
Tier 2 SOC Analyst
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Manage and assess alerts and SOAR cases within the account queue.
• Achieve the established response targets based on priority levels.
• Implement containment and remediation procedures utilizing predefined playbooks.
• Analyze escalated cases across various domains including endpoint, identity, email, and network telemetry.
• Examine forensic artifacts when necessary.
• Incorporate threat intelligence and indicators of compromise during the triage process.
• Detect false positives and provide recommendations for alert tuning.
• Create case documentation that meets client review standards.
• Deliver a written handoff at the conclusion of each coverage period.
• Contribute to the development of runbooks and knowledge base material relevant to the account environment.
• Collaborate with the broader SOC team while overseeing triage, containment, and investigation during the designated coverage window.
• 3–5 years of experience in a SOC or security operations position.
• Demonstrated ability to manage a queue and make independent disposition decisions.
• High level of proficiency with EDR/XDR platforms and SIEM triage processes.
• Experience analyzing endpoint and network artifacts, including registry entries, file system activities, and event logs.
• Skills in malware triage and behavioral analysis.
• Familiarity with sandbox tools such as VirusTotal or Any.run.
• Understanding of attacker tactics as mapped to MITRE ATT&CK.
• Strong judgment in escalation processes and the ability to contextualize decisions.
• Ability to produce clear and structured written documentation suitable for client review.
• Beneficial but not mandatory: Experience with Google SecOps / Chronicle or CrowdStrike Identity Protection.
• Beneficial but not mandatory: Proficiency in scripting languages such as PowerShell, Python, Bash, or SQL.
• Beneficial but not mandatory: Experience in detection tuning.
• Beneficial but not mandatory: Previous experience in MSSP or public sector roles.
• Flexible scheduling options, allowing for start and end times to be adjusted by approximately one hour.
• Fully remote work environment.
• Open to any time zone.
• Initial contract for 90 days with the possibility of extension.
• Accommodation for early start times.
Zepto
Forward Financing
Forward Financing
Included Health
Get handpicked remote jobs straight to your inbox weekly.