Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Operations Analyst II

Full-time

AlphaSense

ABOUT THE ROLE

We are hiring Security Operations Analyst II to join our Security Operations team in a fully remote capacity from Canada. This role sits at Tier 1–2 in our operating model — you are past the stage of learning what alerts look like and ready to own triage, perform structured investigations, and contribute to detection quality. You will handle the day-to-day alert queue, investigate escalated or ambiguous cases, handle incidents and work closely with senior analysts and the Security Operations Manager to close coverage gaps.

We expect you to think analytically, document thoroughly, and operate with growing independence. You will be supported by experienced colleagues and a mature toolset, but you are expected to bring real investigative instinct and a curiosity to grow to the role from day one.

WHAT YOU WILL DO

Alert Triage & Investigation

  • Monitor and triage alerts across endpoint, network, cloud, runtime and identity data sources with accuracy and appropriate urgency
  • Perform structured investigations on escalated or ambiguous alerts: pivot across log sources, correlate events, and build a coherent timeline
  • Classify alerts correctly — true positive, false positive, or benign — with documented rationale, not just a verdict
  • Identify scope and blast radius on confirmed incidents: affected users, systems, and data before escalating or containing
  • Escalate to senior analysts with a complete investigation package — context, evidence, timeline, and a hypothesis

Incident Response Support

  • Participate in active incident response under senior analyst or manager direction: evidence collection, log pulls, timeline reconstruction
  • Execute containment actions — endpoint isolation, account suspension, token revocation — as directed with documented rationale
  • Maintain accurate and timely case documentation throughout the incident lifecycle
  • Contribute to post-incident timelines and assist with root cause documentation

Cloud & Identity Security Monitoring

  • Monitor cloud audit logs and native threat detection findings for suspicious IAM activity, unusual API calls, and access anomalies
  • Investigate identity provider events: suspicious logins, MFA bypass attempts, session anomalies, and unauthorized app assignments
  • Recognize common cloud-native attack patterns: credential abuse via metadata service, privilege escalation via IAM role assumption, and storage misconfiguration access
  • Correlate cloud-side events with endpoint and network telemetry to build a fuller picture of attacker activity

Detection & Quality Improvement

  • Flag false positives and noisy detections with enough context for a senior analyst or detection engineer to tune them
  • Identify gaps in existing detection coverage based on alert patterns you observe during triage
  • Apply knowledge of MITRE ATT&CK to label attacker techniques and communicate findings consistently
  • Contribute to runbook accuracy by flagging outdated steps or missing guidance encountered during investigations
  • Participate with Detections Engineers to build detections and contribute to automating activity with an Engineering mindset

Documentation & Communication

  • Write clear, concise case notes that a colleague could pick up mid-investigation without needing to re-investigate from scratch
  • Produce shift handoff summaries that accurately represent open cases, pending actions, and investigation status
  • Communicate incident updates to the Security Operations Manager with sufficient clarity to brief upward without re-investigation

WHAT WE ARE LOOKING FOR

Required

  • 2–4+ years of hands-on experience in a SOC, or security operations role with direct alert triage responsibility
  • Solid understanding of the MITRE ATT&CK framework — you use it to label and communicate attacker behavior, not just reference it
  • Working knowledge of EDR tooling: process tree analysis, behavioral detection review, and basic endpoint artifact interpretation
  • Familiarity with SIEM-based investigation: querying logs, correlating events across sources, and building timelines from normalized data
  • Understanding of foundational network protocols ( TCP/IP, DNS, TLS ) and how attackers abuse them
  • Exposure to cloud security monitoring ex. AWS or GCP — including audit log review and IAM-related alert investigation
  • Experience investigating identity-based alerts in an enterprise identity provider (e.g., Okta, Entra ID , or equivalent)
  • Strong written communication: your case notes are accurate, structured, and useful to someone who wasn’t there

Preferred

  • Experience with next-gen EDR platforms (e.g., CrowdStrike Falcon, SentinelOne , or equivalent) beyond basic alert review — RTR, process trees, custom detections
  • Hands-on SIEM experience with a cloud-native platform (e.g., Google SecOps/Chronicle, Microsoft Sentinel , or equivalent)
  • Exposure to CSPM or cloud security tooling (e.g., Wiz, Prisma Cloud , or equivalent) as an investigation data source
  • Familiarity with AWS IR fundamentals : CloudTrail, GuardDuty, VPC Flow Logs, IAM chain analysis
  • Understanding of encoding vs. encryption vs. hashing and their relevance to attacker obfuscation techniques
  • Experience working alongside or receiving escalations from a managed detection and response (MDR) partner
  • Relevant certifications: CompTIA CySA+, Security+, BTL1, GCIH , or equivalent practical security credential
Vacancy posted 13 days ago
Similar jobs that could be interesting for youBased on the Security Operations Analyst II in Remote vacancy
  • OverviewSecurity Operations Center Analyst II - Orlando, Florida Company Overview Statement:Working across the globe, V2X builds smart solutions...  ...bring 120 years of successful mission support to improve security, streamline logistics, and enhance readiness. Aligned around... 
    Suggested
    Remote work

    V2X

    Orlando, FL
    1 day ago
  •  ...ABOUT THE ROLE We are hiring Security Operations Analyst II to join our Security Operations team in a fully remote capacity from Canada. This role sits at Tier 1–2 in our operating model — you are past the stage of learning what alerts look like and ready to own triage... 
    Suggested
    Full time
    Remote work
    Shift work

    AlphaSense

    Remote
    14 days ago
  •  ...Inc. (GRS) is seeking an enthusiastic, motivated, detail orientated, and talented individual for the position of Security Operations Center (SOC) Analyst I. Job Description: Summary:  The SOC Analyst’s primary function is to provide comprehensive Computer Network... 
    Suggested
    Work at office
    Remote work

    Global Resource Solutions, Inc.

    Colorado Springs, CO
    14 days ago
  • GDH Consulting, Inc. is seeking a Security Operations Analyst to oversee the operations, governance, and administration of enterprise security solutions. You will conduct audits, manage risk assessments, and ensure compliance with HIPAA, HITRUST, ISO/IEC 27001, NIST, COBIT... 
    Suggested
    Remote job

    Gdh Consulting, Inc.

    Plano, TX
    1 day ago
  • $97.59k - $142.99k

     ...Summary:We have an exciting opportunity to join our team as a Sr. II Security Analyst - Vulnerabilities. In this role, the successful analyst will...  ...vulnerabilitiesWork with stakeholders to harden equipment, operating systems and applicationsUsing Checkmarx, work with... 
    Suggested
    Full time

    NYU Langone Medical Center

    New York, NY
    1 day ago
  •  ...Security Operations Center Analyst Remote At Ardent, we hire people who want more than a job — they want to serve a mission that matters. Our teams...  ...environments. This role combines Tier I and Tier II responsibilities, including initial alert validation, advanced... 
    Work experience placement
    Local area
    Remote work
    Flexible hours
    Shift work

    Ardent Services

    United States
    5 days ago
  •  ...Distinction, Experience and Achievement.We are seeking a Security Cooperation & FMS Analyst (Logistics Analyst II) to support the Logistics and Program Management...  ...Security Cooperation Agencys (DSCA) International Operations Global Execution Division (OPS/GEX). This office... 
    For contractors
    Remote work
    Flexible hours
    2 days per week
    3 days per week

    Advanced Decision Vectors

    Arlington, VA
    1 day ago
  • $36 per hour

     ...recruiter to learn more. Base pay range $36.00/hr - $36.00/hr Direct message the job poster from TekWissen Title: IT Security Analyst II Work Location: Detroit, MI, 48226 Duration: 9 Months Job Type: Contract Work Type: Remote Overview :... 
    Contract work
    Work experience placement
    Remote work

    Tekwissen

    Detroit, MI
    3 days ago
  •  ...Security Analyst II Netrix Global team is looking for an experienced Security Analyst II to join our growing security team. In this role...  ...internal infrastructure against evolving cyber threats. You will operate within a global 24/7 SOC environment, playing a key role in... 
    Casual work
    Remote work
    Shift work
    Night shift
    Rotating shift

    Netrix Global

    United States
    5 days ago
  •  ...IT Security Analyst II The IT Security Analyst II role is responsible for advanced monitoring, analysis, and mitigation of security alerts...  ..., ensuring efficiency and scalability across all security operations. Key Responsibilities Security monitoring Lead... 
    Contract work
    Casual work
    Work at office
    Afternoon shift

    FIT Technologies

    Cleveland, OH
    5 days ago
  • $95k - $101k

    Akima Data Management (ADM), an Akima company, is seeking Security Program Analyst II to provide program support to the Department of State...  ...assists, as needed, the Facility Protection Division and the Operational Support Division security programs. The SPA II works... 
    Full time
    Contract work
    Part time
    For contractors
    Work at office
    Local area
    Remote work
    Worldwide

    Akima Infrastructure Services

    Arlington, VA
    4 days ago
  •  ...following:TITLESecurity Compliance Analyst IILEVELMidRELATIONSHIPSAssigned Team...  ...Capital RegionPOSITION SUMMARYThe Security Compliance Analyst II will assist the assigned Government...  ...RESPONSIBILITIESCreates and develops Standard Operating Procedures, Policy, in support of... 
    For contractors
    Work at office
    Remote work

    H4 Enterprises

    Washington DC
    7 days ago
  • $90k - $120k

     ...military prime contractors such as Lockheed Martin, Northrop Grumman, and Raytheon.   POSITION SUMMARY: The Information Security Analyst II at the Marvin Group will be responsible for monitoring and protecting the organization from all vectors of cyber-attacks... 
    Permanent employment
    Contract work
    For contractors
    Work experience placement
    Work at office
    Flexible hours

    Marvin Group

    Inglewood, CA
    28 days ago
  •  ...Country USA State Ohio City Cincinnati Descriptions & requirements About the role:As a Senior Security Operations Center (SOC) Analyst at TQL, you'll help protect one of the nation's largest freight brokerage technology environments by leading the... 
    H1b

    Total Quality Logistics

    Cincinnati, OH
    4 days ago
  • $72.8k - $130k

     ...flexibility to telecommute* from anywhere within the U.S. as you take on some tough challenges.Position SummaryAs an AI Security Governance Operations Specialist within Optum Technology's Enterprise Information Security organization, you will play a critical role in the... 
    Minimum wage
    Full time
    Work experience placement
    Local area
    Remote work

    UnitedHealth Group

    Eden Prairie, MN
    1 day ago
  •  ...Security Operations Analyst (AI Training) About the Role We're partnering with leading AI research labs to build the next generation of intelligent security systems - and we need experienced SOC professionals to make it happen. Your hands-on knowledge of real-... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    Seattle, WA
    1 day ago
  •  ...Security Operations Analyst (AI Training) About the Role We're looking for experienced Security Operations Analysts to help evaluate and improve AI systems designed for modern SOC environments. Your real-world expertise in threat detection, alert triage, and incident... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    Chicago, IL
    1 day ago
  •  ...The SOC Analyst’s primary function is to provide comprehensive Computer Network Defense...  ...enterprise. This position will conduct security event monitoring, advanced analytics and...  ...endpoint threat detection tools, and security operations ticket management. This position will... 
    Remote work

    General Dynamics Information Technology

    Colorado Springs, CO
    1 day ago
  •  ...SOC Analyst The Security Operations Center (SOC) Analyst is responsible for operating and continuously enhancing Sun King's Security Operations Center. This role focuses on threat detection, threat hunting, incident response, digital forensics, and security automation... 
    Remote work

    Sun King

    United States
    2 days ago
  •  ...variety of industries. The company currently has 44,000 employees supporting its operations in 220 locations in 43 countries. The company is currently looking for an IT Security Operations Analyst, whowill be primarily responsible for the daily monitoring and response of IT... 
    Permanent employment
    Temporary work
    Remote work
    Weekend work

    Pacificacontinental

    Poland, NY
    3 days ago
  • $75.2k - $158.1k

     ...Security Operations Analyst Step into a mission-driven cybersecurity role where your work directly protects critical DoD systems. As part of a high-priority defense program, you'll operate a modern, fully integrated security stack—from Elastic Security and Palo Alto... 
    Contract work
    Work experience placement
    Interim role
    Remote work
    Flexible hours

    CACI International

    United States
    2 days ago
  •  ...Security Operations Analyst Zepto is building the beating heart of Australia's real-time, account-to-account payments revolution. We're a rapidly-scaling business reimagining how money moves for some of Australia's largest merchants, organisations and payment platforms... 
    Remote work
    Work from home
    Home office
    Flexible hours

    Zepto

    United States
    1 day ago
  • $65k - $75k

     ...Position Details Position Details Position Details Advertising/Posting Title Security Operations Analyst Posting Summary Conduct in-depth analyses of operational security data sourced from Endpoint Detection and Response (EDR), Intrusion Detection and Prevention Systems... 
    Full time
    Work at office
    Remote work
    Afternoon shift

    University of Vermont

    New York, NY
    4 days ago
  •  ...you to become a part of our family to help make our vision of Quenching the Thirst of Our Neighbors a reality! Summary The Security Operations Analyst helps protect ABARTA Coca-Cola Beverages’ information technology (IT) and operational technology (OT) environments... 
    Work at office
    Remote work
    Monday to Friday

    ABARTA Coca-Cola Beverages, LLC

    New York, NY
    5 days ago
  •  ...Security Operations Analyst (AI Training) About the Role We're partnering with the world's leading AI research labs to build the next generation of AI-powered security operations tools. As a Security Operations Analyst, you'll bring your real-world SOC experience... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    New York, NY
    1 day ago
  • $91.8k - $114.79k

     ...Position Title:Security Operations AnalystPosition Type:RegularHiring Range:$91,800 - $114,785 annually; Compensation will be based on education...  ...Pay Frequency:AnnualPOSITION PURPOSEThe Security Operations Analyst is focused on supporting and enhancing security capabilities... 
    Work at office
    Local area
    Remote work

    Santa Clara University

    Palo Alto, CA
    2 days ago
  •  ...can leave your mark. Title: Medicaid Senior IT Privacy and Security Analyst Role type: Contract Location: Remote Job...  ...Create and maintain System Security Plans. • Develop standard operating procedures, controls-related documentation, and other required... 
    Contract work
    Remote work

    3i People

    Lincoln, NE
    3 days ago
  •  ...RESPONSIBILITIES: Monitor, analyze, investigate, and report on security events, alerts, vulnerabilities, and risks across the...  ...Recommend and implement process improvements that enhance operational efficiency and reduce organizational risk. Participate in after... 
    Full time
    Work at office
    Weekend work
    Afternoon shift

    Aureon

    Remote
    9 hours ago
  •  ...Looking for an innovative organization and the opportunity to learn and grow professionally? We can help! We are seeking a IT Security Operations Analyst for the IT Technology Services contract. This project will provide IT service desk, systems, network, and security... 
    Full time
    Contract work
    Part time
    Work at office
    Remote work
    Monday to Friday

    Terrestris Global Solutions

    Washington DC
    more than 2 months ago
  • $800 per month

     ...Reports to: Senior Manager, Security Operations Center Location: Remote Australia What We Do: Cybercrime is growing, and more businesses...  ...up for each other. What You’ll Do: You’re a hands-on SOC Analyst who thrives on detecting and responding to cybercrime. You’ll... 
    Full time
    Summer work
    Local area
    Remote work
    Worldwide
    Home office

    Forgepoint Capital

    Australia
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Operations Analyst II. Be the first to apply!