SOC ANALYST TIER 2/3 (Contractor)

Remote, USA Full-time
SOC 2/3 Engineer (Remote Contractor): General Duties - Responsible for investigating security incidents and determining their root causes. They review incidents that have been escalated by Tier 1 analysts, who are responsible for collecting data and reviewing alerts. Tier 2/3 analysts use threat intelligence, such as indicators of compromise, TTPs, and company host system/network data sets to assess the alerts, threats and potential incidents in more depth. General Skills - They have deep experience with SIEM tools specifically Crowdstrike SIEM, network data, host data, Identity and Access log data, developing SIEM use cases, reducing/tuning false alerts and leading investigations until issues have been resolved. They will also monitor systems and events across different operating systems, such as Windows, macOS, and Linux. Specific Requirements - Must have 5+ years recent experience as Tier 2 or 3 analyst at a large organization; government and Critical Infrastructure company preferred. Must have strong, demonstrated SIEM and data correlation experience Must have demonstrated experience designing new SOC use cases and working with vendor on implementing new use cases. Must have experience designing and implementing runbooks and use cases to mitigate security incidents Experience designing Incident Response plan , including alert definition, runbooks, escalation, etc.. Experience documenting incident response communications for technical and management audiences Must have extensive experience reviewing and managing alerts in Microsoft Defender, Splunk Must have experience conducting hunts across disparate data sets, to include host data, vulnerability data, threat data, network data, active directory data, among others to identify threats Experience leading timely security operations response efforts in collaboration with stakeholders Must have experience setting up alert rules and effective alert management Demonstrated ability to create runbooks and conducting investigations with key application, IT Infra and other stakeholders Experience designing custom SOC SIEM use cases in Defender, Splunk and CRWD Experience conducting forensic work investigations Strong security operations documentation abilities Attributes sought - Must be proactive, problem solver and curious. Most be a problem solver Must be curious Must be analytical, qualitative and quantitative abilities Must be adaptive to dynamic environment **MST or PST shift times**
Apply Now

Similar Jobs

Publishing Manager (US, Remote or Hybrid)

Remote, USA Full-time

Learning Course Instructor (part-time) - Remote

Remote, USA Full-time

E&R Analytics Manager (Hulu)

Remote, USA Full-time

Remote Customer Support Representative at Hulu

Remote, USA Full-time

Kaiser Permanente ...

Remote, USA Full-time

Remote Clinical Psychologist Reviewer

Remote, USA Full-time

Freight Handler Part-Time

Remote, USA Full-time

Warehouse Specialist

Remote, USA Full-time

Head of Human Resources

Remote, USA Full-time

Executive Assistant (Remote, Non-Profit Industry)

Remote, USA Full-time

Experienced Aircraft Support Mechanic – Critical TechOps Role in Fleet Maintenance and Customer Experience at Blithequark

Remote, USA Full-time

Experienced Data Entry Specialist – Corporate Database Management and Information Maintenance

Remote, USA Full-time

Senior Director of Product Marketing – Sustainability Solutions

Remote, USA Full-time

Pandora Jewelry: Call Center Support Specialist - Remote Contractor 1099 (#OPA)

Remote, USA Full-time

Experienced System Engineer - Remote Opportunity at Southwest Airlines - $24-$35/Hour

Remote, USA Full-time

[Remote] Nurse Manager, Oncology Population Health

Remote, USA Full-time

Experienced Dog Walker & Sitter - Flexible Pet Care Opportunities with Tailster

Remote, USA Full-time

First Officer- Managed Aircraft Legacy 650 (home based)

Remote, USA Full-time

Flight Attendant at Delta Airlines Seattle, WA

Remote, USA Full-time

Experienced Full Stack Data Entry Associate - Remote Work from Home Opportunity with blithequark

Remote, USA Full-time
Back to Home