freehire launches on Product Hunt on 26 August.

Follow →

Tier 2 SOC Analyst / GRC Specialist

Summary

Investigate escalated security alerts, lead incident response, and advise clients on ISO/IEC 27001 and Singapore Cyber Trust Mark compliance using SIEM, EDR, and cloud logs.

We are looking for a Tier 2 SOC Analyst/Engineer to serve as the escalation point for our Tier 1 SOC team. This role owns in-depth investigation of escalated alerts, performs root cause analysis, leads incident response activities, and provides Governance, Risk and Compliance (GRC) consultancy to clients pursuing ISO/IEC 27001 certification and the Singapore Cyber Trust Mark. You will be a technical anchor for the SOC — turning raw alerts into confirmed incidents and confirmed incidents into stronger, audit-ready security postures for the clients we support.

Department: Security Operations Center (SOC) & Governance, Risk & Compliance (GRC) team

Reports to: SOC Manager (with parallel reporting to GRC Lead)

Works closely with: Tier 1 SOC Analysts (escalation point), Detection Engineering, IT Infrastructure, Application Development

## Key Responsibilities

**Escalation & Investigation**

- Serve as the primary technical escalation point for Tier 1 analysts on alerts requiring deeper analysis

- Conduct in-depth investigations across endpoint, network, cloud, identity, and application telemetry

- Correlate data across multiple tools/log sources (SIEM, EDR, NDR, cloud logs, identity providers) to determine scope and impact

- Distinguish true positives from false positives and refine triage logic accordingly

**Root Cause Analysis**

- Perform root cause analysis on confirmed incidents to determine initial vector, method, and any control gaps

- Document attack timelines/kill chains and produce clear technical findings for stakeholders

- Identify systemic issues (misconfigurations, missing patches, process gaps) surfaced during investigations

**Incident Response**

- Lead or co-lead containment, eradication, and recovery activities for security incidents

- Coordinate with IT, engineering, legal, and management during active incidents per the IR plan

- Author incident reports, timelines, and post-incident/lessons-learned reviews

- Support tabletop exercises and continuous improvement of IR playbooks and runbooks

**Governance, Risk and Compliance (Client Consultancy)**

- Provide consultancy services to clients pursuing ISO/IEC 27001 certification, including gap analysis, ISMS design/implementation guidance, and Statement of Applicability (SoA) support

- Advise and support clients through the Singapore Cyber Trust Mark certification process, including preparation, control implementation guidance, and readiness assessments

- Conduct risk assessments and help clients build/maintain risk registers and risk treatment plans

- Develop and review client-facing security policies, standards, and procedures aligned to ISO 27001 Annex A and Cyber Trust Mark requirements

- Support clients through internal audits, certification audits, and surveillance audits, including evidence preparation and audit findings remediation

- Manage multiple client engagements concurrently, including scoping, timelines, and client communication

**Mentorship & Process**

- Mentor and provide technical guidance to Tier 1 analysts, including escalation reviews and knowledge transfer

- Contribute to and maintain SOC playbooks, runbooks, and standard operating procedures

- Support onboarding of new log sources, tools, and data feeds into the SOC's monitoring scope

- Participate in an on-call/escalation rotation as needed

## Required Qualifications

- 3+ years of hands-on SOC experience, with demonstrated progression into Tier 2/senior analyst responsibilities

- Strong understanding of the attack lifecycle, common TTPs, and the MITRE ATT&CK framework

- Hands-on experience with SIEM platforms (e.g., Splunk, Sentinel, QRadar, Elastic) for investigation and reporting

- Experience with EDR/XDR tools (e.g., CrowdStrike, Microsoft Defender, SentinelOne) for endpoint investigation

- Working knowledge of ISO/IEC 27001 (Annex A controls, ISMS requirements) and ability to guide clients through gap analysis and certification prep

- Familiarity with Singapore's Cyber Trust Mark scheme and its control/assessment requirements

- Comfortable communicating directly with clients — running workshops, presenting findings, and writing client-facing reports

- Solid grasp of networking fundamentals (TCP/IP, DNS, HTTP/S, proxies) and ability to read packet captures

- Experience with incident response processes: containment, eradication, recovery, and post-incident reporting

- Familiarity with cloud security monitoring (AWS/Azure/GCP logs, IAM, CloudTrail or equivalent)

- Scripting/automation skills (Python, PowerShell, or similar) for detection logic, parsing, or workflow automation

- Excellent written and verbal communication skills — able to translate technical findings for non-technical stakeholders

- Ability to remain calm and methodical under pressure during active incidents

## Preferred Qualifications

- Certifications such as GCIH, GCIA, GCFA, CySA+, ISO 27001 Lead Implementer/Lead Auditor, CISA, or CRISC

- Direct experience supporting clients through Cyber Trust Mark or Cyber Essentials Mark certification

- Experience leading or supporting ISO 27001 certification/surveillance audits as a consultant or internal practitioner

- Familiarity with digital forensics tools and techniques (memory/disk forensics)

- Prior experience mentoring or training junior analysts

## What Success Looks Like

- Reduced mean-time-to-detect (MTTD) and mean-time-to-respond (MTTR) for escalated incidents

- Well-documented incidents with clear root cause and remediation tracking

- Clients successfully achieving ISO 27001 certification and Cyber Trust Mark certification on schedule

- High client satisfaction with GRC consultancy engagements, from gap analysis through audit

- Stronger, more capable Tier 1 team through consistent mentorship and escalation feedback

See also