Posted on: 05/10/2026
Cyber Security Analyst II
Role Summary:
We are looking for an experienced Cyber Security Analyst II with strong expertise in Security Operations and Detection Engineering. The ideal candidate will be responsible for end-to-end alert investigation and triage while actively improving security detection capabilities.
This role involves identifying detection gaps, tuning noisy rules, developing new detection logic, and maintaining high-quality, high-fidelity security coverage across on-premises and cloud environments.
Key Responsibilities:
- Lead end-to-end investigation and triage of security alerts across on-premises and cloud environments.
- Operate as a frontline defender within a 24x7 SOC environment.
- Collaborate with cross-functional and global teams to investigate and respond to security threats.
- Identify detection gaps and implement new or enhanced detection rules.
- Tune low-value and noisy alerts to reduce false positives.
- Review, validate, and improve detection logic aligned with MITRE ATT&CK TTPs.
- Develop new security use cases based on attacker behavior and emerging threats.
- Maintain and improve security playbooks, SOPs, and investigation documentation.
- Analyze security telemetry from SIEM, EDR, NDR, firewall, cloud, and SaaS platforms.
- Investigate cloud security threats, including IAM anomalies and SaaS security alerts.
- Monitor and defend modern cloud workloads, including containerized and serverless environments.
- Identify opportunities for automation and AI-driven workflows within detection engineering pipelines.
- Use scripting to automate security enrichment, investigation, and operational tasks.
Required Technical Skills:
- 5+ years of experience in enterprise Security Operations / SOC environments.
- Strong experience in alert triage and detection engineering / content tuning.
- Hands-on experience with SIEM platforms and rule writing.
- Experience with EDR, NDR, and firewall logs.
- Strong understanding of cloud security and cloud log analysis.
- Experience identifying IAM anomalies and SaaS security threats.
- Knowledge of security monitoring across containers and serverless workloads.
- Strong understanding of MITRE ATT&CK framework and TTP mapping.
- Scripting experience with Python, PowerShell, and/or Bash.
- Experience developing, tuning, and validating security detection rules.
- Ability to work across global time zones in a 24x7 security operations environment.
Preferred Profile:
- Strong analytical and investigative mindset.
- Excellent technical documentation and communication skills.
- Ability to work independently with minimal supervision.
- Strong ownership and end-to-end problem-solving ability.
- Comfortable working with ambiguity and making analytical security decisions.
- Experience working in medium-to-large enterprise security environments.
Key Focus Areas:
- SIEM, Detection Engineering, Alert Triage, EDR, NDR, Firewall, Cloud Security, IAM, SaaS Security, MITRE ATT&CK, Python, PowerShell, Bash, SOC, Threat Detection.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1676604