SOC ANALYST TIER 2/3 (Contractor)

Remote Full-time
SOC 2/3 Engineer (Remote Contractor): General Duties - Responsible for investigating security incidents and determining their root causes. They review incidents that have been escalated by Tier 1 analysts, who are responsible for collecting data and reviewing alerts. Tier 2/3 analysts use threat intelligence, such as indicators of compromise, TTPs, and company host system/network data sets to assess the alerts, threats and potential incidents in more depth. General Skills - They have deep experience with SIEM tools specifically Crowdstrike SIEM, network data, host data, Identity and Access log data, developing SIEM use cases, reducing/tuning false alerts and leading investigations until issues have been resolved. They will also monitor systems and events across different operating systems, such as Windows, macOS, and Linux. Specific Requirements - Must have 5+ years recent experience as Tier 2 or 3 analyst at a large organization; government and Critical Infrastructure company preferred. Must have strong, demonstrated SIEM and data correlation experience Must have demonstrated experience designing new SOC use cases and working with vendor on implementing new use cases. Must have experience designing and implementing runbooks and use cases to mitigate security incidents Experience designing Incident Response plan , including alert definition, runbooks, escalation, etc.. Experience documenting incident response communications for technical and management audiences Must have extensive experience reviewing and managing alerts in Microsoft Defender, Splunk Must have experience conducting hunts across disparate data sets, to include host data, vulnerability data, threat data, network data, active directory data, among others to identify threats Experience leading timely security operations response efforts in collaboration with stakeholders Must have experience setting up alert rules and effective alert management Demonstrated ability to create runbooks and conducting investigations with key application, IT Infra and other stakeholders Experience designing custom SOC SIEM use cases in Defender, Splunk and CRWD Experience conducting forensic work investigations Strong security operations documentation abilities Attributes sought - Must be proactive, problem solver and curious. Most be a problem solver Must be curious Must be analytical, qualitative and quantitative abilities Must be adaptive to dynamic environment **MST or PST shift times**
Apply Now

Similar Opportunities

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote Full-time

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote Full-time

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote Full-time

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote Full-time

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote Full-time

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote Full-time

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote Full-time

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote Full-time

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote Full-time

USPS Office Helper

Remote Full-time

Telecommute bolthires Data Entry From Home ?entry Level/no Experience]

Remote Full-time

Experienced Customer Development Manager – Proactive Account Management and Complex Sales Initiatives

Remote Full-time

**Experienced Part-Time Entry-Level Remote Data Entry Clerk Typing Position at arenaflex - Flexible Hours and Competitive Pay Rates**

Remote Full-time

Stormwater Infrastructure Engineer

Remote Full-time

Apply for JobRegional Sales Manager - New EnglandApply for Job

Remote Full-time

Flexible Role for Abdominal Imaging Radiologist | Private Practice | Partnership-Track or Associate | SF Bay (Hybrid)

Remote Full-time

Portfolio Manager Associate

Remote Full-time

Remote Client Service Manager – Wealth Management Client Experience Leader for High‑Net‑Worth Portfolio Services (Hybrid Preferred)

Remote Full-time

Entry-Level Remote Customer Service Representative – Launch Your Career with arenaflex in a Dynamic and Supportive Environment

Remote Full-time

**Experienced Full Stack Data Analyst – Web & Cloud Application Development**

Remote Full-time
← Back to Home