Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Operations Analyst II

Full-time

AlphaSense

ABOUT THE ROLE

We are hiring Security Operations Analyst II to join our Security Operations team in a fully remote capacity from Canada. This role sits at Tier 1–2 in our operating model — you are past the stage of learning what alerts look like and ready to own triage, perform structured investigations, and contribute to detection quality. You will handle the day-to-day alert queue, investigate escalated or ambiguous cases, handle incidents and work closely with senior analysts and the Security Operations Manager to close coverage gaps.

We expect you to think analytically, document thoroughly, and operate with growing independence. You will be supported by experienced colleagues and a mature toolset, but you are expected to bring real investigative instinct and a curiosity to grow to the role from day one.

WHAT YOU WILL DO

Alert Triage & Investigation

  • Monitor and triage alerts across endpoint, network, cloud, runtime and identity data sources with accuracy and appropriate urgency
  • Perform structured investigations on escalated or ambiguous alerts: pivot across log sources, correlate events, and build a coherent timeline
  • Classify alerts correctly — true positive, false positive, or benign — with documented rationale, not just a verdict
  • Identify scope and blast radius on confirmed incidents: affected users, systems, and data before escalating or containing
  • Escalate to senior analysts with a complete investigation package — context, evidence, timeline, and a hypothesis

Incident Response Support

  • Participate in active incident response under senior analyst or manager direction: evidence collection, log pulls, timeline reconstruction
  • Execute containment actions — endpoint isolation, account suspension, token revocation — as directed with documented rationale
  • Maintain accurate and timely case documentation throughout the incident lifecycle
  • Contribute to post-incident timelines and assist with root cause documentation

Cloud & Identity Security Monitoring

  • Monitor cloud audit logs and native threat detection findings for suspicious IAM activity, unusual API calls, and access anomalies
  • Investigate identity provider events: suspicious logins, MFA bypass attempts, session anomalies, and unauthorized app assignments
  • Recognize common cloud-native attack patterns: credential abuse via metadata service, privilege escalation via IAM role assumption, and storage misconfiguration access
  • Correlate cloud-side events with endpoint and network telemetry to build a fuller picture of attacker activity

Detection & Quality Improvement

  • Flag false positives and noisy detections with enough context for a senior analyst or detection engineer to tune them
  • Identify gaps in existing detection coverage based on alert patterns you observe during triage
  • Apply knowledge of MITRE ATT&CK to label attacker techniques and communicate findings consistently
  • Contribute to runbook accuracy by flagging outdated steps or missing guidance encountered during investigations
  • Participate with Detections Engineers to build detections and contribute to automating activity with an Engineering mindset

Documentation & Communication

  • Write clear, concise case notes that a colleague could pick up mid-investigation without needing to re-investigate from scratch
  • Produce shift handoff summaries that accurately represent open cases, pending actions, and investigation status
  • Communicate incident updates to the Security Operations Manager with sufficient clarity to brief upward without re-investigation

WHAT WE ARE LOOKING FOR

Required

  • 2–4+ years of hands-on experience in a SOC, or security operations role with direct alert triage responsibility
  • Solid understanding of the MITRE ATT&CK framework — you use it to label and communicate attacker behavior, not just reference it
  • Working knowledge of EDR tooling: process tree analysis, behavioral detection review, and basic endpoint artifact interpretation
  • Familiarity with SIEM-based investigation: querying logs, correlating events across sources, and building timelines from normalized data
  • Understanding of foundational network protocols ( TCP/IP, DNS, TLS ) and how attackers abuse them
  • Exposure to cloud security monitoring ex. AWS or GCP — including audit log review and IAM-related alert investigation
  • Experience investigating identity-based alerts in an enterprise identity provider (e.g., Okta, Entra ID , or equivalent)
  • Strong written communication: your case notes are accurate, structured, and useful to someone who wasn’t there

Preferred

  • Experience with next-gen EDR platforms (e.g., CrowdStrike Falcon, SentinelOne , or equivalent) beyond basic alert review — RTR, process trees, custom detections
  • Hands-on SIEM experience with a cloud-native platform (e.g., Google SecOps/Chronicle, Microsoft Sentinel , or equivalent)
  • Exposure to CSPM or cloud security tooling (e.g., Wiz, Prisma Cloud , or equivalent) as an investigation data source
  • Familiarity with AWS IR fundamentals : CloudTrail, GuardDuty, VPC Flow Logs, IAM chain analysis
  • Understanding of encoding vs. encryption vs. hashing and their relevance to attacker obfuscation techniques
  • Experience working alongside or receiving escalations from a managed detection and response (MDR) partner
  • Relevant certifications: CompTIA CySA+, Security+, BTL1, GCIH , or equivalent practical security credential
Vacancy posted 10 days ago
Similar jobs that could be interesting for youBased on the Security Operations Analyst II in Remote vacancy
  • OverviewSecurity Operations Center Analyst II - Orlando, Florida Company Overview Statement:Working across the globe, V2X builds smart solutions...  ...bring 120 years of successful mission support to improve security, streamline logistics, and enhance readiness. Aligned around... 
    Suggested
    Remote work

    V2X

    Orlando, FL
    2 days ago
  •  ...SOC AnalystSOC Analyst's primary function is to provide comprehensive Computer Network...  ...enterprise. This position will conduct security event monitoring, advanced analytics and...  ...endpoint threat detection tools, and security operations ticket management. This position will... 
    Suggested
    Work at office
    Remote work

    General Dynamics

    Colorado Springs, CO
    19 hours ago
  • $97.59k - $142.99k

     ...Summary:We have an exciting opportunity to join our team as a Sr. II Security Analyst - Vulnerabilities. In this role, the successful analyst will...  ...vulnerabilitiesWork with stakeholders to harden equipment, operating systems and applicationsUsing Checkmarx, work with... 
    Suggested
    Full time

    NYU Langone Medical Center

    New York, NY
    2 days ago
  •  ...Distinction, Experience and Achievement.We are seeking a Security Cooperation & FMS Analyst (Logistics Analyst II) to support the Logistics and Program Management...  ...Security Cooperation Agencys (DSCA) International Operations Global Execution Division (OPS/GEX). This office... 
    Suggested
    For contractors
    Remote work
    Flexible hours
    2 days per week
    3 days per week

    Advanced Decision Vectors

    Arlington, VA
    2 days ago
  •  ...IT Security Analyst IIThe IT Security Analyst II role is responsible for advanced monitoring, analysis, and mitigation of security alerts and incidents...  ...ensuring efficiency and scalability across all security operations.Key ResponsibilitiesSecurity monitoringLead the... 
    Suggested
    Contract work
    Casual work
    Work at office
    Afternoon shift

    FIT Technologies

    Cleveland, OH
    1 day ago
  •  ...for advancement Training & development POSITION SUMMARY – Security Analyst II (Compliance) Under the general supervision of the GRC Manager...  ...to other IT staff and non‑IT areas on how to align IT operational and technology processes based on information technology risk... 
    Work at office
    Remote work
    Work from home
    Relocation
    Flexible hours

    Technoviz

    Madison, WI
    3 days ago
  • $95k - $101k

    Akima Data Management (ADM), an Akima company, is seeking Security Program Analyst II to provide program support to the Department of State...  ...assists, as needed, the Facility Protection Division and the Operational Support Division security programs. The SPA II works... 
    Full time
    Contract work
    Part time
    For contractors
    Work at office
    Local area
    Remote work
    Worldwide

    Akima

    Arlington, VA
    2 days ago
  • $72k

    Information Security II, BU Info, Security Job Description Category Professional Job Location Boston, MA, United States Tracking Code...  ...protection software, firewalls. Knowledge of network protocols, operating systems, and security technologies. Familiarity with... 
    Full time
    For contractors
    Work at office

    Boston University

    Boston, MA
    2 days ago
  • $36 per hour

     ...with your recruiter to learn more. Base pay range $36.00/hr - $36.00/hr Direct message the job poster from TekWissen Title: IT Security Analyst II Work Location: Detroit, MI, 48226 Duration: 9 Months Job Type: Contract Work Type: Remote Overview : TekWissen is a global... 
    Contract work
    Work experience placement
    Remote work

    Tekwissen

    Detroit, MI
    2 days ago
  •  ...services provider. We provide 24/7 security monitoring, investigation,...  ...AI. Information Security Analysts The Information Security...  ...core of our SOC-as-a-Service operations. They are on the front line receiving...  .... Position level is I or II: Information Security... 
    Remote work

    Proficio Inc

    United States
    3 hours ago
  • $90k - $120k

     ...military prime contractors such as Lockheed Martin, Northrop Grumman, and Raytheon.   POSITION SUMMARY: The Information Security Analyst II at the Marvin Group will be responsible for monitoring and protecting the organization from all vectors of cyber-attacks... 
    Permanent employment
    Contract work
    For contractors
    Work experience placement
    Work at office
    Flexible hours

    Marvin Group

    Inglewood, CA
    24 days ago
  •  ...: Information Security Analyst II - 6188 US:OR:Salem | Information Services | Full Time Posted 3 weeks ago Apply Save Description ***(Candidates who are selected and will work outside of the state of Oregon will be hired through an employer of record)*** Location... 
    Full time
    Temporary work
    Work experience placement
    Remote work
    Relocation package

    Salem Health Hospitals & Clinics

    Salem, OR
    8 days ago
  • H4 Enterprises, LLC in the National Capital Region seeks a Security Compliance Analyst II. You will assist the Government Division Chief and the assigned team leader with IT security duties guiding the Department of State's classified systems through security mandates... 
    Remote work

    H4 Enterprises LLC

    Washington DC
    2 days ago
  •  ...Country USA State Ohio City Cincinnati Descriptions & requirements About the role:As a Senior Security Operations Center (SOC) Analyst at TQL, you'll help protect one of the nation's largest freight brokerage technology environments by leading the... 
    H1b

    Total Quality Logistics

    Cincinnati, OH
    19 hours ago
  • $72.8k - $130k

     ...flexibility to telecommute* from anywhere within the U.S. as you take on some tough challenges.Position SummaryAs an AI Security Governance Operations Specialist within Optum Technology's Enterprise Information Security organization, you will play a critical role in the... 
    Minimum wage
    Full time
    Work experience placement
    Local area
    Remote work

    UnitedHealth Group

    Eden Prairie, MN
    2 days ago
  •  ...the current range is: Grade: Technical 407Pay Range: $108,200.00 - $162,400.00Job DescriptionAbout the Team You’ll collaborate on security-focused tools and services while helping shape security documentation and standards. As an Application Security Engineer, you will... 
    Full time
    Work at office
    Flexible hours

    Western Governors University

    Salt Lake City, UT
    2 days ago
  • $62k - $68k

     ...Security Operations Center AnalystCEVA Logistics provides global supply chain solutions to connect people, products, and providers all around...  ...$68,000Your RoleThe Global Security Operation Center (GSOC) Analyst plays a vital role within CEVA's 24/7/365 Global Security... 
    Contract work
    Remote work

    CMA CGM

    Houston, TX
    2 days ago
  •  ...Philadelphia, PA Hours: 8hr Days Summary: Working under limited supervision, the Senior Information Security Analyst is responsible for ensuring that key security operations tasks are completed. Security Operations involves end user security service escalation, security... 
    Remote work

    Pennsylvania Medicine

    Philadelphia, PA
    2 days ago
  • $65k - $75k

     ...protected by federal or state law. For information on safety and security at the University of Vermont, see the annual security report...  ...’s experience level and length. Conduct in-depth analyses of operational security data sourced from Endpoint Detection and Response ( EDR... 
    Full time
    Work at office
    Remote work
    Afternoon shift

    The University of Vermont

    Wisconsin
    3 days ago
  • $91.8k - $114.79k

     ...Position Title: Security Operations Analyst Position Type: Regular Hiring Range: $91,800 - $114,785 annually; Compensation will be based on education, experience, skills relevant to the role, and internal equity. Pay Frequency: Annual POSITION PURPOSE The Security Operations... 
    Work at office
    Local area
    Remote work

    Santa Clara University

    Santa Clara, CA
    1 day ago
  •  ...Security Operations Analyst We are looking for an experienced Security Operations Analyst to join a long-term cybersecurity programme supporting critical enterprise and government-facing environments. This is an excellent opportunity for a security professional with... 
    Remote work

    Matchtech

    United States
    4 days ago
  •  ...Security Operations Center (SOC) Analyst Duration: 6 months Location: Houston, TX Schedule: Monday - Friday: 7am - 4pm Role Summary The SOC Analyst is responsible for monitoring, investigating, documenting, and coordinating response to cybersecurity events across enterprise... 
    For contractors
    Work at office
    Remote work
    Monday to Friday
    Shift work

    Airswift

    Houston, TX
    3 days ago
  • $70k - $90k

     ...position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Operations Analyst based in the United States. This is a remote-first opportunity for a security professional focused on protecting... 
    Remote work
    Work from home
    Flexible hours

    Jobgether

    New York, NY
    4 days ago
  • $30 - $60 per hour

     ...Security Operations Analyst $30-60/hr Remote Freelance CODING About the Role We're partnering with leading AI research labs to build the next generation of AI systems that reason through real-world security incidents. As a Security Operations Analyst, your hands... 
    Ongoing contract
    Freelance
    Remote work
    Flexible hours

    Alignerr

    United States
    1 day ago
  •  ...As an analytical and thorough individual contributor, the full-time remote Security Operations Analyst will manage threat detection and response, technical security architecture, and SIEM and SOAR engineering to protect critical assets against evolving threats. Key responsibilities... 
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    2 days ago
  •  ...variety of industries. The company currently has 44,000 employees supporting its operations in 220 locations in 43 countries. The company is currently looking for an IT Security Operations Analyst, whowill be primarily responsible for the daily monitoring and response of IT... 
    Permanent employment
    Temporary work
    Remote work
    Weekend work

    Pacificacontinental

    Poland, NY
    4 days ago
  • $69.4k - $158k

     ...Job Number: R0246874 Security Operations Center Analyst The Opportunity: Are you ready to take a strategic role in cyber defense for U.S Cyber Command? Do you want to use your experience-based knowledge to protect critical warfighter infrastructure from the constant onslaught... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Phase2 Technology

    Columbia, MD
    3 days ago
  •  ...Looking for an innovative organization and the opportunity to learn and grow professionally? We can help! We are seeking a IT Security Operations Analyst for the IT Technology Services contract. This project will provide IT service desk, systems, network, and security... 
    Full time
    Contract work
    Part time
    Work at office
    Remote work
    Monday to Friday

    Terrestris Global Solutions

    Washington DC
    4 days ago
  •  ...SOC Analyst About the Role The SOC Analyst is responsible for monitoring, detecting, analyzing, and responding to cybersecurity events and incidents. This role is critical to the Security Operations Center's mission to protect client environments by identifying threats... 
    Local area
    Remote work

    Trace3

    Fargo, ND
    3 days ago
  •  ...Description Job description: Unarmed Security Officer w/ 2 Weeks PTO! Paid training to be an SOC Analyst for a critical infrastructure for a Fortune 500...  ...security procedures based on evolving threats and operational needs Communication & Compliance Escalate... 
    Weekly pay
    Flexible hours

    Metro One LPSG

    Fort Wayne, IN
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Operations Analyst II. Be the first to apply!