Tier 2 SOC Analyst
Careerscape is recruiting on behalf of our client, a managed IT services company based in Atlanta, GA, for a Tier 2 SOC Analyst to join their around-the-clock security operations team. This is a chance to work at the front line of threat detection and response, protecting a diverse portfolio of client environments while working alongside a tight-knit, experienced security team that takes pride in catching what others miss.
About the role
Day to day, you will triage escalations from Tier 1 analysts, dig into alerts across SIEM and EDR platforms, and decide fast whether something is noise or a real incident in progress. The role suits someone who is calm under pressure, genuinely curious about attacker behavior, and comfortable owning an investigation from first alert through containment and documentation. If you like the adrenaline of active incident response paired with the structure of a mature SOC, this is a strong fit.
Responsibilities
- Monitor and triage security alerts escalated from Tier 1 analysts across multiple client environments
- Investigate potential security incidents using SIEM, EDR, and network monitoring tools
- Perform in-depth analysis of logs, network traffic, and endpoint data to determine scope and impact
- Lead initial incident response activities including containment and remediation guidance
- Document findings, timelines, and response actions in detailed incident reports
- Tune detection rules and alert thresholds to reduce false positives and improve fidelity
- Collaborate with Tier 3 analysts and engineering teams on complex or recurring threats
- Track emerging threats and vulnerabilities relevant to client industries
- Participate in an on-call rotation supporting 24x7 SOC coverage
- Mentor Tier 1 analysts on triage and investigation best practices
Requirements
- 2 to 4 years of experience in a security operations center or similar security monitoring role
- Hands-on experience with SIEM platforms such as Splunk, QRadar, or Microsoft Sentinel
- Solid understanding of network protocols, endpoint security, and common attack techniques
- Experience with EDR tools and log analysis across Windows and Linux environments
- Familiarity with the MITRE ATT&CK framework and incident response methodologies
- Strong written communication skills for incident documentation and client-facing reporting
- Ability to work rotating shifts to support round-the-clock monitoring coverage
- Security certification such as Security Plus, CySA Plus, or GCIH preferred
- Bachelor's degree in a related field or equivalent practical experience
Benefits
- Medical, dental, and vision insurance
- 401k with company match
- Paid time off and paid holidays
- Fully remote position with flexible scheduling within shift requirements
- Home office equipment and technology stipend
- Shift differential pay for nights and weekends
- Professional certification reimbursement
- Parental leave
- Employee assistance program
- Ongoing security training and career development support
Pay
The salary range for this role is $70,000 - $88,000 per year, based on experience and qualifications.