Dragonfly AI Logo

Dragonfly AI

Tier 1 SOC Analyst

Posted 9 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in GBR
Junior
Remote
Hiring Remotely in GBR
Junior
Overnight SOC analyst monitors SIEM (Sentinel/Splunk) and EDR alerts, triages incidents per runbooks, validates vulnerabilities (Tenable), maintains auditable tickets and shift logs, escalates incidents, communicates with clients and on-call leads, and supports reporting and SOP improvements.
The summary above was generated by AI
Description

Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.

Dragonfli is hiring a Tier 1 SOC Analyst to join our overnight security operations team. In this role, you will monitor SIEM alerting (Microsoft Sentinel or Splunk) and EDR detections across client tenants, triage events against established runbooks, and escalate through a clear, documented path. You will track and validate vulnerability findings, keep auditable ticket notes and shift logs, and help flag detection gaps and tuning opportunities. This position is well suited to candidates with 0–2 years of security operations or IT experience who are ready to build a strong foundation in SOC monitoring and incident triage.

This is a contract position involving a large commercial enterprise in the transportation/logistics (critical infrastructure) sector. Candidates with previous consulting or contracting experience are preferred. U.S. Citizenship or Permanent Residency is required. If hired, all work related to this role must be performed within the continental U.S.

Responsibilities:

  • Monitor SIEM alerting (for example Microsoft Sentinel or Splunk) and triage events by severity against established runbooks
  • Review and action endpoint detection and response (EDR) alerts across client tenants
  • Track and validate vulnerability findings (Tenable) and route them into the correct workflow
  • Escalate incidents through the defined path with clear, documented handoffs
  • Open, update, and close tickets with accurate, auditable notes, and maintain clean shift logs
  • Communicate clearly with clients and the on-call lead during overnight events
  • Follow and help improve standard operating procedures, and flag detection gaps and tuning opportunities
  • Support monthly reporting with accurate event and response data
Requirements

Must-Have:

  • Ability to pass a drug screening and a full background investigation, including verification of references, employment history, education, and certifications
  • 0–2 years of experience in security operations, IT, or a related technical field
  • Working knowledge of SIEM alerting and EDR alert triage concepts
  • Solid networking and operating-system fundamentals across Windows, macOS, and Linux
  • Understanding of the incident lifecycle: detection, triage, containment, and escalation
  • Ability to work overnight shifts reliably on a rotation that includes weekends
  • Clear written communication and disciplined documentation habits

Preferred / Nice-to-Have:

  • Hands-on exposure to Microsoft Sentinel, Splunk, CrowdStrike or comparable EDR, and Tenable
  • Security+ or a similar entry-level security certification
  • Basic scripting for triage or automation (Python or PowerShell)
  • Coursework, internship, or lab experience in a SOC or IT security environment
  • Residency in the Hampton Roads through Richmond, VA corridor
Skill(s)

Technical Skills:

  • SIEM monitoring (Microsoft Sentinel, Splunk)
  • EDR alert triage
  • Vulnerability tracking (Tenable)
  • Ticketing and shift documentation
  • Windows, macOS, and Linux fundamentals
  • Networking fundamentals
  • Incident lifecycle knowledge

Soft Skills:

  • Attention to detail
  • Clear written communication
  • Reliability on an overnight/weekend rotation
  • Discipline under SLA pressure
  • Collaboration with on-call leads
Benefits

Medical – Multiple POS health plan options including an HSA-compatible plan

Dental – PPO coverage for preventive, basic, and major services

Vision – Annual exam, frames, lenses, and contact lens allowance

401(k) – Employer match up to 5% of eligible compensation

Long-Term Disability – 100% employer-paid coverage at 50% of pre-disability earnings

Life Insurance & AD&D – 100% employer-paid coverage valued at $10,000 each

PTO – 15–25 days annually based on tenure

Paid Federal Holidays – All 11 federal holidays observed

HQ

Dragonfly AI London, England Office

8-14 Vine Hill, London, United Kingdom, EC1R 5DX

Similar Jobs

2 Hours Ago
Remote or Hybrid
United Kingdom
Expert/Leader
Expert/Leader
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Drive pipeline and bookings growth through strategic Global Systems Integrator partnerships across Europe. Develop joint business plans, coordinate enterprise sales pursuits, generate demand, strengthen executive relationships, expand partner-led services and platform adoption, and monitor performance through business reporting. Collaborate with Sales, Marketing, Product, Services, Finance, and alliance teams to execute go-to-market initiatives and deliver measurable revenue outcomes.
Top Skills: Artificial IntelligenceCloud ComputingCybersecurityFalcon FlexSaaS
8 Hours Ago
In-Office or Remote
London, Greater London, England, GBR
Junior
Junior
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Partner with sales and partners to run pre-sales discovery, demonstrate Atlassian products, map customer problems to solutions, identify expansion opportunities, capture product feedback, and support pipeline development for mid-market/enterprise accounts.
Top Skills: Atlassian PlatformAtlassian Products
9 Hours Ago
Easy Apply
Remote
United Kingdom
Easy Apply
Entry level
Entry level
Cloud • Security • Software • Cybersecurity • Automation
Build and maintain Ruby on Rails backend features for vulnerability management, including security dashboards, reports, and ingestion pipelines. Improve system performance, reliability, and scalability; collaborate across backend, frontend, product, design, and security teams; review code; address technical debt; and participate in on-call rotations. The role requires relational database experience, distributed-team collaboration, technical problem-solving, and contributions across the stack when needed.
Top Skills: ElasticsearchGraph DatabasesJavaScriptPostgresRubyRuby On RailsVue

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account