Jobs · Information Technology · California

Security Analyst II (SOC)

Robert Half · Los Angeles, CA · 2 wk ago
On-siteInformation TechnologyTemporary

We are looking for a Security Analyst II (SOC) to join a security operations team in Los Angeles, California as part of a long-term contract engagement.

About the role

This role focuses on monitoring security activity, investigating alerts, and helping drive incident response efforts in a fast-paced environment. The ideal candidate brings hands-on experience in security operations, sound investigative judgment, and the ability to work closely with technical teams to strengthen detection and response capabilities.

Responsibilities

  • Evaluate a high daily volume of security alerts and determine whether events represent genuine threats, routine activity, or inaccurate detections.
  • Triage security events, prioritize risk, and escalate advanced or high-impact issues to Security Engineers when deeper analysis is required.
  • Contribute to incident response activities from initial identification through containment, documentation, and follow-up review.
  • Refine and enhance detection logic to improve visibility, strengthen coverage, and reduce unnecessary alert noise.
  • Investigate suspicious behavior related to data loss, insider risk, and other security concerns surfaced through monitoring tools.
  • Apply threat intelligence by reviewing indicators of compromise and conducting targeted searches across available telemetry sources.
  • Collaborate with IT, platform, and engineering partners to remediate vulnerabilities and address gaps identified during investigations.
  • Support hybrid team operations with onsite participation Tuesday through Thursday as needed.

Requirements

  • 2–4+ years of experience in security analysis, security operations, or detection and response functions.
  • Background working in a Level 1 or Level 2 SOC environment with hands-on alert triage and investigation responsibilities.
  • Understanding of networking concepts, security event logs, SIEM workflows, and incident response practices.
  • Ability to analyze activity patterns and distinguish legitimate business behavior from potentially malicious actions.
  • Strong analytical mindset, investigative problem-solving skills, and a proactive approach to technical learning.
  • Experience with cybersecurity tools and concepts such as DLP, Okta, SIEM platforms, application security, and cyber security policies.
  • Familiarity with tools or platforms such as SentinelOne, CrowdStrike, AWS Security Hub, or similar security technologies is preferred.
  • Relevant security knowledge supported by certifications such as CompTIA Security+ or equivalent practical experience is a plus.

Schedule

Hybrid role requiring onsite participation Tuesday through Thursday as needed.

Benefits

  • Medical, vision, dental, and life and disability insurance.
  • Eligibility to enroll in the company 401(k) plan.

Similar jobs