Job Closed

This listing is no longer active.

Keyrock logo
Keyrock

Digital asset market makers building scalable, self-adaptive technologies to support efficient markets.

SOC Analyst, Level 2

Security OperationsSecurity OperationsOtherRemoteSeniorTeam 51-200Since 2017H1B No SponsorCompany SiteLinkedIn

Location

California + 4 moreAll locations: California | Florida | Illinois | New Jersey | New York

Posted

129 days ago

Salary

0

Seniority

Senior

2.5 yrs expEnglishServiceNowSplunk

Job Description

SOC Analyst, Level 2

Keyrock

• Take escalations from L1 and independently investigate complex, multi-signal alerts (identity compromise, cloud control-plane abuse, endpoint persistence, lateral movement, suspicious automation, data exfiltration). • Perform deep log/telemetry analysis across SIEM, EDR, cloud logs, IAM signals, network telemetry, email security, and SaaS audit trails. • Build and validate hypotheses, pivot across data sources, and produce clear incident timelines and scope assessments. • Serve as technical incident lead for defined incident types/severities (or co-lead with IR), driving containment and eradication steps within authorized bounds. • Execute and improve response playbooks for key scenarios (phishing/BEC, credential theft, token/key compromise, suspicious API activity, ransomware indicators, insider risk signals).

Job Requirements

  • 2–5+ years of SOC / incident response / security operations experience (or equivalent hands-on experience in a fast-paced production environment).
  • Strong ability to investigate across cloud security operations, endpoint security, identity, and core network fundamentals.
  • Proficiency with at least one SIEM and common SOC tooling (e.g., Splunk/Elastic/Sentinel; CrowdStrike/Defender; Jira/ServiceNow).
  • Ability to write clear incident documentation: timelines, scope, impact, containment actions, and recommended remediations.
  • Comfort operating in an on-call or shift environment (depending on coverage model).

Benefits

  • Remote work options
  • Professional development opportunities

Related Categories

Related Job Pages

More Security Operations Jobs

Sentinel Blue logo

SOC Analyst I

Sentinel Blue

Enterprise cybersecurity for small and medium businesses | Specialize in defense and federal | Ask us about CMMC/DFARS

OtherRemoteTeam 11-50H1B No Sponsor

• Continuously monitor the Security Information and Event Management (SIEM) dashboard and leverage security tools to detect potential security incidents and anomalies in real-time. • Analyze incoming alerts to determine their relevance and urgency; effectively distinguish between false and true positives to prioritize response efforts. • Conduct investigations by gathering context and other relevant logs to understand scope of alert. • Strictly adhere to established Service Level Agreements (SLAs), Incident Response (IR) playbooks and Standard Operating Procedures (SOPs) to ensure consistent and compliant handling of security events. • Create, update, and manage tickets in our case management system, ensuring all investigative steps, communications, and findings are thoroughly documented. • Identify and escalate complex or high-severity incidents to Tier II or Incident Response Team, providing clear details and a comprehensive summary of initial findings. • Perform basic remediation actions, such as blocking indicators and isolating compromised hosts, when authorized by SOPs or directed by senior personnel. • Demonstrate excellent verbal and written communication skills, when communicating with team members, clients, and/or stakeholders. • Contribute to the team’s knowledge base, creating or updating articles, SOPs, and/or playbooks when new trends or resolution methods are identified.

United States
$50K - $60K / year
Job Closed
Calendly logo

Security Operations Engineer

Calendly

The scheduling automation platform for eliminating the back-and-forth emails to find the perfect time — and so much more

OtherRemoteTeam 501-1,000Since 2013H1B No Sponsor

• Collaborating with Security Operations Center (SOC) team members to monitor, detect, and respond to cybersecurity threats in a timely manner. • Responding to cybersecurity incidents from identification through resolution. • Developing and maintaining up-to-date knowledge of the threat landscape, as well as advancements in cybersecurity technologies and methodologies. • Identifying, configuring and onboarding security telemetry sources/logs in support of threat detection and incident response • Collaborating with Engineering and SRE to identify and mitigate logging deficiencies • Developing new detection scenarios and queries to broaden and deepen the team’s detection coverage • Tuning and continuously improving existing detection queries to increase signal-to-noise ratio, and ensure our detections remain relevant and functional • Executing and improving incident response protocols and procedures to swiftly and effectively manage security incidents. • Identifying, developing and maintaining automation solutions to increase the efficiency and effectiveness of the team • Integrating various security and IT tools to enhance threat detection, incident response, and operational efficiency. • Conducting regular security assessments, threat hunts, and continuous monitoring to identify vulnerabilities, opportunities for posture enhancements and better incident preparedness. • Collaborating with Engineering, IT and other departments to support the implementation and evangelization of established cybersecurity best practices across the organization. • Leveraging JIRA for creating and managing dashboards, reports, and metrics that support cybersecurity operations and decision-making.

United States
$155.8K - $219.9K / year
Job Closed
6sense logo

Staff Security Engineer – SecOps, Threat

6sense

6sense Revenue AI™ reimagines the way revenue teams create, manage and convert pipeline into revenue.

Full TimeRemoteTeam 1,001-5,000Since 2013H1B Sponsor

• Execute on milestones for end-to-end SecOps & Threat initiatives in accordance with the Security roadmap • Identify and respond to complex security incidents, including system compromise, intrusion attempts, and/or denial of service attacks by conducting continuous monitoring, vulnerability assessments, and log analysis • Engage vendors, Infrastructure, IT, GRC, Cloud, and Application Security teams as required to validate alerts, ensure incident resolution, and perform root cause analysis • Research emerging threats, publicly disclosed vulnerabilities or attack vectors, and proactively push mitigating controls to products and services • Perform security forensics • Build security tools and advanced automation that enable the 6sense Security Team to operate at speed and scale • Propose, plan, lead, and execute threat exercises based on current security trends, advisories, publications, and academic research • Mentor engineers across Information Security to drive security controls and risk remediation • Communicate risks and mitigations across multiple audiences with varying levels of sensitivity • Execute on quarterly individual Key Results that support team Objectives (OKRs)

Romania
Coalfire logo

Senior Technical Manager, Security Operations

Coalfire

Cyber solutions that move you forward, faster.

OtherRemoteTeam 1,001-5,000Since 2001H1B Sponsor

• Act as the primary technical escalation point for complex operational issues across SIEM and continuous monitoring programs, ensuring quick and effective resolutions. • Maintain and optimize critical security systems, including SIEM platforms (e.g., Splunk, ELK, SumoLogic, Sentinel), vulnerability management and scanning tools (e.g., Nessus, Qualys, Tenable), and Anti-Virus/EDR solutions (Trend Micro Deep Security Manager, Microsoft Defender, Crowdstrike). • Oversee continuous monitoring activities for FedRAMP and other compliance programs, including vulnerability scanning, configuration management, security control validation, and compliance artifact generation. • Monitor and improve the team's use of automation and monitoring tools to drive operational efficiency across both SIEM and vulnerability management workflows. • Analyze and resolve system performance issues, ensuring compliance with FedRAMP, SOC, HIPAA, and other security/operational standards. • Participate in incident response, threat hunting, and post-mortem analysis to identify root causes and prevent recurrence. • Manage a team of engineers across SIEM operations and continuous monitoring (vulnerability management) functions, fostering a high-performing and engaged team culture. • Mentor and support the professional growth of engineers through training, feedback, and career development planning. • Assist with hiring, onboarding, and retention to ensure team stability and growth. • Oversee day-to-day delivery of security services, ensuring operational consistency and high-quality outcomes for both SIEM and continuous monitoring programs. • Track and optimize key metrics such as incident response times, vulnerability remediation rates, false positive reduction, operational efficiency, and compliance posture. • Develop and refine processes for incident response, vulnerability remediation, continuous monitoring reporting, and compliance documentation. • Work with cross-functional teams, including consulting teams, SREs, and professional services teams, to improve service delivery and client satisfaction.

United States
$94K - $163K / year
Job Closed