Security Analyst (Tier 2 SOC)

Security Analyst (Tier 2 SOC)

Department: Technical Operations / SOC

Reports to: Director of Technical Operations

Position Summary:

The Tier 2 SOC Analyst plays a critical role in defending clients from cyber threats through proactive monitoring, incident response, threat analysis, and effective management of client security services. This position is responsible for investigating escalated alerts, mentoring Tier 1 analysts, tuning and maintaining security platforms, supporting the onboarding and offboarding of clients across SOC applications and solutions, and enhancing the overall security posture of client environments.

Roles and Responsibilities:

Incident Response & Threat Analysis

  • Investigate security incidents escalated from Tier 1 SOC Analysts.
  • Conduct root cause analysis on recurring or advanced threats.
  • Identify and respond to phishing, malware, unauthorized access, insider threats, and other security events.
  • Assist with incident containment, remediation, documentation, and reporting.
  • Escalate significant incidents in accordance with established incident response procedures.

Security Platform Optimization

  • Tune SIEM, XDR, endpoint security, and other SOC platforms to improve detection accuracy and reduce false positives.
  • Recommend and implement enhancements to detection rules, alerting, and response playbooks.
  • Review security platform health, integrations, and data ingestion to identify configuration or coverage gaps.
  • Work closely with engineering and NOC to ensure security alerts are actionable and prioritized.

Client Security Onboarding & Offboarding

  • Perform technical onboarding of new clients into SOC-managed security applications, platforms, and solutions.Configure client environments, integrations, policies, alerting, monitoring, and required access according to established SOC standards and service requirements.Validate that required security tools, agents, integrations, log sources, and monitoring services are properly deployed and reporting as expected.
  • Coordinate with internal teams to ensure onboarding requirements and dependencies are completed accurately and on schedule.
  • Document client-specific configurations, integrations, contacts, escalation requirements, and operational procedures.
  • Perform technical offboarding of clients from SOC applications and solutions, including removal of integrations, agents, access, monitoring, and client-specific configurations as appropriate.
  • Validate completion of onboarding and offboarding activities using established checklists and quality-control procedures.
  • Identify gaps, inconsistencies, or opportunities to improve SOC onboarding and offboarding standards, documentation, and automation.

Threat Hunting & Research

  • Perform proactive threat hunting across client environments.
  • Analyze logs, endpoint telemetry, and network activity for indicators of compromise (IOCs).
  • Maintain awareness of emerging threats, vulnerabilities, attack techniques, and threat actor activity.
  • Recommend appropriate mitigations and detection improvements based on identified threats.

Mentorship & Collaboration

  • Guide and mentor Tier 1 SOC Analysts on investigation techniques, tools, documentation, and escalation procedures.
  • Assist Tier 1 analysts with complex or ambiguous security events.
  • Participate in internal tabletop exercises, training sessions, and knowledge-sharing activities.
  • Contribute to the development and maintenance of incident response runbooks, SOC procedures, and technical documentation.
  • Collaborate with NOC, Service Desk, Engineering, and other technical teams when security issues cross operational boundaries.

Tool Proficiency

  • SentinelOne and Microsoft Defender for Endpoint/XDR.
  • SIEM platforms such as Microsoft Sentinel, Splunk, LogRhythm, or equivalent.
  • Security monitoring, endpoint protection, vulnerability management, email security, and related SOC technologies.
  • PowerShell or other basic scripting and automation technologies.
  • ConnectWise Manage or comparable ITSM platforms for ticket tracking, workflow, and documentation.

Qualifications & Skills

Required Skills & Experience:

  • Bachelor's degree in Cybersecurity, Information Security, Information Technology, or related field, or equivalent practical experience.
  • 2–4 years of experience in SOC, cybersecurity operations, or managed security services.
  • Hands-on experience with SIEM, XDR, endpoint protection, or related security platforms.
  • Experience configuring, deploying, or administering security tools across multiple environments.
  • Ability to troubleshoot security platform integrations, agents, alerting, and data collection.
  • Knowledge of NIST, ISO 27001, and CIS security frameworks.
  • Strong understanding of incident response processes and security operations practices.

Preferred Experience / Certifications:

  • Experience working within an MSP, MSSP, or multi-client SOC environment.
  • Experience onboarding customers into managed security platforms or services.
  • CompTIA Security+ or CySA+.
  • GIAC certifications such as GCIA or GCIH, CEH, or other relevant vendor-neutral certifications.
  • Experience with scripting or automation used to improve SOC operational efficiency.

Soft Skills:

  • Strong analytical and investigative thinking.
  • Strong attention to detail and ability to follow standardized processes.
  • Ability to clearly document and communicate technical findings.
  • Ability to manage multiple client environments and priorities.
  • Strong sense of ownership and accountability for assigned work.
  • Collaborative mindset with a willingness to share knowledge and improve team processes.
  • Ability to communicate effectively with technical teams and internal stakeholders.

Job Type: Full-time (40 hours per week), Monday to Friday with participation in on-call rotation or extended shift coverage as needed.

Salary: $75,000 - $95,000 (based on experience)

Benefits: Dental insurance, Health insurance, Vision insurance, Life Insurance PTO, and 401(k)

Work Location: In-person (Cherry Hill, NJ, OR, West Caldwell, NJ, OR Boca Raton, FL

Disclaimer: This document outlines the key responsibilities and expectations for the Security Analyst (Tier 2 SOC) role. Responsibilities may evolve based on company priorities, technical operation needs, and business requirements.


EEO: We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, national origin, disability status, protected veteran status or any other characteristic protected by the law.

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available