Our client in IT/Tech sector is seeking a seeking a SOC Analyst II to join the security operations team. This is a hands-on, second-line role at the center of the client's detection and response program.
Job Summary
The ideal candidate will spend each day investigating security alerts that have escalated beyond the initial triage layer, distinguishing genuine threats from false positives, and driving confirmed incidents through containment, remediation, and resolution. The ideal candidate will operate in a fast-paced, telemetry-rich environment spanning cloud and on-premises infrastructure, thousands of endpoints, and a modern security stack that includes SIEM, EDR, and email security platforms.
Beyond day-to-day monitoring, the ideal candidate will take ownership of improving the effectiveness of the security operations function. The ideal candidate will contribute to maturing detection content, reducing alert fatigue by tuning false positives, and enhancing incident response runbooks and playbooks to ensure consistent handling across shifts. Working closely with senior SOC analysts, threat hunters, and detection engineers, the ideal candidate will have the opportunity to strengthen technical expertise and progress toward a Tier 3 SOC Analyst or specialized Security Engineering career path. This is a fully remote opportunity available on either a full-time or contract basis.
Key Responsibilities
Monitor, triage, and investigate security alerts across SIEM, EDR, identity, and email security platforms
Own Tier 2 investigation, containment, eradication, and escalation of confirmed security incidents
Analyze logs, network traffic, endpoint telemetry, and user activity to identify indicators of compromise
Conduct root cause analysis and document incidents, findings, and response actions per established runbooks
Tune detection rules, suppress false positives, and recommend new detection logic in partnership with engineering
Participate in proactive threat hunting based on current threat intelligence and emerging tactics
Support and contribute to post-incident reviews, lessons learned, and continuous improvement of response playbooks
Maintain shift handoff notes and ensure continuity of monitoring across a 24/7 coverage model
Required Qualifications
2 to 4 years of hands-on SOC, incident response, or security analyst experience
Working knowledge of SIEM platforms such as Splunk, Microsoft Sentinel, or QRadar
Familiarity with EDR tooling including CrowdStrike, SentinelOne, or Microsoft Defender
Solid grounding in networking fundamentals, TCP/IP, DNS, and common attack techniques
Ability to interpret logs and telemetry to reconstruct an attack timeline
Strong written documentation and clear communication under time pressure
Preferred Qualifications
Security+, CySA+, GCIH, or equivalent certification
Experience with SOAR platforms and automation scripting in Python or PowerShell
Working familiarity with the MITRE ATT&CK framework and threat-informed defense
Exposure to cloud security monitoring in AWS or Azure
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in the US.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in the US, connecting you to thousands of jobs fast!
Find the best jobs in the US, apply in 1 click and get a job today!