SOC Analyst II
Posted on:
Yesterday
Vacancies:
1 Vacancy
Job Summary
Our client in IT/Tech sector is seeking a seeking a SOC Analyst II to join the security operations team. This is a hands-on second-line role at the center of the clients detection and response program.
Job Summary
The ideal candidate will spend each day investigating security alerts that have escalated beyond the initial triage layer distinguishing genuine threats from false positives and driving confirmed incidents through containment remediation and resolution. The ideal candidate will operate in a fast-paced telemetry-rich environment spanning cloud and on-premises infrastructure thousands of endpoints and a modern security stack that includes SIEM EDR and email security platforms.
Beyond day-to-day monitoring the ideal candidate will take ownership of improving the effectiveness of the security operations function. The ideal candidate will contribute to maturing detection content reducing alert fatigue by tuning false positives and enhancing incident response runbooks and playbooks to ensure consistent handling across shifts. Working closely with senior SOC analysts threat hunters and detection engineers the ideal candidate will have the opportunity to strengthen technical expertise and progress toward a Tier 3 SOC Analyst or specialized Security Engineering career path. This is a fully remote opportunity available on either a full-time or contract basis.
Key Responsibilities
- Monitor triage and investigate security alerts across SIEM EDR identity and email security platforms
- Own Tier 2 investigation containment eradication and escalation of confirmed security incidents
- Analyze logs network traffic endpoint telemetry and user activity to identify indicators of compromise
- Conduct root cause analysis and document incidents findings and response actions per established runbooks
- Tune detection rules suppress false positives and recommend new detection logic in partnership with engineering
- Participate in proactive threat hunting based on current threat intelligence and emerging tactics
- Support and contribute to post-incident reviews lessons learned and continuous improvement of response playbooks
- Maintain shift handoff notes and ensure continuity of monitoring across a 24/7 coverage model
Required Qualifications
- 2 to 4 years of hands-on SOC incident response or security analyst experience
- Working knowledge of SIEM platforms such as Splunk Microsoft Sentinel or QRadar
- Familiarity with EDR tooling including CrowdStrike SentinelOne or Microsoft Defender
- Solid grounding in networking fundamentals TCP/IP DNS and common attack techniques
- Ability to interpret logs and telemetry to reconstruct an attack timeline
- Strong written documentation and clear communication under time pressure
Preferred Qualifications
- Security CySA GCIH or equivalent certification
- Experience with SOAR platforms and automation scripting in Python or PowerShell
- Working familiarity with the MITRE ATT&CK framework and threat-informed defense
- Exposure to cloud security monitoring in AWS or Azure