Security Operations Analyst II
AlphaSense
ABOUT THE ROLE
We are hiring Security Operations Analyst II to join our Security Operations team in a fully remote capacity from Canada. This role sits at Tier 1–2 in our operating model — you are past the stage of learning what alerts look like and ready to own triage, perform structured investigations, and contribute to detection quality. You will handle the day-to-day alert queue, investigate escalated or ambiguous cases, handle incidents and work closely with senior analysts and the Security Operations Manager to close coverage gaps.
We expect you to think analytically, document thoroughly, and operate with growing independence. You will be supported by experienced colleagues and a mature toolset, but you are expected to bring real investigative instinct and a curiosity to grow to the role from day one.
WHAT YOU WILL DO
Alert Triage & Investigation
- Monitor and triage alerts across endpoint, network, cloud, runtime and identity data sources with accuracy and appropriate urgency
- Perform structured investigations on escalated or ambiguous alerts: pivot across log sources, correlate events, and build a coherent timeline
- Classify alerts correctly — true positive, false positive, or benign — with documented rationale, not just a verdict
- Identify scope and blast radius on confirmed incidents: affected users, systems, and data before escalating or containing
- Escalate to senior analysts with a complete investigation package — context, evidence, timeline, and a hypothesis
Incident Response Support
- Participate in active incident response under senior analyst or manager direction: evidence collection, log pulls, timeline reconstruction
- Execute containment actions — endpoint isolation, account suspension, token revocation — as directed with documented rationale
- Maintain accurate and timely case documentation throughout the incident lifecycle
- Contribute to post-incident timelines and assist with root cause documentation
Cloud & Identity Security Monitoring
- Monitor cloud audit logs and native threat detection findings for suspicious IAM activity, unusual API calls, and access anomalies
- Investigate identity provider events: suspicious logins, MFA bypass attempts, session anomalies, and unauthorized app assignments
- Recognize common cloud-native attack patterns: credential abuse via metadata service, privilege escalation via IAM role assumption, and storage misconfiguration access
- Correlate cloud-side events with endpoint and network telemetry to build a fuller picture of attacker activity
Detection & Quality Improvement
- Flag false positives and noisy detections with enough context for a senior analyst or detection engineer to tune them
- Identify gaps in existing detection coverage based on alert patterns you observe during triage
- Apply knowledge of MITRE ATT&CK to label attacker techniques and communicate findings consistently
- Contribute to runbook accuracy by flagging outdated steps or missing guidance encountered during investigations
- Participate with Detections Engineers to build detections and contribute to automating activity with an Engineering mindset
Documentation & Communication
- Write clear, concise case notes that a colleague could pick up mid-investigation without needing to re-investigate from scratch
- Produce shift handoff summaries that accurately represent open cases, pending actions, and investigation status
- Communicate incident updates to the Security Operations Manager with sufficient clarity to brief upward without re-investigation
WHAT WE ARE LOOKING FOR
Required
- 2–4+ years of hands-on experience in a SOC, or security operations role with direct alert triage responsibility
- Solid understanding of the MITRE ATT&CK framework — you use it to label and communicate attacker behavior, not just reference it
- Working knowledge of EDR tooling: process tree analysis, behavioral detection review, and basic endpoint artifact interpretation
- Familiarity with SIEM-based investigation: querying logs, correlating events across sources, and building timelines from normalized data
- Understanding of foundational network protocols ( TCP/IP, DNS, TLS ) and how attackers abuse them
- Exposure to cloud security monitoring ex. AWS or GCP — including audit log review and IAM-related alert investigation
- Experience investigating identity-based alerts in an enterprise identity provider (e.g., Okta, Entra ID , or equivalent)
- Strong written communication: your case notes are accurate, structured, and useful to someone who wasn’t there
Preferred
- Experience with next-gen EDR platforms (e.g., CrowdStrike Falcon, SentinelOne , or equivalent) beyond basic alert review — RTR, process trees, custom detections
- Hands-on SIEM experience with a cloud-native platform (e.g., Google SecOps/Chronicle, Microsoft Sentinel , or equivalent)
- Exposure to CSPM or cloud security tooling (e.g., Wiz, Prisma Cloud , or equivalent) as an investigation data source
- Familiarity with AWS IR fundamentals : CloudTrail, GuardDuty, VPC Flow Logs, IAM chain analysis
- Understanding of encoding vs. encryption vs. hashing and their relevance to attacker obfuscation techniques
- Experience working alongside or receiving escalations from a managed detection and response (MDR) partner
- Relevant certifications: CompTIA CySA+, Security+, BTL1, GCIH , or equivalent practical security credential
- OverviewSecurity Operations Center Analyst II - Orlando, Florida Company Overview Statement:Working across the globe, V2X builds smart solutions... ...bring 120 years of successful mission support to improve security, streamline logistics, and enhance readiness. Aligned around...SuggestedRemote work
- ...ABOUT THE ROLE We are hiring Security Operations Analyst II to join our Security Operations team in a fully remote capacity from Canada. This role sits at Tier 1–2 in our operating model — you are past the stage of learning what alerts look like and ready to own triage...SuggestedFull timeRemote workShift work
- ...Inc. (GRS) is seeking an enthusiastic, motivated, detail orientated, and talented individual for the position of Security Operations Center (SOC) Analyst I. Job Description: Summary: The SOC Analyst’s primary function is to provide comprehensive Computer Network...SuggestedWork at officeRemote work
- GDH Consulting, Inc. is seeking a Security Operations Analyst to oversee the operations, governance, and administration of enterprise security solutions. You will conduct audits, manage risk assessments, and ensure compliance with HIPAA, HITRUST, ISO/IEC 27001, NIST, COBIT...SuggestedRemote job
$97.59k - $142.99k
...Summary:We have an exciting opportunity to join our team as a Sr. II Security Analyst - Vulnerabilities. In this role, the successful analyst will... ...vulnerabilitiesWork with stakeholders to harden equipment, operating systems and applicationsUsing Checkmarx, work with...SuggestedFull time- ...Security Operations Center Analyst Remote At Ardent, we hire people who want more than a job — they want to serve a mission that matters. Our teams... ...environments. This role combines Tier I and Tier II responsibilities, including initial alert validation, advanced...Work experience placementLocal areaRemote workFlexible hoursShift work
- ...Distinction, Experience and Achievement.We are seeking a Security Cooperation & FMS Analyst (Logistics Analyst II) to support the Logistics and Program Management... ...Security Cooperation Agencys (DSCA) International Operations Global Execution Division (OPS/GEX). This office...For contractorsRemote workFlexible hours2 days per week3 days per week
$36 per hour
...recruiter to learn more. Base pay range $36.00/hr - $36.00/hr Direct message the job poster from TekWissen Title: IT Security Analyst II Work Location: Detroit, MI, 48226 Duration: 9 Months Job Type: Contract Work Type: Remote Overview :...Contract workWork experience placementRemote work- ...Security Analyst II Netrix Global team is looking for an experienced Security Analyst II to join our growing security team. In this role... ...internal infrastructure against evolving cyber threats. You will operate within a global 24/7 SOC environment, playing a key role in...Casual workRemote workShift workNight shiftRotating shift
- ...IT Security Analyst II The IT Security Analyst II role is responsible for advanced monitoring, analysis, and mitigation of security alerts... ..., ensuring efficiency and scalability across all security operations. Key Responsibilities Security monitoring Lead...Contract workCasual workWork at officeAfternoon shift
$95k - $101k
Akima Data Management (ADM), an Akima company, is seeking Security Program Analyst II to provide program support to the Department of State... ...assists, as needed, the Facility Protection Division and the Operational Support Division security programs. The SPA II works...Full timeContract workPart timeFor contractorsWork at officeLocal areaRemote workWorldwide- ...following:TITLESecurity Compliance Analyst IILEVELMidRELATIONSHIPSAssigned Team... ...Capital RegionPOSITION SUMMARYThe Security Compliance Analyst II will assist the assigned Government... ...RESPONSIBILITIESCreates and develops Standard Operating Procedures, Policy, in support of...For contractorsWork at officeRemote work
$90k - $120k
...military prime contractors such as Lockheed Martin, Northrop Grumman, and Raytheon. POSITION SUMMARY: The Information Security Analyst II at the Marvin Group will be responsible for monitoring and protecting the organization from all vectors of cyber-attacks...Permanent employmentContract workFor contractorsWork experience placementWork at officeFlexible hours- ...Country USA State Ohio City Cincinnati Descriptions & requirements About the role:As a Senior Security Operations Center (SOC) Analyst at TQL, you'll help protect one of the nation's largest freight brokerage technology environments by leading the...H1b
$72.8k - $130k
...flexibility to telecommute* from anywhere within the U.S. as you take on some tough challenges.Position SummaryAs an AI Security Governance Operations Specialist within Optum Technology's Enterprise Information Security organization, you will play a critical role in the...Minimum wageFull timeWork experience placementLocal areaRemote work- ...Security Operations Analyst (AI Training) About the Role We're partnering with leading AI research labs to build the next generation of intelligent security systems - and we need experienced SOC professionals to make it happen. Your hands-on knowledge of real-...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...Security Operations Analyst (AI Training) About the Role We're looking for experienced Security Operations Analysts to help evaluate and improve AI systems designed for modern SOC environments. Your real-world expertise in threat detection, alert triage, and incident...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...The SOC Analyst’s primary function is to provide comprehensive Computer Network Defense... ...enterprise. This position will conduct security event monitoring, advanced analytics and... ...endpoint threat detection tools, and security operations ticket management. This position will...Remote work
- ...SOC Analyst The Security Operations Center (SOC) Analyst is responsible for operating and continuously enhancing Sun King's Security Operations Center. This role focuses on threat detection, threat hunting, incident response, digital forensics, and security automation...Remote work
- ...variety of industries. The company currently has 44,000 employees supporting its operations in 220 locations in 43 countries. The company is currently looking for an IT Security Operations Analyst, whowill be primarily responsible for the daily monitoring and response of IT...Permanent employmentTemporary workRemote workWeekend work
$75.2k - $158.1k
...Security Operations Analyst Step into a mission-driven cybersecurity role where your work directly protects critical DoD systems. As part of a high-priority defense program, you'll operate a modern, fully integrated security stack—from Elastic Security and Palo Alto...Contract workWork experience placementInterim roleRemote workFlexible hours- ...Security Operations Analyst Zepto is building the beating heart of Australia's real-time, account-to-account payments revolution. We're a rapidly-scaling business reimagining how money moves for some of Australia's largest merchants, organisations and payment platforms...Remote workWork from homeHome officeFlexible hours
$65k - $75k
...Position Details Position Details Position Details Advertising/Posting Title Security Operations Analyst Posting Summary Conduct in-depth analyses of operational security data sourced from Endpoint Detection and Response (EDR), Intrusion Detection and Prevention Systems...Full timeWork at officeRemote workAfternoon shift- ...you to become a part of our family to help make our vision of Quenching the Thirst of Our Neighbors a reality! Summary The Security Operations Analyst helps protect ABARTA Coca-Cola Beverages’ information technology (IT) and operational technology (OT) environments...Work at officeRemote workMonday to Friday
- ...Security Operations Analyst (AI Training) About the Role We're partnering with the world's leading AI research labs to build the next generation of AI-powered security operations tools. As a Security Operations Analyst, you'll bring your real-world SOC experience...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
$91.8k - $114.79k
...Position Title:Security Operations AnalystPosition Type:RegularHiring Range:$91,800 - $114,785 annually; Compensation will be based on education... ...Pay Frequency:AnnualPOSITION PURPOSEThe Security Operations Analyst is focused on supporting and enhancing security capabilities...Work at officeLocal areaRemote work- ...can leave your mark. Title: Medicaid Senior IT Privacy and Security Analyst Role type: Contract Location: Remote Job... ...Create and maintain System Security Plans. • Develop standard operating procedures, controls-related documentation, and other required...Contract workRemote work
- ...RESPONSIBILITIES: Monitor, analyze, investigate, and report on security events, alerts, vulnerabilities, and risks across the... ...Recommend and implement process improvements that enhance operational efficiency and reduce organizational risk. Participate in after...Full timeWork at officeWeekend workAfternoon shift
- ...Looking for an innovative organization and the opportunity to learn and grow professionally? We can help! We are seeking a IT Security Operations Analyst for the IT Technology Services contract. This project will provide IT service desk, systems, network, and security...Full timeContract workPart timeWork at officeRemote workMonday to Friday
$800 per month
...Reports to: Senior Manager, Security Operations Center Location: Remote Australia What We Do: Cybercrime is growing, and more businesses... ...up for each other. What You’ll Do: You’re a hands-on SOC Analyst who thrives on detecting and responding to cybercrime. You’ll...Full timeSummer workLocal areaRemote workWorldwideHome office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Operations Analyst II. Be the first to apply!
- physical security analyst Remote
- IT security analyst Remote
- senior security analyst Remote
- application security analyst Remote
- entry level security analyst Remote
- work from home security analyst Remote
- rate analyst Remote
- information security compliance analyst Remote
- security analyst Remote
- network security analyst Remote




