Remote job
Security Analyst II: Gaurdian
Job details
About this role
Role overview A Security Analyst II role on a security operations team responsible for monitoring, investigating, and responding to security events across customer environments. The position supports incident response, threat detection, and continuous tuning of detection and response processes within a managed security services context. It suits an analytically minded analyst with SOC experience who enjoys collaborative, complex problem-solving.
Responsibilities - Monitor security alerts and events across the platform and customer environments, driving effective customer outcomes. - Analyze, investigate, and respond to security events, performing initial triage to determine severity, scope, and potential impact. - Investigate suspicious activity across endpoints, networks, identity systems, cloud environments, and security technologies. - Escalate confirmed or high-risk incidents to incident response or senior security resources and assist with containment and remediation. - Review logs, telemetry, and other data sources to identify malicious or abnormal behavior and document findings, actions, and customer communications. - Identify and recommend improvements to detection capabilities, operational processes, automation, and overall platform effectiveness. - Collaborate with teams across Managed Detection and Response, Threat Hunting, Incident Response, Engineering, and Customer Success.
Requirements - Experience working in a Security Operations Center (SOC), Managed Security Service Provider (MSSP), or Managed Detection and Response (MDR) environment. - Hands-on experience with SIEM and log management platforms such as Splunk, Elastic Stack, Microsoft Sentinel, or Google Security Operations. - Experience with Endpoint Detection and Response tools such as CrowdStrike, Microsoft Defender, or SentinelOne. - Experience with cloud platforms including AWS, Microsoft Azure, and Google Cloud Platform, plus familiarity supporting Microsoft 365, Entra ID, or Proofpoint. - Scripting or development experience with Python, PowerShell, JavaScript, or similar, plus familiarity with SOAR platforms such as Cortex XSOAR or Splunk SOAR. - Understanding of the MITRE ATT&CK framework and common adversary behaviors; familiarity with incident response, threat hunting, digital forensics, or malware analysis is beneficial.
Nice to have - Relevant cybersecurity certifications. - Advanced system administration experience with Windows PowerShell, Ansible, SaltStack, Chef, Puppet, or comparable tooling.
Benefits and work setup - Published salary range of $68,000 to $75,000 USD per year for this full-time position.