Security Analyst II
Core
L1 security analyst owning end-to-end triage of cloud audit, identity, WAF, and network flow detections with escalation to L2.
Role type
L1 SOC analyst (cloud & identity security)
Builds
Detection triage, containment actions, and alert quality feedback loops
Domain
Cybersecurity, Cloud Infrastructure, Identity Management
Deliverable
client delivery
Required skills
SIEM investigation, log correlation, threat intelligence enrichment, containment execution, ITSM ticketing, runbook authoring, trainee coaching, cross-domain coordination
Preferred skills
Kubernetes/container security, query languages (KQL/SPL/SQL), security certifications (Security+, CySA+, CEH), GCP logging/cloud security
Technologies
Exaforce, Cortex XSIAM, Chronicle, Splunk, Sentinel, Okta, Cloudflare, Cilium, Hubble, GCP, Kubernetes
Responsibilities
Triage and investigate Exaforce detections; correlate across log sources and enrich with threat intelligence; Execute approved containment steps; Maintain alert-quality feedback via false-positive tagging and tuning suggestions; Meet MTTA/MTTD SLAs; Author and refresh triage runbooks; Coordinate with the NOC shift on cross-domain events
Seniority
Mid-level, hands-on IC
