SOC 2 Analyst
Core
Investigate security incidents, determine root causes, and lead investigations escalated from Tier 1 analysts using threat intelligence and system data.
Role type
Senior SOC 2 Analyst (Tier 2/3)
Builds
Security operations response efforts, incident response plans, and custom SIEM use cases
Domain
Cybersecurity / Security Operations Center
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SIEM tool expertise (CrowdStrike, Splunk, Microsoft Defender), data correlation, incident response planning, runbook design, threat hunting, forensic investigation, alert management, stakeholder collaboration
Preferred skills
Experience in government or Critical Infrastructure sectors, designing new SOC use cases with vendors
Technologies
CrowdStrike SIEM, Splunk, Microsoft Defender, Windows, macOS, Linux, Active Directory
Responsibilities
Review escalated incidents from Tier 1, assess alerts using threat intelligence (IoCs, TTPs), monitor systems across multiple OS, design and implement runbooks and incident response plans, conduct threat hunts across disparate data sets, lead security operations response, document incident communications
Seniority
Senior, hands-on IC