> Markdown version of [/jobs/ext/1409571-tier-2-security-operations-analyst](https://www.wearedevelopers.com/jobs/ext/1409571-tier-2-security-operations-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Tier 2 Security Operations Analyst - **Company:** OSTRA - **Location:** Eden Prairie, MN, United States (Remote available) - **Experience:** Experienced - **Salary:** $95,000.0 - $120,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Data Analysis, Antivirus Softwares, Audit Trail, Microsoft Azure, Bash Shell, Cloud Computing Security, CompTIA Security+, Cyber Security, Query Languages, Event Logging, Intrusion Detection Systems, Python (Programming Language), Network Protocols, Windows PowerShell, Security Information and Event Management, TCP/IP, Scripting, Google Cloud, Mitre Att&ck, Security Orchestration, Automation & Response, Vulnerability Analysis - **Published:** July 23, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=8e3b9dd65bf26fa9 ## About the Role * 3-5 years of hands-on experience as a SOC analyst, incident responder, or security-focused network analyst, ideally in a fast-paced or multi-client environment. * Demonstrated experience investigating and escalating security incidents beyond initial triage-establishing root cause, scope, and impact. * Working knowledge of TCP/IP and common network protocols, Windows event logs, *nix audit logs, and IDS/IPS alerting. * Hands-on experience with core security tooling categories: SIEM, SOAR, EDR/XDR, next-generation firewalls (NGFW), IDS/IPS, HIDS/HIPS, antivirus, and vulnerability scanners. * Proficiency with at least one SIEM query language and the ability to build, tune, and troubleshoot detections. * Proficiency in at least one common scripting language (PowerShell, Bash, Python, or similar) to automate analysis and response. * Solid understanding of the MITRE ATT&CK framework and experience building use cases and SOPs around relevant TTPs. * Familiarity with the NIST Cybersecurity Framework and the ability to apply its principles in practice. * Strong technical writing skills-able to document processes, procedures, and incident findings clearly for varied audiences. * Excellent problem-solving skills and comfort working through ambiguity and incomplete information. * Self-motivated, dependable, and able to deliver end-to-end results in a high-tempo environment. * Bachelor's degree in a related field, or equivalent practical experience. * Willingness to participate in a rotating on-call schedule and provide off-hours support as needed., * Prior experience at a managed security service provider (MSSP) or in a multi-tenant SOC. * Relevant certifications (preferred, not required): CompTIA Security+, CompTIA CySA+, GIAC (GCIH, GCIA, GCFA), or CISSP. * Cloud security experience across AWS, Azure, Google Cloud, and/or Microsoft 365. * Experience developing new detection use cases and SOAR automations from scratch. * Experience working with a geographically distributed team across multiple time zones. * Expert-level understanding of common and emerging security threats, vulnerabilities, and attacker tradecraft. ## Description As a Tier 2 Security Operations Analyst, you are the investigative backbone of Ostra's managed SOC. You take ownership of escalated alerts and incidents across our clients' environments, driving them from detection through root-cause analysis and containment. You go beyond triage: you dig into endpoint, network, and log data to determine what happened, how far it reached, and what to do next-then you translate those findings into clear guidance for clients and durable detections for the team. This is a multi-tenant role. You will work across many client environments, prioritize based on risk and service-level agreements (SLAs), and communicate effectively with both technical and non-technical stakeholders. You will also mentor Tier 1 analysts, sharpen our detection and response playbooks, and serve as an escalation point during on-call rotations., Investigate & classify incidents. Own escalated alerts and incidents across client environments; classify them, determine severity, and analyze data and systems to establish cause, scope, and impact. * Lead response & containment. Act as an incident handler for sensitive and need-to-know incidents, applying CSIRT best practices and Ostra's incident response model; coordinate with clients and external parties to drive incidents to closure. * Threat hunt. Proactively hunt for novel and evasive threats using sound hunt methodology. * Engineer & tune detections. Understand, monitor, and optimize SIEM detection rules and SOAR playbooks; continuously improve detection accuracy, reduce false positives, and accelerate or automate response. * Author & maintain playbooks. Develop, document, and maintain playbooks and standard operating procedures (SOPs) for recurring incidents and tasks so the SOC can respond consistently and quickly. * Produce & apply threat intelligence. Ingest threat data from open and closed sources, correlate it against client context to produce actionable intelligence, and take appropriate action to mitigate risk. * Communicate with clients. Clearly explain technical findings, risk, and recommended actions to client stakeholders; deliver timely, well-written incident updates and reports within SLA. * Mentor Tier 1 analysts. Guide and upskill Tier 1 analysts, review their work, and help raise the overall quality and speed of the SOC. * Improve continuously. Refine processes and procedures to improve speed and accuracy, and contribute to a culture of measurable improvement. * Provide on-call escalation. Serve as an escalation point during a rotating on-call schedule, supporting a global SOC and off-hours coverage as required by the business. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [MCP doesn’t suck — your agent does](https://www.wearedevelopers.com/videos/100202-mcp-doesn-t-suck-your-agent-does) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk)