Tier 2 Security Operations Analyst

Location

United States

Posted

5 days ago

Salary

$95K - $120K / year

Seniority

Mid Level

No structured requirement data.

Job Description

Tier 2 Security Operations Analyst

Ostra Security

Role Description As a Tier 2 Security Operations Analyst, you are the investigative backbone of Ostra's managed SOC. You take ownership of escalated alerts and incidents across our clients' environments, driving them from detection through root-cause analysis and containment. You go beyond triage: - Investigate and classify incidents. - Own escalated alerts and incidents across client environments; classify them, determine severity, and analyze data and systems to establish cause, scope, and impact. - Lead response and containment. - Act as an incident handler for sensitive and need-to-know incidents, applying CSIRT best practices and Ostra's incident response model; coordinate with clients and external parties to drive incidents to closure. - Threat hunt. - Proactively hunt for novel and evasive threats using sound hunt methodology. - Engineer and tune detections. - Understand, monitor, and optimize SIEM detection rules and SOAR playbooks; continuously improve detection accuracy, reduce false positives, and accelerate or automate response. - Author and maintain playbooks. - Develop, document, and maintain playbooks and standard operating procedures (SOPs) for recurring incidents and tasks so the SOC can respond consistently and quickly. - Produce and apply threat intelligence. - Ingest threat data from open and closed sources, correlate it against client context to produce actionable intelligence, and take appropriate action to mitigate risk. - Communicate with clients. - Clearly explain technical findings, risk, and recommended actions to client stakeholders; deliver timely, well-written incident updates and reports within SLA. - Mentor Tier 1 analysts. - Guide and upskill Tier 1 analysts, review their work, and help raise the overall quality and speed of the SOC. - Improve continuously. - Refine processes and procedures to improve speed and accuracy, and contribute to a culture of measurable improvement. - Provide on-call escalation. - Serve as an escalation point during a rotating on-call schedule, supporting a global SOC and off-hours coverage as required by the business. Qualifications - 3–5 years of hands-on experience as a SOC analyst, incident responder, or security-focused network analyst, ideally in a fast-paced or multi-client environment. - Demonstrated experience investigating and escalating security incidents beyond initial triage—establishing root cause, scope, and impact. - Working knowledge of TCP/IP and common network protocols, Windows event logs, *nix audit logs, and IDS/IPS alerting. - Hands-on experience with core security tooling categories: SIEM, SOAR, EDR/XDR, next-generation firewalls (NGFW), IDS/IPS, HIDS/HIPS, antivirus, and vulnerability scanners. - Proficiency with at least one SIEM query language and the ability to build, tune, and troubleshoot detections. - Proficiency in at least one common scripting language (PowerShell, Bash, Python, or similar) to automate analysis and response. - Solid understanding of the MITRE ATT&CK framework and experience building use cases and SOPs around relevant TTPs. - Familiarity with the NIST Cybersecurity Framework and the ability to apply its principles in practice. - Strong technical writing skills—able to document processes, procedures, and incident findings clearly for varied audiences. - Excellent problem-solving skills and comfort working through ambiguity and incomplete information. - Self-motivated, dependable, and able to deliver end-to-end results in a high-tempo environment. - Bachelor's degree in a related field, or equivalent practical experience. - Willingness to participate in a rotating on-call schedule and provide off-hours support as needed. Preferred Qualifications - Prior experience at a managed security service provider (MSSP) or in a multi-tenant SOC. - Relevant certifications (preferred, not required): CompTIA Security+, CompTIA CySA+, GIAC (GCIH, GCIA, GCFA), or CISSP. - Cloud security experience across AWS, Azure, Google Cloud, and/or Microsoft 365. - Experience developing new detection use cases and SOAR automations from scratch. - Experience working with a geographically distributed team across multiple time zones. - Expert-level understanding of common and emerging security threats, vulnerabilities, and attacker tradecraft. Benefits - A people-first culture built on trust and authenticity. - Competitive pay and comprehensive benefits. - Professional growth opportunities in a fast-evolving industry. - A mission-driven company protecting good businesses from cyber threats. Equal Opportunity Statement Ostra Security is proud to be an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All employment decisions are made based on qualifications, merit, and business needs—without regard to race, color, religion, gender, gender identity, sexual orientation, national origin, age, disability, veteran status, or any other protected characteristic. FLSA Status Exempt Salary Grade $95,000 – $120,000 base, commensurate with experience (plus benefits) Position Type Full-time Remote Location Candidates residing in Minnesota will be given preference based on business needs and team alignment.

Related Categories

Related Job Pages

More Security Operations Jobs

Full TimeRemoteTeam 10,001+Since 1931H1B Sponsor

• Lead the Supplier Security Due Diligence & Monitoring Service and oversee day-to-day service delivery. • Manage and develop a team responsible for supplier security contracting support and risk-based decision making. • Review and interpret supplier security assessment outcomes and monitoring results to guide contractual negotiations. • Provide guidance on acceptable contractual security positions, fallback language, compensating controls, and alternative risk mitigation approaches. • Ensure consistent application of enterprise security requirements across supplier agreements. • Oversee documentation and tracking of contractual exceptions, deviations, and risk accommodations. • Escalate contractual positions that exceed established risk tolerances through appropriate governance and risk acceptance processes. • Partner closely with Legal, Procurement, Cybersecurity, Enterprise Risk Management, and business stakeholders to resolve complex supplier issues. • Establish and maintain operational metrics, service-level objectives, reporting, and quality management practices. • Lead continuous improvement efforts designed to improve scalability, consistency, and stakeholder experience.

United States
$120K - $193.7K / year
Full TimeRemoteTeam 1,001-5,000Since 2012H1B Sponsor

• Serve as a primary responder for Cyber Operations client systems, taking ownership of client configuration issues and tracking through resolution • Act as a point of escalation for other Engineers (Associate Engineer) and provide guidance and mentoring. • Advise best practice on SIEM and Enterprise Security products to both technical and relatively non-technical personnel • Provide remote consulting services via interactive client sessions to assist with implementation of multiple product vendors and technologies • Implement and configure discipline software and appliance-based products in large enterprise environments • Develop and maintain content and reporting • Provide escalation support to Tier 1 and 2 for Authorized Support Customers, following processes and interacting appropriately with both customers and partners when required • Perform knowledge transfers to clients regarding security and system configuration awareness • Performs other duties as assigned • Complies with all policies and standards

Florida + 2 moreAll locations: Florida | Kansas | Texas
NBCUniversal logo

Director, Retail Security Operations

NBCUniversal

Here you can create the extraordinary. Join us.

Full TimeRemoteTeam 10,001+Since 2004H1B Sponsor

• Lead the retail security operating model for company-owned stores while providing governance, advisory support, standards alignment, escalation coordination, and risk visibility for branded partner locations. • Build and mature enterprise governance structures, operational processes, reporting frameworks, standards, and accountability models. • Oversee key retail security programs, including guard force operations, cash logistics, alarm systems, video management, and asset protection technologies. • Establish performance metrics, dashboards, scorecards, and executive reporting that provide visibility into security risks, loss trends, compliance, vendor performance, and operational effectiveness. • Coordinate cross-functional response and escalation for retail security incidents, operational risks, vendor issues, and emerging threats. • Drive vendor performance through service-level expectations, scorecards, governance routines, and continuous improvement initiatives. • Partner closely with Retail Operations, Supply Chain, Finance, Audit, regional teams, branded partner stakeholders, and business leaders to strengthen controls, improve store readiness, and reduce risk. • Support investigative teams through operational coordination, reporting, and process enablement without assuming primary responsibility for investigations. • Influence outcomes across a highly matrixed environment through partnership, governance, relationship management, and executive alignment rather than direct authority. • Support branded partner locations through influence, advisory support, standards alignment, and relationship-led governance rather than direct operational control.

Colorado + 1 moreAll locations: Colorado | Minnesota
$114.9K - $199.5K / year
Securitas Security Services logo

Deputy Regional Director of Security Operations

Securitas Security Services

Securitas’ mission is to protect homes, workplaces, and communities by providing the security services they need to protect their assets, safeguard their people, and maintain their ability to generate profits. Core values - Integrity, Vigilance, and Helpfulness Employees come from diverse backgrounds, bringing distinctive skills and perspectives.

Full TimeRemoteTeam 10,001

Role Description The Deputy Regional Director of Security Operations (Deputy RDSO) supports the delivery of a large-scale, 24/7 physical security operations program for a multinational datacenter client across the AMER region. This role serves as a regional execution leader, working in close partnership with Regional Director(s) of Security Operations (RDSOs) to drive consistent, compliant, and high-performing operations. - Translate strategic direction into operational execution. - Drive performance, reinforce standards, and identify risks across the field. - Operate in a highly collaborative, fast-paced environment. - Manage complexity across multiple teams and stakeholders. In this role, you will partner with Regional Director(s) of Security Operations to help deliver consistent, high-performing security operations across assigned areas within the AMER region. - Work closely with Regional Security Managers (RSMs), site leaders, and internal partners. - Ensure operations align with client expectations, program standards, and contractual requirements. - Communicate directly and regularly with the client and execute client-driven tasks. - Drive the day-to-day execution of regional security operations. - Support and guide RSMs and site leadership to maintain strong performance across guarding operations, safety, and service delivery. - Drive and support adherence to SOPs, KPIs, SLAs, and compliance standards. - Review operational data and performance metrics to identify trends, risks, and gaps. - Play a key role in site stabilization efforts, new site launches, transitions, and overall operational readiness. - Support regional initiatives and continuous improvement efforts. - Participate in incident response and escalation management as needed. - Contribute to executive-ready reporting, dashboards, and client communications. This role operates in a fast-paced, 24/7 environment and requires flexibility to support after-hours operations during critical events. Qualifications - Bachelor’s degree in business, security, or a related field. - 8+ years of progressive leadership experience in physical security or account management. - Experience leading teams. - Experience supporting multi-site or regional operations in a 24/7 environment is strongly preferred. - Strong communication skills. - Sound judgment in high-pressure situations. - Process-driven approach. Requirements - Travel approximately 50% of the time. - Passion for travel and a valid passport. - Reliable means of communication. - Reliable means of transportation (public or private) to get to/from work. - Legal right to work in the country where the position is located. - Ability to speak, read, and write in English proficiently. Benefits - Base salary of $180,000 to $200,000. - 100% coverage of medical benefits. - Dental and Vision insurance. - Company-paid life and AD&D insurance. - Voluntary short-term disability and long-term disability. - Employee assistance program. - 4 floating holidays. - 10 paid holidays. - 3 weeks’ vacation every year. - Paid Family Leave - up to 12 weeks a year in accordance with State law.

United States
$180K - $200K / year