
Tier 2 Cybersecurity Engineer
Posted Sep 17

Posted Sep 17
This is a fully remote position, open to applicants in Florida, +1 more state.
• Conduct thorough investigations and triage of security alerts produced by the SIEM.
• Evaluate correlated alerts across endpoint, identity, email, and network telemetry.
• Differentiate true positives from false positives and document findings with clarity.
• Lead incident response efforts, including containment, eradication, and recovery support.
• Escalate high-severity incidents with detailed impact analysis and proposed actions.
• Carry out advanced investigations and triage of security alerts generated by the EDR, SIEM, Firewalls, Sentinel, and other security tools.
• Install and configure security solutions as required.
• Monitor and respond to alerts generated by the SOC MDR.
• Provide contextual enrichment and validation of SIEM findings.
• Serve as the internal escalation point for complex or unclear detections.
• Collaborate with application/SOC support for feedback on detection and escalations.
• Manage Tier 2-level incidents from investigation to resolution.
• Ensure accurate case documentation and timelines are maintained.
• Create clear, customer-facing incident summaries when necessary.
• Contribute to post-incident reviews and lessons learned sessions.
• Mentor Tier 1 SOC analysts and assist with handling escalations.
• Participate in tabletop exercises and incident simulations.
• Stay updated on emerging threats, attacker techniques, and tool capabilities.
• Suggest enhancements to SOC processes, tools, and response workflows.
• A minimum of 5 years of hands-on experience in SOC, incident response, or security operations.
• Strong understanding of endpoint security principles.
• In-depth knowledge of email and phishing attack vectors.
• Solid understanding of identity-based attacks, including credential abuse and MFA bypass.
• Experience with SIEM platforms, including querying, investigations, and rule tuning.
• Proficiency with endpoint detection and response tools.
• Ability to document technical findings clearly for both technical and non-technical audiences.
• A valid and current CompTIA Security+ certification.
• GCIH (GIAC Certified Incident Handler) certification is a plus.
• CompTIA CySA+ certification is also a plus.
• Excellent health and dental benefits provided by BCBS/Guardian/Legalshield/Aflac.
• Vision coverage.
• Company-sponsored $50,000.00 life insurance policy.
• Short and long-term disability plans.
• 128 hours of PTO each year!
• Opportunities for bonuses and salary increases through our certifications program.
• Commissions for parts sold.
• Paid certifications.
• Complimentary snacks.
• Comprehensive training programs.
• Access to advanced tools.
• A collaborative team environment.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.