Our client in IT/Tech sector is seeking a
seeking a SOC Analyst II to join the security operations team. This is a hands-on, second-line role at the center of the client's detection and response program.
Job Summary
The ideal candidate will spend each day investigating security alerts that have escalated beyond the initial triage layer, distinguishing genuine threats from false positives, and driving confirmed incidents through containment, remediation, and resolution. The ideal candidate will operate in a fast-paced, telemetry-rich environment spanning cloud and on-premises infrastructure, thousands of endpoints, and a modern security stack that includes SIEM, EDR, and email security platforms.
Beyond day-to-day monitoring, the ideal candidate will take ownership of improving the effectiveness of the security operations function. The ideal candidate will contribute to maturing detection content, reducing alert fatigue by tuning false positives, and enhancing incident response runbooks and playbooks to ensure consistent handling across shifts. Working closely with senior SOC analysts, threat hunters, and detection engineers, the ideal candidate will have the opportunity to strengthen technical expertise and progress toward a Tier 3 SOC Analyst or specialized Security Engineering career path. This is a fully remote opportunity available on either a full-time or contract basis.
Key Responsibilities
Monitor, triage, and investigate security alerts across SIEM, EDR, identity, and email security platforms
Own Tier 2 investigation, containment, eradication, and escalation of confirmed security incidents
Analyze logs, network traffic, endpoint telemetry, and user activity to identify indicators of compromise
Conduct root cause analysis and document incidents, findings, and response actions per established runbooks
Tune detection rules, suppress false positives, and recommend new detection logic in partnership with engineering
Participate in proactive threat hunting based on current threat intelligence and emerging tactics
Support and contribute to post-incident reviews, lessons learned, and continuous improvement of response playbooks
Maintain shift handoff notes and ensure continuity of monitoring across a 24/7 coverage model
Required Qualifications
2 to 4 years of hands-on SOC, incident response, or security analyst experience
Working knowledge of SIEM platforms such as Splunk, Microsoft Sentinel, or QRadar
Familiarity with EDR tooling including CrowdStrike, SentinelOne, or Microsoft Defender
Solid grounding in networking fundamentals, TCP/IP, DNS, and common attack techniques
Ability to interpret logs and telemetry to reconstruct an attack timeline
Strong written documentation and clear communication under time pressure
Preferred Qualifications
Security+, CySA+, GCIH, or equivalent certification
Experience with SOAR platforms and automation scripting in Python or PowerShell
Working familiarity with the MITRE ATT&CK framework and threat-informed defense
Exposure to cloud security monitoring in AWS or Azure