
Security Operations Analyst II
Posted 14 hours ago

Posted 14 hours ago
This is a fully remote position, open to applicants in Canada.
• Oversee and prioritize alerts across various data sources including endpoint, network, cloud, runtime, and identity.
• Conduct structured investigations on escalated or unclear alerts by navigating through logs, correlating events, and constructing timelines.
• Classify alerts as true positives, false positives, or benign while providing documented reasoning.
• Determine the scope and impact of incidents, including affected users, systems, and data.
• Prepare comprehensive investigation packages for escalation to senior analysts.
• Engage in incident response activities, which involve evidence collection, log retrieval, and timeline reconstruction.
• Implement directed containment measures such as isolating endpoints, suspending accounts, and revoking tokens.
• Ensure case documentation is maintained throughout the incident lifecycle.
• Assist in developing post-incident timelines and root cause analyses.
• Monitor cloud audit logs and threat detection alerts for suspicious IAM activities, unusual API calls, and access irregularities.
• Investigate identity provider events, including suspicious logins, MFA bypass attempts, session anomalies, and unauthorized app assignments.
• Correlate cloud events with telemetry from endpoints and networks.
• Identify false positives, detect coverage gaps, and contribute to tuning detection mechanisms.
• Utilize the MITRE ATT&CK framework to categorize attacker techniques.
• Identify outdated runbook procedures or gaps in investigation guidance.
• Collaborate with Detection Engineers to develop detections and automate activities.
• Document clear case notes and prepare shift handoff summaries.
• Provide incident updates to the Security Operations Manager.
• 2–4+ years of practical experience in a SOC or security operations role with direct responsibility for alert triage.
• Strong understanding of the MITRE ATT&CK framework.
• Proficient in EDR tools, including process tree analysis, reviewing behavioral detections, and basic interpretation of endpoint artifacts.
• Familiar with SIEM-based investigations, including log queries, event correlation across sources, and timeline creation from normalized data.
• Knowledge of TCP/IP, DNS, HTTP/S, and TLS, and their exploitation by attackers.
• Experience in cloud security monitoring, particularly with AWS or GCP, including audit log analysis and IAM-related alert investigations.
• Background in investigating identity-based alerts within enterprise identity providers like Okta or Entra ID.
• Excellent written communication skills and structured case documentation abilities.
• Preferred: experience with CrowdStrike Falcon, SentinelOne, or similar tools beyond basic alert evaluations.
• Preferred: hands-on experience with Google SecOps/Chronicle, Microsoft Sentinel, or equivalent platforms.
• Preferred: knowledge of CSPM or cloud security tools such as Wiz or Prisma Cloud.
• Preferred: understanding of AWS incident response fundamentals, including CloudTrail, GuardDuty, VPC Flow Logs, and IAM chain analysis.
• Preferred: grasp of encoding, encryption, hashing, and techniques for attacker obfuscation.
• Preferred: experience working with an MDR partner.
• Preferred: possession of CompTIA CySA+, Security+, BTL1, GCIH, or equivalent practical security certifications.
• Fully remote work capacity available for residents of Canada.
• Flexibility to work within the Pacific time zone.
• Reasonable accommodations for qualified employees with protected disabilities, as mandated by applicable laws.
• Commitment to equal-opportunity employment.
Charter Technology Solutions
Viatris
Teamified
Zscaler
Get handpicked remote jobs straight to your inbox weekly.