Posted on: 17/07/2026
About the Role :
We are seeking a Tier 2 SOC Analyst to join our Security Operations Center. In this role, you will investigate escalated alerts from Tier 1, perform in-depth threat analysis, and lead incident response activities. You will serve as a subject matter expert for the SOC team and play a key role in maturing our detection and response capabilities.
Responsibilities :
- Triage and investigate security alerts escalated from Tier 1 analysts, determining scope, impact, and root cause
- Perform in-depth analysis of endpoint, network, and log data using SIEM, EDR, and threat intelligence platforms
- Lead incident response activities including containment, eradication, and recovery
- Hunt proactively for threats and indicators of compromise (IOCs) across the environment
- Develop and refine detection rules, playbooks, and runbooks to improve SOC efficiency
- Mentor Tier 1 analysts and provide guidance on complex investigations
- Coordinate with IT, engineering, and business teams during active incidents
- Document findings and produce clear, actionable incident reports for technical and non-technical audiences
- Track and manage incidents through the full lifecycle using ticketing systems
- Contribute to post-incident reviews and recommend improvements to security controls
Required Qualifications :
- 3+ years of experience in SOC, incident response, or cybersecurity operations role
- Proficiency with SIEM platforms (e.g., Splunk, Microsoft Sentinel, QRadar)
- Hands-on experience with EDR tools (e.g., CrowdStrike Falcon, Microsoft Defender, Carbon Black)
- Strong understanding of the MITRE ATT&CK framework and its application to threat detection
- Solid knowledge of networking fundamentals (TCP/IP, DNS, HTTP/S, firewalls, proxies)
- Experience analyzing malware behavior, phishing campaigns, and intrusion attempts
- Familiarity with log analysis across Windows, Linux, and cloud environments
- Ability to write and run queries in SPL, KQL, or equivalent query languages
Preferred Qualifications :
- Relevant certifications : Security+, CySA+, CEH, GCIH, GCIA, or equivalent
- Experience with cloud security monitoring (AWS, Azure, or GCP)
- Scripting skills in Python, PowerShell, or Bash for automation and analysis
- Familiarity with SOAR platforms and playbook automation
- Prior experience with threat intelligence platforms (e.g., MISP, ThreatConnect)
What We Offer :
- Competitive salary and benefits
- Opportunities for professional development and certification support
- Collaborative team environment with exposure to a diverse technology stack
- Clear path to senior and Tier 3 analyst roles
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1655375