Security Operations Analyst II
AlphaSense
ABOUT THE ROLE
We are hiring Security Operations Analyst II to join our Security Operations team in a fully remote capacity from Canada. This role sits at Tier 1–2 in our operating model — you are past the stage of learning what alerts look like and ready to own triage, perform structured investigations, and contribute to detection quality. You will handle the day-to-day alert queue, investigate escalated or ambiguous cases, handle incidents and work closely with senior analysts and the Security Operations Manager to close coverage gaps.
We expect you to think analytically, document thoroughly, and operate with growing independence. You will be supported by experienced colleagues and a mature toolset, but you are expected to bring real investigative instinct and a curiosity to grow to the role from day one.
WHAT YOU WILL DO
Alert Triage & Investigation
- Monitor and triage alerts across endpoint, network, cloud, runtime and identity data sources with accuracy and appropriate urgency
- Perform structured investigations on escalated or ambiguous alerts: pivot across log sources, correlate events, and build a coherent timeline
- Classify alerts correctly — true positive, false positive, or benign — with documented rationale, not just a verdict
- Identify scope and blast radius on confirmed incidents: affected users, systems, and data before escalating or containing
- Escalate to senior analysts with a complete investigation package — context, evidence, timeline, and a hypothesis
Incident Response Support
- Participate in active incident response under senior analyst or manager direction: evidence collection, log pulls, timeline reconstruction
- Execute containment actions — endpoint isolation, account suspension, token revocation — as directed with documented rationale
- Maintain accurate and timely case documentation throughout the incident lifecycle
- Contribute to post-incident timelines and assist with root cause documentation
Cloud & Identity Security Monitoring
- Monitor cloud audit logs and native threat detection findings for suspicious IAM activity, unusual API calls, and access anomalies
- Investigate identity provider events: suspicious logins, MFA bypass attempts, session anomalies, and unauthorized app assignments
- Recognize common cloud-native attack patterns: credential abuse via metadata service, privilege escalation via IAM role assumption, and storage misconfiguration access
- Correlate cloud-side events with endpoint and network telemetry to build a fuller picture of attacker activity
Detection & Quality Improvement
- Flag false positives and noisy detections with enough context for a senior analyst or detection engineer to tune them
- Identify gaps in existing detection coverage based on alert patterns you observe during triage
- Apply knowledge of MITRE ATT&CK to label attacker techniques and communicate findings consistently
- Contribute to runbook accuracy by flagging outdated steps or missing guidance encountered during investigations
- Participate with Detections Engineers to build detections and contribute to automating activity with an Engineering mindset
Documentation & Communication
- Write clear, concise case notes that a colleague could pick up mid-investigation without needing to re-investigate from scratch
- Produce shift handoff summaries that accurately represent open cases, pending actions, and investigation status
- Communicate incident updates to the Security Operations Manager with sufficient clarity to brief upward without re-investigation
WHAT WE ARE LOOKING FOR
Required
- 2–4+ years of hands-on experience in a SOC, or security operations role with direct alert triage responsibility
- Solid understanding of the MITRE ATT&CK framework — you use it to label and communicate attacker behavior, not just reference it
- Working knowledge of EDR tooling: process tree analysis, behavioral detection review, and basic endpoint artifact interpretation
- Familiarity with SIEM-based investigation: querying logs, correlating events across sources, and building timelines from normalized data
- Understanding of foundational network protocols ( TCP/IP, DNS, TLS ) and how attackers abuse them
- Exposure to cloud security monitoring ex. AWS or GCP — including audit log review and IAM-related alert investigation
- Experience investigating identity-based alerts in an enterprise identity provider (e.g., Okta, Entra ID , or equivalent)
- Strong written communication: your case notes are accurate, structured, and useful to someone who wasn’t there
Preferred
- Experience with next-gen EDR platforms (e.g., CrowdStrike Falcon, SentinelOne , or equivalent) beyond basic alert review — RTR, process trees, custom detections
- Hands-on SIEM experience with a cloud-native platform (e.g., Google SecOps/Chronicle, Microsoft Sentinel , or equivalent)
- Exposure to CSPM or cloud security tooling (e.g., Wiz, Prisma Cloud , or equivalent) as an investigation data source
- Familiarity with AWS IR fundamentals : CloudTrail, GuardDuty, VPC Flow Logs, IAM chain analysis
- Understanding of encoding vs. encryption vs. hashing and their relevance to attacker obfuscation techniques
- Experience working alongside or receiving escalations from a managed detection and response (MDR) partner
- Relevant certifications: CompTIA CySA+, Security+, BTL1, GCIH , or equivalent practical security credential
- OverviewSecurity Operations Center Analyst II - Orlando, Florida Company Overview Statement:Working across the globe, V2X builds smart solutions... ...bring 120 years of successful mission support to improve security, streamline logistics, and enhance readiness. Aligned around...SuggestedRemote work
- ...SOC AnalystSOC Analyst's primary function is to provide comprehensive Computer Network... ...enterprise. This position will conduct security event monitoring, advanced analytics and... ...endpoint threat detection tools, and security operations ticket management. This position will...SuggestedWork at officeRemote work
$97.59k - $142.99k
...Summary:We have an exciting opportunity to join our team as a Sr. II Security Analyst - Vulnerabilities. In this role, the successful analyst will... ...vulnerabilitiesWork with stakeholders to harden equipment, operating systems and applicationsUsing Checkmarx, work with...SuggestedFull time- ...Distinction, Experience and Achievement.We are seeking a Security Cooperation & FMS Analyst (Logistics Analyst II) to support the Logistics and Program Management... ...Security Cooperation Agencys (DSCA) International Operations Global Execution Division (OPS/GEX). This office...SuggestedFor contractorsRemote workFlexible hours2 days per week3 days per week
- ...IT Security Analyst IIThe IT Security Analyst II role is responsible for advanced monitoring, analysis, and mitigation of security alerts and incidents... ...ensuring efficiency and scalability across all security operations.Key ResponsibilitiesSecurity monitoringLead the...SuggestedContract workCasual workWork at officeAfternoon shift
- ...for advancement Training & development POSITION SUMMARY – Security Analyst II (Compliance) Under the general supervision of the GRC Manager... ...to other IT staff and non‑IT areas on how to align IT operational and technology processes based on information technology risk...Work at officeRemote workWork from homeRelocationFlexible hours
$95k - $101k
Akima Data Management (ADM), an Akima company, is seeking Security Program Analyst II to provide program support to the Department of State... ...assists, as needed, the Facility Protection Division and the Operational Support Division security programs. The SPA II works...Full timeContract workPart timeFor contractorsWork at officeLocal areaRemote workWorldwide$72k
Information Security II, BU Info, Security Job Description Category Professional Job Location Boston, MA, United States Tracking Code... ...protection software, firewalls. Knowledge of network protocols, operating systems, and security technologies. Familiarity with...Full timeFor contractorsWork at office$36 per hour
...with your recruiter to learn more. Base pay range $36.00/hr - $36.00/hr Direct message the job poster from TekWissen Title: IT Security Analyst II Work Location: Detroit, MI, 48226 Duration: 9 Months Job Type: Contract Work Type: Remote Overview : TekWissen is a global...Contract workWork experience placementRemote work- ...services provider. We provide 24/7 security monitoring, investigation,... ...AI. Information Security Analysts The Information Security... ...core of our SOC-as-a-Service operations. They are on the front line receiving... .... Position level is I or II: Information Security...Remote work
$90k - $120k
...military prime contractors such as Lockheed Martin, Northrop Grumman, and Raytheon. POSITION SUMMARY: The Information Security Analyst II at the Marvin Group will be responsible for monitoring and protecting the organization from all vectors of cyber-attacks...Permanent employmentContract workFor contractorsWork experience placementWork at officeFlexible hours- ...: Information Security Analyst II - 6188 US:OR:Salem | Information Services | Full Time Posted 3 weeks ago Apply Save Description ***(Candidates who are selected and will work outside of the state of Oregon will be hired through an employer of record)*** Location...Full timeTemporary workWork experience placementRemote workRelocation package
- H4 Enterprises, LLC in the National Capital Region seeks a Security Compliance Analyst II. You will assist the Government Division Chief and the assigned team leader with IT security duties guiding the Department of State's classified systems through security mandates...Remote work
- ...Country USA State Ohio City Cincinnati Descriptions & requirements About the role:As a Senior Security Operations Center (SOC) Analyst at TQL, you'll help protect one of the nation's largest freight brokerage technology environments by leading the...H1b
$72.8k - $130k
...flexibility to telecommute* from anywhere within the U.S. as you take on some tough challenges.Position SummaryAs an AI Security Governance Operations Specialist within Optum Technology's Enterprise Information Security organization, you will play a critical role in the...Minimum wageFull timeWork experience placementLocal areaRemote work- ...the current range is: Grade: Technical 407Pay Range: $108,200.00 - $162,400.00Job DescriptionAbout the Team You’ll collaborate on security-focused tools and services while helping shape security documentation and standards. As an Application Security Engineer, you will...Full timeWork at officeFlexible hours
$62k - $68k
...Security Operations Center AnalystCEVA Logistics provides global supply chain solutions to connect people, products, and providers all around... ...$68,000Your RoleThe Global Security Operation Center (GSOC) Analyst plays a vital role within CEVA's 24/7/365 Global Security...Contract workRemote work- ...Philadelphia, PA Hours: 8hr Days Summary: Working under limited supervision, the Senior Information Security Analyst is responsible for ensuring that key security operations tasks are completed. Security Operations involves end user security service escalation, security...Remote work
$65k - $75k
...protected by federal or state law. For information on safety and security at the University of Vermont, see the annual security report... ...’s experience level and length. Conduct in-depth analyses of operational security data sourced from Endpoint Detection and Response ( EDR...Full timeWork at officeRemote workAfternoon shift$91.8k - $114.79k
...Position Title: Security Operations Analyst Position Type: Regular Hiring Range: $91,800 - $114,785 annually; Compensation will be based on education, experience, skills relevant to the role, and internal equity. Pay Frequency: Annual POSITION PURPOSE The Security Operations...Work at officeLocal areaRemote work- ...Security Operations Analyst We are looking for an experienced Security Operations Analyst to join a long-term cybersecurity programme supporting critical enterprise and government-facing environments. This is an excellent opportunity for a security professional with...Remote work
- ...Security Operations Center (SOC) Analyst Duration: 6 months Location: Houston, TX Schedule: Monday - Friday: 7am - 4pm Role Summary The SOC Analyst is responsible for monitoring, investigating, documenting, and coordinating response to cybersecurity events across enterprise...For contractorsWork at officeRemote workMonday to FridayShift work
$70k - $90k
...position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Operations Analyst based in the United States. This is a remote-first opportunity for a security professional focused on protecting...Remote workWork from homeFlexible hours$30 - $60 per hour
...Security Operations Analyst $30-60/hr Remote Freelance CODING About the Role We're partnering with leading AI research labs to build the next generation of AI systems that reason through real-world security incidents. As a Security Operations Analyst, your hands...Ongoing contractFreelanceRemote workFlexible hours- ...As an analytical and thorough individual contributor, the full-time remote Security Operations Analyst will manage threat detection and response, technical security architecture, and SIEM and SOAR engineering to protect critical assets against evolving threats. Key responsibilities...Full timeRemote work
- ...variety of industries. The company currently has 44,000 employees supporting its operations in 220 locations in 43 countries. The company is currently looking for an IT Security Operations Analyst, whowill be primarily responsible for the daily monitoring and response of IT...Permanent employmentTemporary workRemote workWeekend work
$69.4k - $158k
...Job Number: R0246874 Security Operations Center Analyst The Opportunity: Are you ready to take a strategic role in cyber defense for U.S Cyber Command? Do you want to use your experience-based knowledge to protect critical warfighter infrastructure from the constant onslaught...Full timeContract workPart timeWork at officeLocal areaRemote work- ...Looking for an innovative organization and the opportunity to learn and grow professionally? We can help! We are seeking a IT Security Operations Analyst for the IT Technology Services contract. This project will provide IT service desk, systems, network, and security...Full timeContract workPart timeWork at officeRemote workMonday to Friday
- ...SOC Analyst About the Role The SOC Analyst is responsible for monitoring, detecting, analyzing, and responding to cybersecurity events and incidents. This role is critical to the Security Operations Center's mission to protect client environments by identifying threats...Local areaRemote work
- ...Description Job description: Unarmed Security Officer w/ 2 Weeks PTO! Paid training to be an SOC Analyst for a critical infrastructure for a Fortune 500... ...security procedures based on evolving threats and operational needs Communication & Compliance Escalate...Weekly payFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Operations Analyst II. Be the first to apply!


