Tier 2 SOC Analyst

Job not on LinkedIn

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of STIGroup

STIGroup

11 - 50 employees

Founded 2000

💼 Consulting

📦 Logistics

🛡️ Insurance

Consulting • Logistics • Insurance

STIGroup is a cybersecurity and managed IT services provider that offers a comprehensive range of tailored solutions designed to meet business needs. With over 20 years of experience, they specialize in managed cybersecurity solutions, IT support, and compliance advisory services, all supported by a robust concierge helpdesk that operates 24/7. STIGroup combines proven methodologies with the latest technologies to ensure the security and integrity of their clients' critical information.

📋 Description

• Triage and disposition alerts and SOAR cases in the account queue • Meet agreed response targets according to priority • Execute containment and remediation actions using established playbooks • Investigate escalated cases across endpoint, identity, email, and network telemetry • Review forensic artifacts when warranted • Apply threat intelligence and indicators of compromise during triage • Identify false positives and submit alert-tuning recommendations • Produce case documentation suitable for client review • Provide a written handoff at the end of each coverage window • Contribute to runbooks and knowledge-base content for the account environment • Work alongside the wider SOC team while owning triage, containment, and investigation during the assigned window

🎯 Requirements

• 3–5 years in a SOC or security operations role • Proven ability to work a queue and make disposition decisions independently • Strong proficiency with EDR/XDR platforms and SIEM triage workflows • Endpoint and network artifact analysis, including registry entries, file system activity, and event logs • Malware triage and behavioral analysis • Experience with sandbox tooling such as VirusTotal or Any.run • Working knowledge of attacker tradecraft mapped to MITRE ATT&CK • Sound escalation judgment and ability to justify decisions in context • Clear, structured written documentation suitable for client review • Helpful but not required: Google SecOps / Chronicle or CrowdStrike Identity Protection experience • Helpful but not required: scripting with PowerShell, Python, Bash, or SQL • Helpful but not required: detection tuning experience • Helpful but not required: prior MSSP or public-sector experience

🏖️ Benefits

• Flexible schedule window, with start and end times adjustable by about an hour • Fully remote work • Any time zone • Initial 90-day term with intent to extend • Early start accommodation

Apply Now