1

Soc Tier 1 Jobs (NOW HIRING)

SOC Manager

Washington, DC · On-site

$120 - $150/hr

This role directs Tier 1, Tier 2, and Tier 3 analysts across a 24x7x365 coverage model, sets the shift schedule, and ensures the SOC has the people, procedures, and tools in place to triage alerts.

This role directs Tier 1, Tier 2, and Tier 3 analysts across a 24x7x365 coverage model, sets the shift schedule, and ensures the SOC has the people, procedures, and tools in place to triage alerts.

This role directs Tier 1, Tier 2, and Tier 3 analysts across a 24x7x365 coverage model, sets the shift schedule, and ensures the SOC has the people, procedures, and tools in place to triage alerts.

Tier 2 SOC Analyst

Seaside, CA · On-site

$94K - $127K/yr

Description Tier 2 SOC Analyst Xcelerate Solutions is seeking a Tier 2 SOC Analyst to support ... Perform advanced analysis of security events escalated from Tier 1 or identified through endpoint ...

Tier 2 SOC Analyst

Alexandria, VA · On-site

$94K - $127K/yr

Description Tier 2 SOC Analyst Xcelerate Solutions is seeking a Tier 2 SOC Analyst to support ... Perform advanced analysis of security events escalated from Tier 1 or identified through endpoint ...

Tier 2 SOC Analyst

Alexandria, VA · On-site

$94K - $127K/yr

Description Tier 2 SOC Analyst Xcelerate Solutions is seeking a Tier 2 SOC Analyst to support ... Perform advanced analysis of security events escalated from Tier 1 or identified through endpoint ...

Tier 2 SOC Analyst

Seaside, CA · On-site

$94 - $127/hr

Xcelerate Solutions is seeking a Tier 2 SOC Analyst to support CyberPRIMES cybersecurity, privacy ... Perform advanced analysis of security events escalated from Tier 1 or identified through endpoint ...

Tier 2 SOC Analyst

Seaside, CA · On-site

$94 - $127/hr

Xcelerate Solutions is seeking a Tier 2 SOC Analyst to support CyberPRIMES cybersecurity, privacy ... Perform advanced analysis of security events escalated from Tier 1 or identified through endpoint ...

New

Tier 2 SOC Analyst

Alexandria, VA · On-site

$94 - $127/hr

Xcelerate Solutions is seeking a Tier 2 SOC Analyst to support CyberPRIMES cybersecurity, privacy ... Perform advanced analysis of security events escalated from Tier 1 or identified through endpoint ...

SOC Analyst (Tier 2)

Washington, DC · On-site

$125 - $135/hr

Description Quantum Sky is searching for a Tier 2 SOC Analyst to support a federal government ... Minimum of one IAT Level I security industry specific certification (8570 Baseline Certifications ...

You will support Tier 1 and Tier 2 SOC operations, contribute to SOC playbook development, and help mature cyber defense strategies in a mission-focused environment. Location and Clearance

SOC Analyst

Washington, DC · On-site

$100K - $120K/yr

You will support Tier 1 and Tier 2 SOC operations, contribute to SOC playbook development, and help mature cyber defense strategies in a mission-focused environment. Location and Clearance

SOC Analyst

Washington, DC · On-site

$100K - $120K/yr

You will support Tier 1 and Tier 2 SOC operations, contribute to SOC playbook development, and help mature cyber defense strategies in a mission-focused environment. Location and Clearance

You will support Tier 1 and Tier 2 SOC operations, contribute to SOC playbook development, and help mature cyber defense strategies in a mission-focused environment. Location and Clearance

Showing results 41-60

Soc Tier 1 information

See salary details

$11

$31

$72

How much do soc tier 1 jobs pay per hour?

As of Sep 4, 2026, the average hourly pay for soc tier 1 in the United States is $31.61, according to ZipRecruiter salary data. Most workers in this role earn between $19.95 and $37.74 per hour, depending on experience, location, and employer.

What is a SOC Tier 1 analyst?

SOC Tier 1 analysts are entry-level cybersecurity professionals who monitor and analyze security events within a Security Operations Center (SOC). Their main responsibilities include reviewing alerts from security tools, identifying possible threats, and escalating incidents to higher-tier analysts when necessary. They act as the first line of defense against cyber threats, ensuring that potential security issues are detected early and responded to promptly. Tier 1 analysts also document their findings and help maintain the overall security posture of an organization.

What skills and qualifications are needed to thrive as a SOC Tier 1 analyst?

To thrive as a SOC Tier 1 Analyst, you need foundational knowledge of cybersecurity principles, incident response processes, and typically a degree in computer science or a related field. Familiarity with security information and event management (SIEM) tools, intrusion detection systems (IDS), and relevant certifications like CompTIA Security+ or Cisco CCNA Cyber Ops is important. Attention to detail, critical thinking, and effective communication are crucial soft skills for identifying, escalating, and documenting security incidents. These skills ensure prompt detection and escalation of threats, helping protect organizational assets and maintain security posture.

How does a SOC Tier 1 analyst collaborate with higher-tier analysts and other IT teams during a security incident?

As a SOC Tier 1 analyst, you'll be the first line of defense, responsible for monitoring security alerts and identifying potential threats. When a suspicious activity is detected, you'll follow established escalation protocols to collect relevant information and communicate your findings to Tier 2 or Tier 3 analysts, who perform deeper investigations. You'll also frequently coordinate with IT support or network teams to gather additional context or implement immediate containment measures. Effective communication and accurate documentation are essential, as your initial analysis often sets the stage for how incidents are handled and resolved.

What is the difference between Soc Tier 1 vs Soc Tier 2?

AspectSoc Tier 1Soc Tier 2
CertificationsCompTIA Security+, Network+CompTIA Security+, Network+
Work EnvironmentEntry-level, monitoring security alertsMid-level, analyzing security incidents
Employer UsageCommon in security operations centers (SOCs)Often in larger organizations or teams

Soc Tier 1 professionals focus on monitoring and initial incident response, while Soc Tier 2 staff handle deeper analysis and troubleshooting. The roles are distinct but complementary within security teams, with Tier 2 requiring more experience and technical skills.

More about Soc Tier 1 jobs

What cities are hiring for Soc Tier 1 jobs?

Cities with the most Soc Tier 1 job openings:

What states have the most Soc Tier 1 jobs?

States with the most job openings for Soc Tier 1 jobs include:

Infographic showing various Soc Tier 1 job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 12% Part Time, and 6% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $65,757 per year, or $31.6 per hour.

$120 - $150/hr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 17 days ago


Job description

Position Description

Valiant Solutions is seeking a SOC Manager to join our rapidly growing and innovative cybersecurity team!

The SOC Manager leads the daily operations of the Security Operations Center and owns the end-to-end incident response mission for the client enterprise. This role directs Tier 1, Tier 2, and Tier 3 analysts across a 24x7x365 coverage model, sets the shift schedule, and ensures the SOC has the people, procedures, and tools in place to triage alerts. The SOC Manager owns the SOC documentation, including Standard Operating Procedures, Playbooks, and the Concept of Operations, and ensures that every incident is handled in compliance with NIST SP 800-61 and client incident-response SOPs. The SOC Manager coordinates containment, eradication, and recovery actions across SOC, engineering, and partner SOC teams, manages the SIEM notable events dashboard, and maintains the partner and Cloud Service Provider call tree that drives stakeholder notification during an incident.

Named one of the Best Places to Work in the Washington DC area for 12 consecutive years, Valiant is proud of our employee-centric culture and commitment to excellence. If you are interested in learning more about Valiant and this opportunity, we invite you to apply now!

Location: The SOC Manager will primarily work remotely but should be prepared to report on-site in the Washington, DC Metro area as needed. Remote work requires a high level of trust in our employees, and we strictly adhere to the details outlined in our Remote Work Policy below.

Eligibility Requirements: U.S. Citizenship is required due to federal contract obligations, along with the ability to successfully pass a federal background investigation.

  • 8+ years of Information Technology experience, with at least four years dedicated to incident response.
  • At least one of the following certifications: GCIH, GCFA, or GREM. Equivalent industry incident response certifications, such as CISSP, CISM, or CySA+, may be considered.
  • Experience with SIEM, SOAR, EDR, CDM, and malware analysis.
  • Demonstrated experience managing a Security Operations Center, including overseeing complex systems, multi-tier analyst teams, and 24x7x365 coverage models.
  • Hands-on experience with SIEM, SOAR, and EDR platforms, including building and tuning notable event dashboards, correlation content, and automated response playbooks.
  • Experience with Continuous Diagnostics and Mitigation (CDM) data feeds and the integration of CDM telemetry into SIEM for centralized visibility.
  • Working knowledge of malware analysis workflows, including triage, sandbox detonation, and coordination with Tier 3 reverse engineering resources.
  • Strong working knowledge of enterprise operating systems (Windows, Linux) and networking concepts, including TCP/IP, DNS, routing, firewalls, and proxy architectures.
  • Hands-on experience with AWS native services and tools, including CloudTrail, GuardDuty, Security Hub, VPC Flow Logs, and IAM, in support of cloud incident detection and response.
  • Working knowledge of NIST SP 800-61 (Computer Security Incident Handling Guide) and the ability to align SOC operations and reporting to its four-phase model.
  • Familiarity with the MITRE ATT&CK framework and experience applying it to detection coverage assessments and post-incident reviews.
  • Experience building and maintaining shift schedules, call trees, and stakeholder notification procedures that meet contractual notification timelines.
  • Experience leading post-incident reviews, root cause analysis, and lessons-learned sessions, and translating findings into updated SOPs and playbooks.
  • Strong written and verbal communication skills, including the ability to brief incident
  • Required to obtain and maintain a Non-Sensitive / High Risk (Public Trust) security clearance at the Tier 4/6c level.
  • Must be available to support 24x7x365 SOC coverage, including on-call response and on-site presence at client Headquarters in Washington, DC as needed.

Responsibilities:

  • Manage daily SOC activities, including building and maintaining shift schedules that sustain 24x7x365 coverage and ensure adequate staffing across Tier 1, Tier 2, and Tier 3 functions.
  • Maintain all SOC documentation, including Standard Operating Procedures, Playbooks, and the SOC Concept of Operations, reviewing and updating them on the cadence required by the client SOC CONOPS.
  • Manage Tier 1, Tier 2, and Tier 3 incident response operations, including alert triage, escalation, in-depth analysis, and advanced forensics.
  • Coordinate containment, eradication, and recovery activities across SOC analysts, engineering teams, system owners, and partner SOCs.
  • Lead post-incident reviews and root cause analysis sessions, document findings, and translate lessons learned into updates to playbooks, detection content, and SOPs.
  • Ensure all incident response activities comply with NIST SP 800-61 and client incident response SOPs, and that reporting timelines are met.
  • Manage the SIEM notable events dashboard, including reviewing detection coverage, false-positive rates, and analyst workload, and direct tuning activities to improve signal quality.
  • Maintain the shift coverage schedule and ensure handoff procedures preserve situational awareness across rotations.
  • Maintain the SOC call tree, including contact information for all partner organizations, Cloud Service Providers, and client stakeholders, and validate the call tree at least quarterly.
  • Serve as the primary escalation point for high-severity incidents and lead cross-team coordination during active response.
  • Track and report SOC performance metrics, including mean time to detect, mean time to respond, ticket volume by tier, and escalation rates, and present them to client SOC leadership.
  • Coordinate with the Cyber Threat Intelligence and Cyber Hunt teams to incorporate new threat indicators and detection logic into SOC operations.
  • Support inter-agency threat intelligence exchanges and partner SOC collaboration to align client response activities with national cybersecurity priorities.
  • Develop and deliver training and knowledge transfer for SOC analysts on new SOPs, playbooks, tools, and detection content.
  • Participate in the Engineering Review Board, Change Control Board, and other client governance reviews for SOC-related changes.
  • Stay current on emerging adversary tactics, techniques, and procedures, and recommend improvements to the client's detection and response posture.

Remote Work Policy

Remote work necessitates a high level of trust in our employees. To ensure that employee performance does not suffer in a remote work environment, all employees who telecommute are expected to have a quiet and distraction-free workspace with adequate internet, dedicate their full attention and availability to their job duties during working hours, and maintain a schedule during core business hours that align with those of their coworkers and Valiant's clients. In alignment with Valiant's inclusive and engaging environment, cameras are encouraged and can be required to be on during virtual video conferences. Additionally, in alignment with the Office of the Inspector General’s effort to eliminate conflicting employment, all Valiant employees are required to disclose any current or future outside employment engagements. During onboarding and throughout employment, employees must disclose any current activities or intent to engage in outside employment or other professional activities and obtain written approval. Employees may not solicit or conduct any outside business during core business hours for Valiant Solutions and our clients.

Equal Employment Opportunity

Valiant Solutions is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, marital status, or veteran status, in accordance with applicable law.

Physical Demands

Sitting or standing at a desk for prolonged periods of time and consistent operation of a computer. Frequent communication and exchanging of accurate information via electronic communication, phones, and in person. Occasionally lift and/or move moderate amounts of weight, typically less than 20 pounds. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of the job.

Benefits Snapshot (includes, but not limited to)

  • Valiant pays 99% of the Medical, Dental, and Vision Coverage for Full-time Employees
  • Valiant contributes 25% towards Health Coverage for Family and Dependents
  • 100% Paid Short Term Disability and Life Insurance Policy for Full-time Employees
  • 100% Paid Certifications
  • 401K Matching up to 4%
  • Paid Time Off
  • Paid Federal Holidays
  • Wellness & Fitness Program
  • Valiant University – Online Education and Training Portal
  • FSA programs for: Medical Costs, Dependent Care, Transit, and Parking
  • Referral Bonuses
#J-18808-Ljbffr