freehire launches on Product Hunt on 26 August.

Follow →

Tier 2 SOC Analyst - REMOTE

Summary

A hands-on security analyst who tunes detection rules, reduces false positives, and leads vulnerability management and remediation for clients using tools like Splunk and SentinelOne.


Binary Defense is seeking a client-facing Tier 2 SOC Analyst to serve as a hands-on contributor within a client’s Security Operations team.


This is a technical position responsible for transforming the client’s detection strategy, organizing detections, tuning rules, and creating and maintaining cross functional feedback loops. Additionally, leading analysis, design, and hands-on analysis and remediation for Attack Surface Reduction functions such as vulnerability management and penetration test remediation.


You’ll play a key role in growing capabilities with leading tools in the client’s environment such as Splunk, Proofpoint, SentinelOne, and more. This role requires deep technical expertise, strong cross-functional communication, and the ability to deliver operational results.


Responsibilities


  • Create internal alert strategy and process documentation for how client identifies alerting opportunities, prioritizes based on threat level, with a focus and priority on gaps
  • Review alerts that are too noisy to tune and drive down alert fatigue
  • Assess alerts that haven’t triggered to determine whether logic needs to
  • Be the main point of contact to the MDR Provider’s Detection team
  • Work with the client’s Incident Responders on alert feedback loops; analyze true and false positive alerts
  • Create regular reporting cadence for of all detections created, rules tuned
  • Contribute to client’s homegrown “Signal to Noise ratio” detection metric
  • Coordinate with MDR Threat Hunting team to request and implement Sentinel One STAR rules
  • Map detections to standard frameworks such as the Cyber Kill Chain
  • Work with MDR provider on an ongoing tuning of the on-call criteria
  • Perform attack surface reduction including full-scope change management, cross functional coordination, enterprise communication planning/execution, execution of changes in support of security remediation
  • Provide vulnerability prioritization and analysis, ticketing, reporting, trending, metrics, assistance to patch teams on troubleshooting root cause of patching challenges
  • Analyze stale identities and accounts, admin privileges, and recommend and implement improvements


See also