More jobs:
Cybersecurity Analyst – Tier 2
Job Description & How to Apply Below
Job Title Cybersecurity Analyst – Tier 2 Job Description
The Security Operations Center – Tier 2 Analyst will lead complex investigations, coordinate incident response efforts, and drive continuous improvement in threat detection and response capabilities. You will serve as a technical expert and escalation point for Tier 1 analysts, customers or other departments. This role supports incident detection, escalation, and response activities within customer environments, in line with agreed SOC service scope and service level agreements (SLAs).
You will have had previous experience in handling escalation from Tier 1 and direct work in security monitoring, threat intelligence, or incident response
- Perform advanced analysis of escalated security incidents and support investigation efforts.
- Act as an escalation point for Tier 1 analysts and provide expert guidance during incident response activities.
- Develop and tune detection rules and use cases in SIEM and other platforms.
- Perform threat hunting based on intelligence and behavioral analysis.
- Conduct forensic analysis and reverse engineering of malware when needed.
- Collaborate with threat intelligence teams to enrich investigations.
- Provide strategic recommendations to improve SOC processes and technologies.
- Mentor junior analysts and contribute to training programs.
- Participate in detection validation and lessons‑learned activities to enhance SOC detection and response.
- Validate complex alerts escalated by Tier 1
- Determine scope, impact, and severity of confirmed incidents.
- Perform deep log analysis, forensic investigations, and develop custom detection rules.
- Implement containment, mitigation and remediation accordance with playbooks and customer agreements
- Understanding TTPs (tactics, techniques, procedures) of threat actors
- Ability to develop custom detection rules and correlation logic
- Analyze data patterns and outliers to identify threat actor behaviors and insider threats.
- Conduct deep investigations into logs, network telemetry, and endpoint activity.
- Document findings, actions taken, and recommended next steps.
- Assist the SOC team during active security incidents by collecting evidence and containing low‑severity threats as per playbooks.
- Follow established runbooks to ensure consistent and compliant response actions.
- Respond to escalated security incidents requiring advanced analysis.
- Provide containment recommendations and support remediation.
- Processing user access requests (add, remove, modify) following established workflows.
- Enforcing least‑privilege principles and role‑based access standards.
- Conducting periodic access reviews (user accounts, permissions, group memberships).
- Investigating and escalating suspicious access activities or unauthorized access attempts.
- Assist with tracking and verifying system patch status as part of vulnerability review activities. Monitor patch‑related alerts (failed deployments, outdated versions) within security tools and coordinate remediation with IT operations. Support the vulnerability management process by validating missing patches identified during scans and escalating high‑risk findings. (This is aligned with Tier 1’s documented tasks involving vulnerability scans and reporting.)
- Generate clear, accurate incident reports and daily shift summaries.
- Communicate event details with internal teams in a professional and timely manner.
- Recommend improvements to detection rules, response processes, and SOC procedures.
- Stay current on cyber threat trends, attacker techniques (TTPs), and security best practices.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×