Ostra Security
Remote Jobs
1 Jobs
Role Description As a Tier 2 Security Operations Analyst, you are the investigative backbone of Ostra's managed SOC. You take ownership of escalated alerts and incidents across our clients' environments, driving them from detection through root-cause analysis and containment. You go beyond triage: - Investigate and classify incidents. - Own escalated alerts and incidents across client environments; classify them, determine severity, and analyze data and systems to establish cause, scope, and impact. - Lead response and containment. - Act as an incident handler for sensitive and need-to-know incidents, applying CSIRT best practices and Ostra's incident response model; coordinate with clients and external parties to drive incidents to closure. - Threat hunt. - Proactively hunt for novel and evasive threats using sound hunt methodology. - Engineer and tune detections. - Understand, monitor, and optimize SIEM detection rules and SOAR playbooks; continuously improve detection accuracy, reduce false positives, and accelerate or automate response. - Author and maintain playbooks. - Develop, document, and maintain playbooks and standard operating procedures (SOPs) for recurring incidents and tasks so the SOC can respond consistently and quickly. - Produce and apply threat intelligence. - Ingest threat data from open and closed sources, correlate it against client context to produce actionable intelligence, and take appropriate action to mitigate risk. - Communicate with clients. - Clearly explain technical findings, risk, and recommended actions to client stakeholders; deliver timely, well-written incident updates and reports within SLA. - Mentor Tier 1 analysts. - Guide and upskill Tier 1 analysts, review their work, and help raise the overall quality and speed of the SOC. - Improve continuously. - Refine processes and procedures to improve speed and accuracy, and contribute to a culture of measurable improvement. - Provide on-call escalation. - Serve as an escalation point during a rotating on-call schedule, supporting a global SOC and off-hours coverage as required by the business. Qualifications - 3–5 years of hands-on experience as a SOC analyst, incident responder, or security-focused network analyst, ideally in a fast-paced or multi-client environment. - Demonstrated experience investigating and escalating security incidents beyond initial triage—establishing root cause, scope, and impact. - Working knowledge of TCP/IP and common network protocols, Windows event logs, *nix audit logs, and IDS/IPS alerting. - Hands-on experience with core security tooling categories: SIEM, SOAR, EDR/XDR, next-generation firewalls (NGFW), IDS/IPS, HIDS/HIPS, antivirus, and vulnerability scanners. - Proficiency with at least one SIEM query language and the ability to build, tune, and troubleshoot detections. - Proficiency in at least one common scripting language (PowerShell, Bash, Python, or similar) to automate analysis and response. - Solid understanding of the MITRE ATT&CK framework and experience building use cases and SOPs around relevant TTPs. - Familiarity with the NIST Cybersecurity Framework and the ability to apply its principles in practice. - Strong technical writing skills—able to document processes, procedures, and incident findings clearly for varied audiences. - Excellent problem-solving skills and comfort working through ambiguity and incomplete information. - Self-motivated, dependable, and able to deliver end-to-end results in a high-tempo environment. - Bachelor's degree in a related field, or equivalent practical experience. - Willingness to participate in a rotating on-call schedule and provide off-hours support as needed. Preferred Qualifications - Prior experience at a managed security service provider (MSSP) or in a multi-tenant SOC. - Relevant certifications (preferred, not required): CompTIA Security+, CompTIA CySA+, GIAC (GCIH, GCIA, GCFA), or CISSP. - Cloud security experience across AWS, Azure, Google Cloud, and/or Microsoft 365. - Experience developing new detection use cases and SOAR automations from scratch. - Experience working with a geographically distributed team across multiple time zones. - Expert-level understanding of common and emerging security threats, vulnerabilities, and attacker tradecraft. Benefits - A people-first culture built on trust and authenticity. - Competitive pay and comprehensive benefits. - Professional growth opportunities in a fast-evolving industry. - A mission-driven company protecting good businesses from cyber threats. Equal Opportunity Statement Ostra Security is proud to be an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All employment decisions are made based on qualifications, merit, and business needs—without regard to race, color, religion, gender, gender identity, sexual orientation, national origin, age, disability, veteran status, or any other protected characteristic. FLSA Status Exempt Salary Grade $95,000 – $120,000 base, commensurate with experience (plus benefits) Position Type Full-time Remote Location Candidates residing in Minnesota will be given preference based on business needs and team alignment.