Security Operations Center Analyst

Pest
IT and Telecommunication
Remote 3-5 Years Of Professional Experience
Short Description

We are looking for an experienced SOC Level 2 Analyst to join a high-performing Security Operations Centre, where you'll play a key role in investigating complex security incidents and strengthening detection and response capabilities. Acting as the bridge between frontline analysts and senior threat hunters, you'll take ownership of escalated cases from initial investigation through containment and resolution.Working primarily with the SentinelOne Singularity Platform, you'll perform in-depth threat analysis, improve detection logic, develop operational playbooks and help automate security processes to continuously enhance SOC efficiency.

Description

  • Investigate and validate security incidents escalated by Level 1 analysts, distinguishing genuine threats from false positives using SentinelOne telemetry and endpoint data
  • Assess the severity of incidents by considering asset criticality, user identity and potential business impact, ensuring appropriate prioritisation and timely response
  • Conduct detailed forensic investigations to identify attack vectors, root causes and attacker behaviour across endpoint, identity and network data
  • Document investigations with clear technical finding, indicators of compromise (IOCs)v and MITRE ATT&CK mappings
  • Perform containment and remediation activities, including endpoint isolation, malicious process termination and recovery actions where appropriate
  • Work closely with IT teams to coordinate remediation efforts and escalate major incidents to senior incident response teams when required
  • Support the continuous improvement of detection capabilities by recommending tuning changes, refining detection rules and reducing false positives
  • Collaborate with detection engineering teams to implement new threat intelligence into behavioural detections and custom security rules
  • Develop and maintain SOC playbooks, investigation procedures and automated response workflows to improve consistency and reduce response times
  • Contribute to internal knowledge sharing by producing documentation and supporting the onboarding of new SOC team members

Requirements

  • Minimum 3 years of experience in a Security Operations Centre, including previous responsibility for handling escalated (Level 2) security incidents
  • Practical experience working with the SentinelOne Singularity Platform, including Deep Visibility, Storyline, RemoteOps and endpoint investigation
  • Strong understanding of Windows, Linux and macOS operating systems, endpoint attack techniques and the MITRE ATT&CK framework
  • Experience working with SIEM solutions, security logs and incident/case management platforms
  • Excellent analytical, investigative and problem-solving skills
  • Strong written communication skills with the ability to produce clear incident reports and technical documentation
Nice to Have:
  • SentinelOne certification or other relevant endpoint security certifications
  • Experience with SOAR platforms such as Palo Alto XSOAR, Tines or Swimlane
  • Familiarity with identify-based investigations and behavioural analytical platforms
  • Industry certification including GCIH, GCIA, CySA+, Security+ or similar
  • Previous experience working within an MSSP or MDR environment supporting multiple customers

Your next job is out there.
We'll help you find it.

Join our database and get contacted when suitable opportunities open.

Join our database
Security Operations Center Analyst
Job Application
Allowed extensions: doc, docx, pdf, txt. Maximum file size: 50MB.
Are You Willing to Relocate?
CAPTCHA
Enter the characters shown in the image.
This question is for testing whether or not you are a human visitor and to prevent automated spam submissions.
loading-gif