Security Operations Analyst II
Core
Tier 1-2 Security Operations Analyst responsible for alert triage, structured investigations, and incident response support across endpoint, network, cloud, and identity data sources.
Role type
mid-level SOC analyst (alert triage & investigation)
Builds
detection quality improvements and incident response outcomes
Domain
cybersecurity (SOC operations, cloud security, identity security)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
alert triage, structured investigation, MITRE ATT&CK framework application, EDR tooling, SIEM querying, network protocol analysis, cloud audit log review, identity provider investigation
Preferred skills
next-gen EDR platforms, cloud-native SIEM, CSPM tooling, AWS IR fundamentals, encoding/encryption/hash analysis, MDR partner collaboration
Technologies
EDR, SIEM, AWS, GCP, Okta, Entra ID, CrowdStrike Falcon, SentinelOne, Wiz, Prisma Cloud, CloudTrail, GuardDuty, VPC Flow Logs
Responsibilities
monitor and triage alerts across multiple data sources, perform structured investigations on escalated cases, classify alerts with documented rationale, identify incident scope and blast radius, execute containment actions, contribute to post-incident timelines, flag false positives for tuning, identify detection coverage gaps, write clear case notes and shift handoff summaries
Seniority
Mid-level, hands-on IC
