SOC Analyst II
Summary
Investigates security alerts, distinguishes threats from false positives, and drives incident containment/remediation using SIEM, EDR, and email security platforms in a fast-paced, telemetry-rich environment.
- Monitor, triage, and investigate security alerts across SIEM, EDR, identity, and email security platforms
- Own Tier 2 investigation, containment, eradication, and escalation of confirmed security incidents
- Analyze logs, network traffic, endpoint telemetry, and user activity to identify indicators of compromise
- Conduct root cause analysis and document incidents, findings, and response actions per established runbooks
- Tune detection rules, suppress false positives, and recommend new detection logic in partnership with engineering
- Participate in proactive threat hunting based on current threat intelligence and emerging tactics
- Support and contribute to post-incident reviews, lessons learned, and continuous improvement of response playbooks
- Maintain shift handoff notes and ensure continuity of monitoring across a 24/7 coverage model
- 2 to 4 years of hands-on SOC, incident response, or security analyst experience
- Working knowledge of SIEM platforms such as Splunk, Microsoft Sentinel, or QRadar
- Familiarity with EDR tooling including CrowdStrike, SentinelOne, or Microsoft Defender
- Solid grounding in networking fundamentals, TCP/IP, DNS, and common attack techniques
- Ability to interpret logs and telemetry to reconstruct an attack timeline
- Strong written documentation and clear communication under time pressure
- Security+, CySA+, GCIH, or equivalent certification
- Experience with SOAR platforms and automation scripting in Python or PowerShell
- Working familiarity with the MITRE ATT&CK framework and threat-informed defense
- Exposure to cloud security monitoring in AWS or Azure