early detection and response to cyber threats, ensuring the organization's security posture is maintained. Tier One analysts use various security tools and follow established procedures to assess and document incidents. This position often serves as a stepping stone to more advanced cybersecurity roles.

Can you make $500,000 a year in cyber security?

Soc Analyst Tier One roles typically have salaries ranging from $50,000 to $80,000 annually, depending on experience and location. Earning $500,000 a year in cybersecurity generally requires advanced roles such as senior security executives, consultants, or specialists with extensive expertise, certifications, and leadership responsibilities. Entry-level positions like Tier One analysts are unlikely to reach that income level without significant career progression.

What are some common challenges faced by a SOC Analyst Tier One, and how can they be addressed?

SOC Analyst Tier One professionals often face the challenge of handling a high volume of security alerts, many of which may be false positives. Prioritizing alerts and developing efficient triage processes are essential for managing workload and ensuring that true threats are not overlooked. Building strong communication skills is also important, as Tier One analysts frequently collaborate with higher-tier analysts and IT teams to escalate incidents and share findings. Continuous learning and staying updated on evolving threats can help analysts stay effective in this fast-paced environment.

What are the key skills and qualifications needed to thrive as a SOC Analyst Tier One, and why are they important?

To thrive as a SOC Analyst Tier One, you need foundational knowledge of cybersecurity concepts, network protocols, and incident response, often supported by a relevant degree or certifications like CompTIA Security+. Familiarity with security information and event management (SIEM) tools, intrusion detection systems, and ticketing platforms is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify threats and escalate incidents appropriately. These skills are crucial for quickly detecting and mitigating security risks to protect organizational assets.

What is a Tier 1 SOC analyst?

A Tier 1 SOC analyst is an entry-level cybersecurity professional responsible for monitoring security alerts, analyzing potential threats, and escalating incidents as needed. They use security information and event management (SIEM) tools and typically work in a security operations center (SOC) environment, often requiring basic knowledge of networking and security principles.

What is a Level 1 SOC analyst?

A Level 1 SOC analyst is an entry-level cybersecurity professional responsible for monitoring security alerts, analyzing potential threats, and escalating incidents as needed. They typically use security information and event management (SIEM) tools and require foundational knowledge of network security and incident response procedures.

How much do Tier 1 SOC analysts make?

Tier 1 SOC analysts typically earn between $45,000 and $65,000 annually, depending on experience, location, and employer. Entry-level positions may start lower, while those with certifications like CompTIA Security+ or familiarity with SIEM tools can earn higher salaries.
More about Soc Analyst Tier One jobs
What cities are hiring for Soc Analyst Tier One jobs? Cities with the most Soc Analyst Tier One job openings:
What states have the most Soc Analyst Tier One jobs? States with the most job openings for Soc Analyst Tier One jobs include:
Infographic showing various Soc Analyst Tier One job openings in the United States as of June 2026, with employment types broken down into 50% As Needed, and 50% Full Time. Highlights an 81% Physical, 6% Hybrid, and 13% Remote job distribution, with an average salary of $99,157 per year, or $47.7 per hour.
SOC Tier 3 Analyst

SOC Tier 3 Analyst

ECS

Portland, OR • On-site

Full-time

Posted 24 days ago


Job description

Job Summary:
Everforth ECS is seeking a SOC Tier 3 Analyst to work in their Portland, OR office. This role supports the organization's security operations by leading complex incident analysis, validating investigative findings, and coordinating technical response actions while mentoring lower-tier analysts.
Responsibilities:
• Lead analysis of complex, high-impact, multi-stage, or ambiguous security incidents across enterprise systems, cloud environments, identity platforms, endpoints, networks, and applications.
• Validate incident severity, scope, attack path, affected assets, affected accounts, likely root cause, and potential operational or business impact.
• Review and resolve escalated findings from SOC Analyst 1 and SOC Analyst 2, including disputed severity, inconclusive evidence, or multi-source correlation challenges.
• Provide technical facts, risk context, and recommended response priorities to SOC leadership for major incident handling and stakeholder communication.
• Coordinate complex containment, eradication, and recovery support with Security Engineer, Senior Engineer, system owners, incident responders, and other technical teams.
• Define evidence collection requirements and coordinate handoff to Forensics Lead or Forensics Mid when formal acquisition, preservation, chain of custody, or deep forensic analysis is required.
• Guide investigation strategy, timeline development, technical response sequencing, and escalation decisions for complex incidents.
• Maintain alignment with approved incident response plans, playbooks, evidence-handling expectations, and leadership direction.
• Analyze adversary behaviors, attack patterns, vulnerabilities, threat intelligence, control gaps, and recurring incident trends to improve detection and response effectiveness.
• Define analytic requirements and validate correlation rules, alert logic, dashboards, use cases, and response playbooks for operational effectiveness.
• Map complex observed behaviors to MITRE ATT&CK and other applicable threat models to support analytic improvement and stakeholder reporting.
• Coordinate with SOC Threat Hunter to convert hunt findings into operational detections and with Senior Splunk Engineer or Splunk Architect/Lead for technical implementation.
• Prepare or review complex incident summaries, technical timelines, investigation narratives, after-action inputs, and lessons-learned content.
• Communicate complex technical findings in clear operational, business, and risk language for SOC leadership, program stakeholders, and technical teams.
• Provide technical input to SOC Technical Writer for SOPs, playbooks, knowledge articles, and formal documentation products.
• Mentor SOC Analyst 1 and SOC Analyst 2 personnel through escalation review, coaching, analytic guidance, and quality feedback.
• Lead or support detection reviews, tabletop exercises, incident retrospectives, process assessments, and quality improvement activities.
• Identify recurring gaps in telemetry, tools, controls, workflows, documentation, or analyst training and coordinate corrective action requirements with the appropriate owner.
• Stay current with evolving cyber threats, vulnerabilities, adversary tradecraft, detection techniques, and security operations best practices.
• Translate lessons learned and threat developments into improved detections, procedures, escalation criteria, and analyst enablement materials.
Qualifications:
Required:
• U.S. Citizenship with ability to obtain and maintain a DOE “L” clearance after start.
• 5+ years of experience in SOC operations, incident response, detection engineering support, threat analysis, or advanced cybersecurity operations.
• Advanced experience using SIEM, EDR, log analysis, case management, and cross-tool correlation to investigate complex security incidents.
• Strong understanding of adversary tradecraft, MITRE ATT&CK, incident response lifecycle activities, evidence handling, detection logic, and enterprise security architecture.
• Experience leading complex investigations, validating technical findings, defining response priorities, and coordinating technical response across multiple teams.
• Experience developing or validating detection requirements, alert logic, analytic coverage, investigation workflows, or response playbooks.
• Strong written and verbal communication skills, including the ability to brief technical findings and mentor lower-tier analysts.
Preferred:
• Experience working in a 24x7 SOC, managed security operations environment, government program, or regulated organization.
• Familiarity with frameworks and guidance such as MITRE ATT&CK, NIST CSF, NIST SP 800-61, CIS Controls, or Cyber Kill Chain.
• Experience with tools such as Splunk, Microsoft Sentinel, QRadar, CrowdStrike, Microsoft Defender, Palo Alto, SOAR platforms, or similar technologies.
• Certifications such as GCIH, GCIA, GCFA, GNFA, CySA+, CISSP, CEH, SSCP, or equivalent experience.
• Experience coordinating with threat hunting, threat intelligence, forensics, Splunk engineering, security engineering, and SOC leadership during high-impact incidents.
• Experience leading lessons-learned reviews, tabletop exercises, detection reviews, analyst enablement, or SOC process improvement initiatives.
Company:
Everforth ECS is the federal segment of Everforth, a $4B global organization with over 10,000 employees. Founded in 2001, the company is headquartered in Fairfax, USA, with a team of 1001-5000 employees. The company is currently Late Stage.