Tier 2 Security Operations Analyst
Remote · На постоянной основе
Подайте заявку первыми!
- Опыт
- 3–5 лет
- Зарплата
- USD 95,000 – USD 120,000 / year
- Открытия
- 1
- Опубликовано
- 4 часа назад
- Режим работы
- Работа из дома
- Образование
- Bachelor's degree or equivalent practical experience
- Резюме
- Необходимо подать заявку.
Описание работы
About Ostra Security
Ostra Security specializes in managed extended detection and response (MXDR), aiming to provide enterprise-level cybersecurity to organizations of all sizes. Their comprehensive service includes detection, response, and threat intelligence, enabling clients to focus on their core operations without worrying about cyber attacks. The Security Operations Center (SOC) operates 24/7, combining advanced technology with dedicated personnel who treat each client's network with utmost care.
Role Overview
The Tier 2 Security Operations Analyst acts as a crucial investigator within Ostra’s managed SOC. This position involves handling escalated alerts and incidents across multiple client environments, conducting detailed root-cause analyses, and containment actions. The analyst digs deeply into endpoint, network, and log information to ascertain incident details, the extent of impact, and appropriate mitigation steps, then clearly communicates findings and develops durable detection methods.
Key Responsibilities
- Investigate and classify incidents by analyzing their severity, cause, scope, and impact across client environments.
- Lead incident response efforts, coordinating with clients and external entities to effectively contain and resolve incidents.
- Conduct proactive threat hunting to identify novel and evasive security threats using established methodologies.
- Develop, monitor, and optimize SIEM detection rules and SOAR playbooks to enhance detection accuracy, reduce false positives, and automate response.
- Author and update playbooks and SOPs for recurring incidents ensuring consistent and rapid SOC responses.
- Leverage threat intelligence from various sources to produce actionable insights tailored to client contexts and mitigate risks.
- Communicate complex technical findings and risks to diverse stakeholder groups with timely updates and reports that meet SLAs.
- Mentor Tier 1 analysts to enhance their skills, review their work, and elevate SOC efficiency and quality.
- Continuously refine SOC processes and procedures to boost performance and accuracy.
- Participate in a rotating on-call schedule as an escalation point, providing support during off-hours for a global SOC.
Required Qualifications
- 3 to 5 years of practical experience as a SOC analyst, incident responder, or network security analyst, preferably in multi-client or high-paced settings.
- Proven ability to conduct thorough investigations of security incidents beyond initial triage, including root cause and impact analysis.
- Solid understanding of TCP/IP, network protocols, Windows and Unix/Linux logs, and IDS/IPS systems.
- Hands-on experience with SIEM, SOAR, EDR/XDR, NGFW, IDS/IPS, HIDS/HIPS, antivirus, and vulnerability scanners.
- Competence with at least one SIEM query language and skills to create, tune, and troubleshoot threat detections.
- Proficiency in a scripting language such as PowerShell, Bash, or Python for automation of analysis and response tasks.
- Familiar with the MITRE ATT&CK framework and capable of designing use cases and SOPs based on threat behaviors.
- Knowledge of the NIST Cybersecurity Framework with practical implementation capabilities.
- Excellent technical writing skills with the ability to document procedures and incident reports for varied audiences.
- Strong problem-solving aptitude and comfort working with ambiguous or incomplete data.
- Self-driven and reliable with the capability to manage end-to-end incident resolutions in a fast-paced environment.
- Bachelor's degree in a relevant discipline or equivalent practical experience.
- Willingness to engage in a rotating on-call schedule to provide off-hours support as needed.
Preferred Qualifications
- Previous experience in a Managed Security Service Provider (MSSP) or multi-tenant SOC environment.
- Industry certifications such as CompTIA Security+, CompTIA CySA+, GIAC certifications (GCIH, GCIA, GCFA), or CISSP are advantageous.
- Experience with cloud security technologies across AWS, Azure, Google Cloud, or Microsoft 365.
- Track record of creating new detection use cases and SOAR automations from scratch.
- Experience collaborating with geographically dispersed teams across multiple time zones.
- Advanced familiarity with emerging cyber threats, vulnerabilities, and attacker techniques.
Employment Details & Culture
Ostra Security offers a supportive culture emphasizing trust and authenticity, competitive remuneration packages, and opportunities for professional growth in the cybersecurity sector. The company is dedicated to diversity and inclusivity, ensuring employment decisions are merit-based and free from discrimination.
Salary & Location
The salary range for this full-time remote position is between $95,000 and $120,000 annually, depending on experience. Preference is given to candidates residing in Minnesota for business and team alignment reasons.
Equal Opportunity
Ostra Security is an equal opportunity employer committed to fostering an inclusive workplace where individuals of all backgrounds are valued.