Tier 2 SOC Analyst
Hamilton Barnes ๐ณ ยท New York, United States
Apply & track with Apply EdgeTier 2 SOC Analyst
This role serves as a technical escalation point for complex, high-severity security incidents affecting our client base, working within a Microsoft-centric security stack (Sentinel, Defender XDR suite). You'll operate with a high degree of autonomy, mentor Tier 1 analysts, and play a key role in maturing detection and response capabilities across multiple client environments.This is a hybrid role based in New York, combining in-office collaboration with remote flexibility.Key ResponsibilitiesServe as the primary Tier 2 escalation point for security alerts and incidents triaged and escalated by Tier 1 analysts.Perform in-depth investigation and correlation of security events across SIEM, EDR, identity, email, cloud, and network telemetry.Conduct threat hunting using KQL and advanced hunting queries to proactively identify malicious or anomalous activity.Lead incident response activities including containment, eradication, and recovery โ including endpoint isolation, credential resets, mailbox remediation, and cloud resource actions.Perform root cause analysis on confirmed incidents and produce clear, accurate incident documentation and post-incident reports for clients.Develop, tune, and optimize SIEM detection rules, correlation logic, and automation/SOAR playbooks to reduce false positives and improve detection fidelity.Review Tier 1 analyst investigations for quality and accuracy, providing coaching and technical mentorship.Analyze malware samples, phishing attempts, and suspicious artifacts to determine scope and impact.Maintain and enhance SOC playbooks, runbooks, and standard operating procedures.Support vulnerability management efforts by correlating findings with active threats where relevant.Participate in an on-call/rotational schedule to support 24/7 SOC coverage as needed.Required Skills & ExperienceMinimum 5 years of hands-on experience in cybersecurity, with significant time in a SOC or security operations role.Strong working knowledge of Microsoft Sentinel and the Microsoft Defender XDR suite (Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud, Entra ID).Proficiency writing and tuning KQL (Kusto Query Language) queries for hunting and detection engineering.Solid understanding of networking fundamentals, Windows security events, and common attack techniques (mapped to MITRE ATT&CK where applicable).Experience with EDR, firewall, IDS/IPS, and network traffic analysis tools (e.g., Wireshark).Familiarity with SOAR platforms and Logic Apps (or equivalent) for automation and playbook development.Working knowledge of Active Directory, Entra ID, VPN, DLP, and CASB technologies.Prior MSSP or multi-client SOC experience strongly preferred.Must be a U.S. Citizen. Preferred CertificationsSecurity+, CySA+, or equivalentGCIH, GCIA, or CISSPMicrosoft SC-200 (Security Operations Analyst Associate) or similarWhat We OfferCompetitive base salary: $125,000 โ $145,000Hybrid work model based out of our New York officeHealth, dental, and vision insurance401(k) with company matchOngoing training and certification supportClear growth path toward Tier 3 / Senior Analyst and detection engineering roles