Security Analyst Tier 2
Guarda esta oferta y sigue tu búsqueda
Crea una cuenta gratis para guardar empleos, crear alertas y volver a esta oferta desde tu panel.
Your Mission
As a Tier 2 SOC Analyst, you will serve as a subject matter expert in our technology stack while optimizing security tools and detection workflows, mentoring junior analysts on complex investigation techniques, and driving continuous improvement initiatives across our multi-client SOC environment.
This role demands advance analytical skills to conduct in-depth analysis of escalated security incidents from Tier 1 analysts, performing advanced threat investigations to determine attack vectors, assess impact scope, and develop comprehensive remediation strategies.
Your responsibilities will be:
- General responsibilities
- Use AI to support continuous improvement work: refining incident templates, proposing workflow enhancements, and contributing to SOP updates.
- Propose enhancement on tools and workflow
- Respond in a timely manner (within documented SLA) to support tickets.
- Document actions in tickets to effectively communicate information internally and to customers.
- Adhere to policies, procedures, and security best practices.
- Take responsibility for customer satisfaction and overall success of managed services.
- Be available, ready, and able to accept incoming clients calls
- Mentor fellow Security Engineers and Security Analysts.
- Service improvement
- Optimize SIEM rules and detection logic to reduce false positives and improve detection accuracy Support rules factory program in improving the global set of detection
- Validate Go-to-Active and Go-to-Prod gates of our new clients to ensure a smooth transition to operation
- Continuously improve incident templates in terms of content for the clients and in terms of
- automation to best support the operation
- Support rollout of new set of rules for our clients
- Qualify, analyze, and provide recommendations for new standard data source requests
- Support Product teams to build best new services to fit with Operations capabilities (needs,
- scalability, efficiency)
- Threat Monitoring
- Manage escalated cases from T1 Analysts
- Analyze and respond to security events from SIEM, EDR, FWs, IDS, IPS, AV and other security data
- sources.
- Use approved AI tools to summarize complex incident timelines and consolidate evidence across sources (SIEM/EDR/network) to speed up escalated investigations.
- Use AI-assisted analysis to identify patterns, likely attack paths, and investigation hypotheses, supporting deeper incident scoping and threat hunting activities.
- Deliver high quality Incident Handling and investigation
- Conduct threat hunting activities using advanced analytics and threat intelligence
- Provide 24/7 on-call support for critical security incidents outside business hours
You are
- A team-player willing to iterate on our internal processes to improve the team’s efficiency
- Experience in international/global environment
- At ease with solving complex problems
- Dynamic, with strong interpersonal and communication skills
- Autonomous, self-taught and transparent
- Able to handle and prioritize parallel tasks with multiple interfaces
- Fluent in English
You have
- Minimum 4 years of hands-on experience in cybersecurity operations, incident response, or threat analysis, bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or equivalent experience and
- Proven track record in a SOC and international/global environment
- Advanced proficiency with SIEM platforms (Splunk, QRadar, Sentinel, etc.)
- Extensive experience with EDR/XDR solutions (CrowdStrike, SentinelOne, Microsoft Defender, etc.)
- Deep understanding of network security technologies (firewalls, IDS/IPS, network monitoring)
- Strong knowledge of Windows and Linux/Unix operating systems and forensics
- Experience with cloud security (AWS, Azure, GCP) and containerization technologies
- Familiarity with OT/ICS environments and industrial control systems security
- Proficiency in scripting languages (Python, PowerShell, Bash) for automation
- Understanding of threat intelligence platforms and MITRE ATT&CK framework
- Spanish or any other language
Why you’ll love it here
If you are seeking a culture that supports growth, fosters success, and moves the industry forward, then Kudelski Security is where you need to be As the premier provider of cybersecurit