Tier 2 SOC Analyst - REMOTE
Summary
A hands-on security analyst who tunes detection rules, reduces false positives, and leads vulnerability management and remediation for clients using tools like Splunk and SentinelOne.
Binary Defense is seeking a client-facing Tier 2 SOC Analyst to serve as a hands-on contributor within a client’s Security Operations team.
This is a technical position responsible for transforming the client’s detection strategy, organizing detections, tuning rules, and creating and maintaining cross functional feedback loops. Additionally, leading analysis, design, and hands-on analysis and remediation for Attack Surface Reduction functions such as vulnerability management and penetration test remediation.
You’ll play a key role in growing capabilities with leading tools in the client’s environment such as Splunk, Proofpoint, SentinelOne, and more. This role requires deep technical expertise, strong cross-functional communication, and the ability to deliver operational results.
Responsibilities
- Create internal alert strategy and process documentation for how client identifies alerting opportunities, prioritizes based on threat level, with a focus and priority on gaps
- Review alerts that are too noisy to tune and drive down alert fatigue
- Assess alerts that haven’t triggered to determine whether logic needs to
- Be the main point of contact to the MDR Provider’s Detection team
- Work with the client’s Incident Responders on alert feedback loops; analyze true and false positive alerts
- Create regular reporting cadence for of all detections created, rules tuned
- Contribute to client’s homegrown “Signal to Noise ratio” detection metric
- Coordinate with MDR Threat Hunting team to request and implement Sentinel One STAR rules
- Map detections to standard frameworks such as the Cyber Kill Chain
- Work with MDR provider on an ongoing tuning of the on-call criteria
- Perform attack surface reduction including full-scope change management, cross functional coordination, enterprise communication planning/execution, execution of changes in support of security remediation
- Provide vulnerability prioritization and analysis, ticketing, reporting, trending, metrics, assistance to patch teams on troubleshooting root cause of patching challenges
- Analyze stale identities and accounts, admin privileges, and recommend and implement improvements