Security Operations Analyst II

1 day, 5 hours ago
Mid Level
Cybersecurity
Alphasense

Alphasense

Alphasense is a global leader in providing high-quality gas sensors and air quality monitors to industrial OEMs. With over 25 years of experience, the company offers a wide range of innovative gas sensor technologies for various applications, including...

Industrial Conglomerates
51-250
Founded 1996

Description

  • Monitor and triage alerts across endpoint, network, cloud, runtime, and identity data sources.
  • Perform structured investigations on escalated or ambiguous alerts and build clear event timelines.
  • Classify alerts as true positive, false positive, or benign with documented rationale.
  • Identify incident scope and blast radius before escalation or containment.
  • Escalate cases with complete investigation packages including context, evidence, timelines, and hypotheses.
  • Support active incident response through evidence collection, log pulls, and timeline reconstruction.
  • Execute containment actions such as endpoint isolation, account suspension, and token revocation as directed.
  • Maintain accurate case documentation, shift handoffs, and incident status updates.
  • Monitor cloud audit logs and identity provider events for suspicious activity and access anomalies.
  • Flag false positives, detection gaps, and outdated runbook steps to improve security operations quality.

Requirements

  • 2–4+ years of hands-on experience in a SOC or security operations role with direct alert triage responsibility.
  • Strong understanding of the MITRE ATT&CK framework.
  • Working knowledge of EDR tooling, including process tree analysis and endpoint artifact interpretation.
  • Familiarity with SIEM-based investigations, including querying logs and building timelines.
  • Understanding of foundational network protocols such as TCP/IP, DNS, HTTP/S, and TLS.
  • Exposure to cloud security monitoring such as AWS or GCP, including audit log review and IAM-related investigations.
  • Experience investigating identity-based alerts in an enterprise identity provider such as Okta or Entra ID.
  • Strong written communication and case documentation skills.
  • Experience with next-gen EDR platforms such as CrowdStrike Falcon or SentinelOne is preferred.
  • Hands-on SIEM experience with a cloud-native platform such as Google SecOps/Chronicle or Microsoft Sentinel is preferred.
  • Exposure to CSPM or cloud security tooling such as Wiz or Prisma Cloud is preferred.
  • Familiarity with AWS IR fundamentals, including CloudTrail, GuardDuty, VPC Flow Logs, and IAM chain analysis is preferred.
  • Understanding of encoding, encryption, and hashing is preferred.
  • Experience working with or receiving escalations from an MDR partner is preferred.
  • Relevant certifications such as CompTIA CySA+, Security+, BTL1, or GCIH are preferred.

Benefits

  • Fully remote role within Canada.
  • Must be able to work in the Pacific time zone.
  • Opportunity to work with a mature security toolset and experienced colleagues.
  • Equal-opportunity employer commitment.
  • Reasonable accommodation for qualified employees with protected disabilities.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Associate Principal Cyber Threat Intelligence Analyst

Dragos 251-1K Professional Services

Dragos is hiring an OT Cyber Threat Intelligence Analyst to support a Singapore government security team with threat hunting, intelligence analysis, and incident response for critical infrastructure environments.

LLM SIEM
5 hours, 26 minutes ago

CyberSecurity Specialist

Avertium 251-1K IT Services

Avertium is hiring a Cyber Security Specialist to support 24x7 SOC monitoring and incident response for mid-market and enterprise clients.

Cybersecurity DNS Encryption HIPAA HTTP SIEM TCP/IP
1 day, 5 hours ago

Security Operations Engineer

Mesh 51-200 financial services

Mesh is hiring a Security Ops Engineer to design, operate, and respond to security controls across its infrastructure and systems as it builds payments infrastructure for the next era of the global economy.

AWS Azure Datadog Docker GCP Kubernetes Network Security Python SIEM Splunk
2 days, 4 hours ago

Security analyst

Gravity Payments 51-250 Diversified Financial Services

Gravity Payments is seeking a Security Analyst to protect and improve security operations across cloud, endpoint, identity, SaaS, and corporate environments.

AWS JIRA Linux macOS Network Security Penetration Testing PowerShell Python Shell Scripting SIEM
2 days, 4 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers