
Tier 2 SOC Analyst, AI Tools Experience
Posted Sep 1

Posted Sep 1
This is a fully remote position, open to applicants in Texas.
• Revamp the client’s detection strategy.
• Structure detections, refine rules, and establish and maintain cross-functional feedback mechanisms.
• Lead the analysis, design, and hands-on evaluation and remediation for attack surface reduction initiatives, including vulnerability management and penetration testing remediation.
• Develop internal alert strategies and process documentation detailing how clients identify alerting opportunities and prioritize them based on threat level, emphasizing existing gaps.
• Examine excessive alerts and adjust them to minimize alert fatigue.
• Evaluate alerts that have not been triggered to ascertain if the underlying logic requires modification.
• Act as the primary liaison to the MDR provider’s Detection team.
• Collaborate with client Incident Responders on alert feedback loops and analyze true versus false positive alerts.
• Generate regular reports on newly created detections and adjusted rules.
• Contribute to the client’s “Signal to Noise ratio” detection metric.
• Coordinate with the MDR Threat Hunting team to request and implement SentinelOne STAR rules.
• Align detections with standard frameworks such as the Cyber Kill Chain.
• Collaborate with the MDR provider for ongoing tuning of on-call criteria.
• Execute attack surface reduction strategies, which include change management, cross-functional coordination, enterprise communication planning and execution, and security remediation adjustments.
• Offer vulnerability prioritization and analysis, ticketing, reporting, trending, metrics, and support to patch teams in resolving root causes of patching issues.
• Review stale identities and accounts along with admin privileges, providing recommendations and executing improvements.
• A minimum of 3 years in Security Operations or a related field.
• Experience with Artificial Intelligence (AI) tools.
• Proficiency with Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) tools.
• Experience in mapping detections to common frameworks and risk reduction models.
• Knowledge of the latest trends in attacker tactics, techniques, and procedures (TTPs).
• Competitive medical coverage for employees and their dependents.
• Dental coverage for employees and their dependents.
• Vision coverage for employees and their dependents.
• 401k matching with vesting occurring every payroll.
• Flexible and remote-friendly work environment.
• Opportunities for training to enhance your skill set.
Live Nation Entertainment
Samsara
Accendra Health
Axians Somnitec AG
Get handpicked remote jobs straight to your inbox weekly.