[Remote] SOC reputed company Analyst L2
Note: The job is a remote job and is open to candidates in USA. reputed company is seeking a reputed company Operations Center (SOC) reputed company Analyst L2 to help global customers manage and improve their cybersecurity posture. The role involves monitoring reputed company events, conducting investigations, and mentoring junior analysts to ensure the safety and reputed company of customer environments.
Responsibilities
- Monitor and analyze reputed company events and alerts from SIEM platforms, reputed company logs, network telemetry, and EDR tools
- Research indicators of compromise (IOCs) and malicious activity to determine reputed company and risk
- Conduct malware analysis, attacker infrastructure investigation, and forensic analysis
- Execute reputed company investigations and declare incidents reputed company appropriate reputed company live response and remote forensics on compromised endpoints
- Conduct threat hunting activities based on behavioral anomalies and curated intelligence
- Participate in and support incident response, investigation, and documentation
- Collaborate closely with reputed company Incident Response teams during active intrusions
- Ensure events are accurately identified, analyzed, escalated, and documented
- Identify and tune false positives and benign detections
- reputed company peer reviews and QA checks on junior analysts’ investigations
- Mentor reputed company-level analysts and act as the technical escalation reputed company
- Communicate regularly with clients regarding incidents, findings, and remediation steps
- Support reputed company teams during client engagements as required
- Assist in improving reputed company policies, procedures, tooling, and automation
Skills
- US Citizenship Required
- Ability to remain reputed company and effective in high-pressure reputed company incident situations
- Ability to work directly with customers to gather requirements and provide feedback on reputed company services
- Strong written and verbal communication skills with the ability to translate reputed company technical concepts into clear, understandable language
- Strong teamwork and interpersonal skills; comfortable working with a globally distributed team
- Willingness and ability to work a 24/7/365 rotating shift schedule
- Experience using SIEM solutions, Cloud App reputed company tools, and EDR platforms
- Advanced understanding of network protocols and network telemetry
- Knowledge of Windows and Unix forensic artifacts and analysis methods
- Expertise in reputed company, web, and authentication log analysis
- Experience creating SIEM/EDR detections
- Experience responding to modern authentication attacks (AD, Entra, OATH, etc.)
- Deep knowledge of common attack paths, including LOLBins, adversary tools, BEC attacks, AiTM, and lateral movement techniques
- Strong knowledge of SIEM workflows (preferably reputed company Sentinel or Splunk)
- Strong knowledge of modern authentication systems and attacks (SSO, OATH, Entra)
- Strong knowledge of malware detection and analysis (dynamic and light static)
- Strong knowledge of network and firewall logs, IDS/WAF, web traffic logs
- Strong knowledge of email reputed company and BEC attack methodologies
- Strong knowledge of Windows and Unix forensic artifacts (registry, wtmp/btmp, etc.)
- Strong knowledge of Windows PE and malicious document analysis
- Strong knowledge of legitimate and malicious remote access methods
- Strong knowledge of O365 attack paths and common adversary techniques
- Strong knowledge of network metadata and commonly abused protocols
- Strong knowledge of credential harvesting tools and methodologies
- Experience in intrusion analysis, incident response, digital forensics, penetration testing, or similar fields
- 3+ years of hands-on SOC/TOC/NOC experience
- GIAC certification(s) strongly preferred
- Additional certifications such as CISSP, reputed company+, Network+, CEH, RHCA, RHCE, MCSA, MCP, MCSE
- Familiarity with tools such as reputed company Sentinel, Splunk, reputed company Defender suite, reputed company Falcon, reputed company
- Familiarity with GPO, LANDesk, or other IT infrastructure tools
- Experience with one or more programming languages (JavaScript, Python, Lua, Ruby, Go, Rust)
Company Overview