Tier 2 SOC Analyst / GRC Specialist
Summary
Investigate escalated security alerts, lead incident response, and advise clients on ISO/IEC 27001 and Singapore Cyber Trust Mark compliance using SIEM, EDR, and cloud logs.
We are looking for a Tier 2 SOC Analyst/Engineer to serve as the escalation point for our Tier 1 SOC team. This role owns in-depth investigation of escalated alerts, performs root cause analysis, leads incident response activities, and provides Governance, Risk and Compliance (GRC) consultancy to clients pursuing ISO/IEC 27001 certification and the Singapore Cyber Trust Mark. You will be a technical anchor for the SOC — turning raw alerts into confirmed incidents and confirmed incidents into stronger, audit-ready security postures for the clients we support.
Department: Security Operations Center (SOC) & Governance, Risk & Compliance (GRC) team
Reports to: SOC Manager (with parallel reporting to GRC Lead)
Works closely with: Tier 1 SOC Analysts (escalation point), Detection Engineering, IT Infrastructure, Application Development
## Key Responsibilities
**Escalation & Investigation**
- Serve as the primary technical escalation point for Tier 1 analysts on alerts requiring deeper analysis
- Conduct in-depth investigations across endpoint, network, cloud, identity, and application telemetry
- Correlate data across multiple tools/log sources (SIEM, EDR, NDR, cloud logs, identity providers) to determine scope and impact
- Distinguish true positives from false positives and refine triage logic accordingly
**Root Cause Analysis**
- Perform root cause analysis on confirmed incidents to determine initial vector, method, and any control gaps
- Document attack timelines/kill chains and produce clear technical findings for stakeholders
- Identify systemic issues (misconfigurations, missing patches, process gaps) surfaced during investigations
**Incident Response**
- Lead or co-lead containment, eradication, and recovery activities for security incidents
- Coordinate with IT, engineering, legal, and management during active incidents per the IR plan
- Author incident reports, timelines, and post-incident/lessons-learned reviews
- Support tabletop exercises and continuous improvement of IR playbooks and runbooks
**Governance, Risk and Compliance (Client Consultancy)**
- Provide consultancy services to clients pursuing ISO/IEC 27001 certification, including gap analysis, ISMS design/implementation guidance, and Statement of Applicability (SoA) support
- Advise and support clients through the Singapore Cyber Trust Mark certification process, including preparation, control implementation guidance, and readiness assessments
- Conduct risk assessments and help clients build/maintain risk registers and risk treatment plans
- Develop and review client-facing security policies, standards, and procedures aligned to ISO 27001 Annex A and Cyber Trust Mark requirements
- Support clients through internal audits, certification audits, and surveillance audits, including evidence preparation and audit findings remediation
- Manage multiple client engagements concurrently, including scoping, timelines, and client communication
**Mentorship & Process**
- Mentor and provide technical guidance to Tier 1 analysts, including escalation reviews and knowledge transfer
- Contribute to and maintain SOC playbooks, runbooks, and standard operating procedures
- Support onboarding of new log sources, tools, and data feeds into the SOC's monitoring scope
- Participate in an on-call/escalation rotation as needed
## Required Qualifications
- 3+ years of hands-on SOC experience, with demonstrated progression into Tier 2/senior analyst responsibilities
- Strong understanding of the attack lifecycle, common TTPs, and the MITRE ATT&CK framework
- Hands-on experience with SIEM platforms (e.g., Splunk, Sentinel, QRadar, Elastic) for investigation and reporting
- Experience with EDR/XDR tools (e.g., CrowdStrike, Microsoft Defender, SentinelOne) for endpoint investigation
- Working knowledge of ISO/IEC 27001 (Annex A controls, ISMS requirements) and ability to guide clients through gap analysis and certification prep
- Familiarity with Singapore's Cyber Trust Mark scheme and its control/assessment requirements
- Comfortable communicating directly with clients — running workshops, presenting findings, and writing client-facing reports
- Solid grasp of networking fundamentals (TCP/IP, DNS, HTTP/S, proxies) and ability to read packet captures
- Experience with incident response processes: containment, eradication, recovery, and post-incident reporting
- Familiarity with cloud security monitoring (AWS/Azure/GCP logs, IAM, CloudTrail or equivalent)
- Scripting/automation skills (Python, PowerShell, or similar) for detection logic, parsing, or workflow automation
- Excellent written and verbal communication skills — able to translate technical findings for non-technical stakeholders
- Ability to remain calm and methodical under pressure during active incidents
## Preferred Qualifications
- Certifications such as GCIH, GCIA, GCFA, CySA+, ISO 27001 Lead Implementer/Lead Auditor, CISA, or CRISC
- Direct experience supporting clients through Cyber Trust Mark or Cyber Essentials Mark certification
- Experience leading or supporting ISO 27001 certification/surveillance audits as a consultant or internal practitioner
- Familiarity with digital forensics tools and techniques (memory/disk forensics)
- Prior experience mentoring or training junior analysts
## What Success Looks Like
- Reduced mean-time-to-detect (MTTD) and mean-time-to-respond (MTTR) for escalated incidents
- Well-documented incidents with clear root cause and remediation tracking
- Clients successfully achieving ISO 27001 certification and Cyber Trust Mark certification on schedule
- High client satisfaction with GRC consultancy engagements, from gap analysis through audit
- Stronger, more capable Tier 1 team through consistent mentorship and escalation feedback