SOC Analyst Tier 2
Location
United States
Posted
7 days ago
Salary
0
Seniority
Senior
Job Description
SOC Analyst Tier 2
Vaultes
• Monitor SIEM, EDR, IDS/IPS, email security, vulnerability, and other security platforms for suspicious activity. • Triage alerts and distinguish false positives from actionable security events. • Investigate security events using log data, endpoint telemetry, network data, and threat intelligence. • Escalate incidents in accordance with severity, impact, and response procedures. • Document investigations, findings, and actions taken in ticketing/case management systems. • Support incident handling activities including containment, evidence collection, and coordination with technical teams. • Review vulnerability findings and assist with prioritization and routing to responsible teams. • Participate in shift turnover reporting and maintain accurate operational notes. • Support development and refinement of detection rules, playbooks, and standard operating procedures. • Contribute to metrics reporting such as alert volumes, escalation rates, false positives, and response timelines.
Job Requirements
- Ability to obtain and maintain a Public Trust
- US Citizenship is required
- Bachelor’s degree in cybersecurity, information systems, computer science, or related field; equivalent experience may be substituted.
- 3–5 years of experience in a SOC, cybersecurity operations, or related IT security role.
- Experience working with SIEM platforms, ticketing systems, and endpoint/network security tools.
- Understanding of common attack techniques, indicators of compromise, and incident triage workflows.
- Familiarity with Windows, Linux, Active Directory, cloud environments, and networking fundamentals.
- Familiarity with NIST, FISMA, RMF, or similar frameworks.
- Experience supporting federal, regulated, or compliance-driven environments.
- Strong analytical, written, and verbal communication skills.
- Comfortable working across shifts and during time-sensitive events.
Benefits
- Paid time off
- Paid holidays
- Work-from-home opportunities
- 401k with matching incentive
- Competitive Medical/dental/vision benefits
- Company provided life insurance
- Company provided short-term disability
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
Manager, Security Operations
RulaYour journey to mental well-being gets easier from here. Progress awaits.
• Lead the team responsible for how Rula detects, investigates, responds to, and learns from security events. • Manage and coach a team of engineers while remaining close to technical work such as detection design, alert tuning, incident response, runbooks, operations, and security automation. • Manage the relationships with security operations vendors and work closely with Security, Engineering, IT, Compliance, Privacy, and external partners to improve Rula's ability to protect patient and provider data. • Build practical security operations in a high-trust environment where clear communication, sound judgment, and measurable outcomes matter more than titles or jargon.
• Act as liaison with our Managed Security Service Provider (MSSP), reviewing Tier 1/2 alert summaries, validating findings with organizational context, and facilitating escalations for hands-on resolution • Conduct real-time troubleshooting, log analysis, endpoint forensics, and containment actions on internal systems using tools like MS Defender, Wiz, and Tenable • Participate in incident response activities, ensuring timely communication with stakeholders and proper documentation of security events • Support our endpoint security solutions, including EDR solutions across the enterprise • Monitor endpoint compliance, investigate agent health issues, and coordinate remediation with IT teams • Perform regular health checks, updates, and optimization of security agents to ensure maximum coverage and performance across all organizational assets • Generate compliance reports, executive briefings, and threat intelligence summaries for leadership and cross-functional teams (IT, Legal, Governance, Program Security)
• Continuously monitoring the alert queue for multiple clients, from small business to large organizations using multiple tools, such as IDS, SIEM and SOAR. • Conducting initial triage and investigation of alerts to identify potential true positives, false positives, policy violations, and compromises. • Escalating problematic alerts for client review and validation via email or phone. • Performing basic threat hunting activities against customer networks. • Assist with writing customer facing reports: Threat report, Advisories or Vulnerabilities. • Interfacing with customers to remediate security issues. • Meeting timely Service Level Agreements (SLAs) for the full alert and case life cycle.
• Deliverable 1: Mock-up of COMS NR/NS environment on the NATO Software Factory • Deliverable 2: Identification and documentation of the COMS requirements • Deliverable 3: Creation of a video demonstrating the identified requirements in D2 • Deliverable 4: Demonstration of the COMS mock-up environment



