Security Analyst - Level 2

Security AnalystSecurity AnalystFull TimeRemoteMid LevelTeam 1,001-5,000

Location

Romania

Posted

7 days ago

Salary

0

Seniority

Mid Level

Job Description

Security Analyst - Level 2

Accesa

Role Description You will be joining a team that operates as consultants and partners to our clients, helping them innovate their existing processes and tools. We are focused on efficiency, strong communication, and sustainable learning paths. You will have an impact on the project’s evolution and the chance to contribute your own ideas to build successful client relationships. We are looking for a SOC Analyst - Level 2 with strong experience in deeper investigation, incident validation, response recommendations, targeted hunting, and hands-on guidance for the analysts around them. This is the escalation and deeper-investigation analyst lane. It is expected to take technically demanding cases further than the Level 1 lane, improve case quality across the team, and help shape practical service improvements. It is not a baseline architecture role, and it is not the default owner of recurring detection content or day-to-day platform administration. This role includes scheduled weekly on-call escalation coverage outside normal working or rota hours, according to the agreed service process. Key Responsibilities - Lead the investigation of higher-severity, ambiguous, or fast-moving incidents across available security telemetry and case evidence. - Determine likely root cause, affected identities and assets, probable scope, and the next actions that matter most. - Use targeted hunting and hypothesis-testing workflows to validate suspicious activity and uncover related activity that is not obvious from the initial alert. - Produce clear investigation records and evidence-based response recommendations that support timely decision-making through the customer approval path. - Support clear customer-facing incident handling by turning technical findings into usable evidence summaries and next-step recommendations within the defined case path. - Review escalations from Level 1 analysts and help move difficult cases forward without unnecessary reinvention. - Provide scheduled weekly on-call escalation support according to the agreed service process. - Identify visibility gaps, weak alert context, and recurring investigative friction that should feed into detection tuning, playbook refinement, or workflow improvement. - Propose practical automation ideas where repetitive investigation work can be made faster or more consistent. - Support the technical growth of other analysts through case guidance, review, and operationally useful feedback. Qualifications - Strong hands-on experience in SOC, MDR, or incident-response work. - Practical depth in investigation across endpoint, identity, email, cloud, network, and case evidence. - Strong analytical skills for investigation, hunting, and validating suspicious activity. - Ability to assess scope, impact, and urgency in higher-severity cases. - Ability to produce evidence-based recommendations and clear escalation or response records. - Strong written and verbal communication in English. - Ability to guide Level 1 analysts through technically difficult casework. - Willingness and ability to participate in weekly on-call escalation coverage. - Responsible AI literacy, including the ability to use approved AI-assisted workflows cautiously, validate outputs against source evidence, avoid entering customer-sensitive data into unapproved or public AI tools, and avoid treating AI output as evidence, approval, or authority. - Ability to challenge weak AI-assisted analysis from others when it skips evidence validation, creates false confidence, or exceeds the approved operating model. Soft Skills - Consultative Approach: Ability to explain technical risks to non-technical business stakeholders. - Communication: Excellent written and verbal communication in English (German is a strong plus). - Proactive Mindset: A history of self-driven learning (e.g., setting up a home lab, following security researchers). Nice to Have - 3-5+ years of relevant experience in cybersecurity operations, incident response, or MDR delivery. - Hands-on exposure to Microsoft Sentinel, Microsoft Defender XDR, Cortex XSOAR, Elastic Security, Vectra NDR, or similar security operations platforms. - Strong KQL or equivalent query-language experience for investigation and hunting. - Experience with Logic Apps, SOAR workflows, or operational automation. - Familiarity with ATT&CK-style analysis and coverage discussions. - PowerShell or similar scripting experience for investigation support or workflow improvement. - Microsoft SC-200, SC-100, AZ-500, or similar operational security certifications. - German would be an advantage. Benefits - Enjoy our holistic benefits program that covers the four pillars that we believe come together to support our wellbeing, covering social, physical, emotional wellbeing, as well as work-life fusion. - Physical Wellbeing: Our wellbeing program includes medical benefits, gym support, and personalised fitness options for an active lifestyle, complemented by team events and the Healthy Habits Club. - Work-Life Fusion: In very dynamic industries such as IT, the line between our professional and personal lives can quickly become blurred. Having a one-size-fits-one approach gives us the flexibility to define the work-life dynamic that works for us. - Emotional Wellbeing: We believe that to maintain our overall health, we need to invest in our mental wellbeing just as much as we do in our physical health, social connections or in achieving work-life balance. - Social Wellbeing: As a growing community in a hybrid environment, we want to ensure we remain connected not just by the great work we do every day but through our passions and interests.

Related Job Pages

More Security Analyst Jobs

CallTek logo

Cyber Security Analyst

CallTek

Your White Label Enterprise Support Company.

Full TimeRemoteTeam 5,001-10,000Since 2008H1B No Sponsor

• Investigate security alerts escalated by SOC Level 1 analysts. • Perform deeper analysis of suspicious activity across SIEM, EDR, network, identity, cloud, and email security platforms. • Validate whether security events represent false positives, suspicious behavior, policy violations, or confirmed cybersecurity incidents. • Correlate events across multiple log sources to identify attack patterns, affected assets, compromised accounts, lateral movement, malware activity, or unauthorized access. • Determine the scope, severity, business impact, and urgency of security incidents. • Recommend containment, eradication, and remediation actions to the appropriate technical teams. • Create and maintain accurate incident timelines, investigation notes, evidence records, and escalation summaries. • Support phishing investigations, endpoint compromise analysis, suspicious login reviews, malware alerts, brute-force attacks, data exfiltration indicators, and cloud security events. • Review and improve SOC playbooks, investigation procedures, and escalation criteria. • Provide technical guidance, coaching, and feedback to SOC Level 1 analysts. • Identify recurring false positives and recommend tuning improvements for SIEM, EDR, and other detection platforms. • Participate in post-incident reviews and provide recommendations to improve detection, response, and prevention. • Support shift handovers by documenting open incidents, pending actions, and important operation contexts.

Philippines
Commonwealth of Virginia logo

Cloud Security Analyst - Information Technology

Commonwealth of Virginia

The Commonwealth of Virginia is a state in the South Atlantic region of the United States that stretches from the Appalachian Mountains to the Chesapeake Bay. W

Cloud Security Analyst - Information Technology - ID 20001876 - Harrisonburg, Virginia, United States - Information Technology - Information Technology - Full-Time (Salaried) - James Madison University Position Type: Full-time Staff (Classified) Position Status: Full-Time FLSA Status: Exempt: Not Eligible for Overtime College/Division: Information Technology Department: 100755 - IT - Reengineering Madison EG Pay Band: 5 Pay Rate: Pay Range Specify Range or Amount: $75,000 - $80,000 Is this a JMU only position? No Is this a grant-funded position? No Is this a Conflict of Interest designated position? No About JMU: At James Madison University (JMU), we’re more than just a publicly funded institution — we’re a vibrant, welcoming community located on a stunning campus where innovation, collaboration, and personal growth thrive. Our mission is to prepare students for a bright future, and we believe that starts with supporting the people who make it all possible: our employees. Why Work at JMU? We offer a comprehensive benefits package designed to support your professional journey and personal wellbeing: • Generous Leave: Enjoy paid vacation, sick leave, parental leave, community service leave, and 19 paid holidays annually. • Comprehensive Health Coverage: Access high-quality health insurance options that fit your needs. • Retirement Options: Plan for your future with retirement benefits through the Virginia Retirement System. • Employee Well-Being: Our Balanced Dukes program promotes wellness and work-life integration through resources, events, and support. • Tuition Waiver Program: Advance your education with our tuition waiver program for undergraduate and graduate courses taken at JMU. At JMU, we believe in Being the Change — and that starts with creating an environment where you can grow, contribute meaningfully, and feel supported every step of the way. Discover what makes JMU a great place to work: bit.ly/JMUEmployment General Information: We’re seeking an experienced Cloud Security Analyst to assess, monitor, and improve the security configuration and risk posture of our cloud applications and environments. This role will work closely within IT, and across campus to assist the university ensure compliance with security best practices, regulatory requirements, and internal policies. The ideal candidate has a strong understanding of cloud-based environments, security frameworks, and risk assessment methodologies. This position is eligible for a remote or hybrid work schedule. Duties and Responsibilities: •Evaluate the security configuration, access controls, and risk posture of cloud environments (SaaS, PaaS) used across the university. •Implement and maintain continuous monitoring processes to detect misconfigurations, access anomalies, and potential security threats. •Assist with audits and security reviews by providing necessary documentation and technical insights. •Work within IT and with business stakeholders to integrate security controls into cloud solutions during the implementation phase and ongoing governance processes. •Stay up to date with emerging security threats, trends, and regulatory changes to enhance the security posture of the university. •Conduct security assessments, gap analyses, and risk evaluations for new and existing cloud environments. •Establish and document security requirements and best practices for cloud application onboarding, configuration, and lifecycle management. •Work to automate processes to streamline and work more efficiently as we continue to grow. •Collaborate and build relationships with multiple teams throughout the university. •Influence internal security strategy, develop and execute security initiatives to meet our objectives, and help define the criteria and measurements that we use to assess our progress. Qualifications: •Professional experience in two or more of the following areas: •SaaS application configuration management •PaaS application configuration management •Identity, authentication, and access management •Working knowledge of compliance standards and risk mitigation •Experience securing key enterprise systems, including solutions like: Salesforce CRM, Oracle Cloud, Okta, Boomi, M365, AWS, Azure and Netskope. •Strong problem-solving abilities •Experience working with remote teams •Demonstrated proficiency in working with cross-functional teams Additional Considerations: •Proven experience in cloud application integration and secure configuration management •Experience working in organizations that develop software and / or operate managed infrastructure and technology services for their own customers •Experience working in organizations that develop and operate Software as a Service •Familiarity with implementation industry established benchmarks such as CIS Benchmarks Additional Posting Information: Conditions of Employment: Employment is contingent upon the successful completion of a criminal background check. E-Verify Notice: After accepting employment, new hires are required to complete an I-9 form and present documentation of their identity and eligibility to work in the United States. James Madison University uses the E-Verify system to confirm identity and work authorization. EEO Statement: James Madison University is committed to creating and supporting a diverse and inclusive work and educational community that is free of all forms of discrimination. This institution does not tolerate discrimination or harassment on the basis of age, color, disability, gender identity or expression, genetic information, national origin, parental status, political affiliation, race, religion, sex, sexual orientation or veteran status. We promote access, inclusion and diversity for all students, faculty, staff, constituents and programs, believing that these qualities are foundational components of an outstanding education in keeping with our mission. The university is interested in candidates whose experience and qualifications support an ongoing commitment to this core quality. Anyone having questions concerning discrimination should contact the Office for Equal Opportunity: (540) 568-6991. Reasonable Accommodation: If you are an individual with a disability and need assistance searching or applying for jobs please contact us at (540) 568-3597 or jobs@jmu.edu. You may also visit the JMU Human Resource Office, located at 752 Ott Street, Harrisonburg, VA 22807 and we will be happy to assist you. Each agency within the Commonwealth of Virginia is dedicated to recruiting, supporting, and maintaining a competent and diverse work force. Equal Opportunity Employer

Virginia
$75K - $80K / year
ContractRemoteTeam 11-50Since 2002H1B No Sponsor

• Perform risk assessments, audit reviews, generate findings reports, and make appropriate recommendations for improvement and track outcomes from those activities for DES reporting requirements. • Develop and formulate comprehensive reports detailing the findings, areas of non-compliance, required POA&Ms (Plan of Action and Milestones), environmental observations, and incident reports. • Review, update, and manage security related audit plans, security plans and risk plan documentation for accuracy and consistency, proactively solves problems. • Evaluate data and formulate comprehensive reports detailing the findings, areas of non-compliance, required action plans, and environmental observations. • Generates incident reports and investigates suspicious network activity. • Preparing audit documentation that supports audit results, drafting and editing audit findings to adhere to the standards and the agency's writing style. • Research agency and industry IT security practices standards, best practices, laws and regulations, and other applicable resources, ensures compliance with standards

Arizona
$45 / hour
Job Closed
CSG logo

Information Security Analyst II

CSG

CSG delivers innovative customer engagement solutions that help you acquire, monetize, engage and retain customers.

Full TimeRemoteTeam 5,001-10,000Since 1982H1B Sponsor

• Support the design, implementation, and continuous improvement of security controls, policies, and processes aligned with HITRUST requirements • Maintain the HITRUST certification posture, supporting assessments, and ensuring controls remain effective and audit ready • Collaborate closely with teams around the world • Play a key role in demonstrating CSG’s security posture to auditors, customers, partners, and regulators • Drive process improvements related to HITRUST compliance program, including control implementation and monitoring, assessment, evidence management and audit readiness

Brazil
Job Closed