Tier 2 SOC Analyst

Paylocity
Houston, TX, United States
about 1 month ago
Apply on recruiting.paylocity.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Cyber Security Security Information and Event Management Software Vulnerability Management Mitre Att&ck Splunk SentinelOne Expertise

Job description

Binary Defense is seeking a client-facing Tier 2 SOC Analyst to serve as a hands-on contributor within a client’s Security Operations team.

This is a technical position responsible for transforming the client’s detection strategy, organizing detections, tuning rules, and creating and maintaining cross functional feedback loops. Additionally, leading analysis, design, and hands-on analysis and remediation for Attack Surface Reduction functions such as vulnerability management and penetration test remediation.

You’ll play a key role in growing capabilities with leading tools in the client’s environment such as Splunk, Proofpoint, SentinelOne, and more. This role requires deep technical expertise, strong cross-functional communication, and the ability to deliver operational results.

Responsibilities

  • Create internal alert strategy and process documentation for how client identifies alerting opportunities, prioritizes based on threat level, with a focus and priority on gaps
  • Review alerts that are too noisy to tune and drive down alert fatigue
  • Assess alerts that haven’t triggered to determine whether logic needs to
  • Be the main point of contact to the MDR Provider’s Detection team
  • Work with the client’s Incident Responders on alert feedback loops; analyze true and false positive alerts
  • Create regular reporting cadence for of all detections created, rules tuned
  • Contribute to client’s homegrown “Signal to Noise ratio” detection metric
  • Coordinate with MDR Threat Hunting team to request and implement Sentinel One STAR rules
  • Map detections to standard frameworks such as the Cyber Kill Chain
  • Work with MDR provider on an ongoing tuning of the on-call criteria
  • Perform attack surface reduction including full-scope change management, cross functional coordination, enterprise communication planning/execution, execution of changes in support of security remediation
  • Provide vulnerability prioritization and analysis, ticketing, reporting, trending, metrics, assistance to patch teams on troubleshooting root cause of patching challenges
  • Analyze stale identities and accounts, admin privileges, and recommend and implement improvements

Requirements

  • 5+ Years Security Operations or Equivalent Experience
  • Experience with Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) tools
  • Experience mapping detections to common frameworks and risk reduction models
  • Familiarity with the latest trends in attacker TTPs

About the company

Binary Defense is a leading Managed Detection and Response (MDR) provider, trusted by hundreds of organizations to protect what matters most. Our team of SOC analysts, threat hunters, detection engineers, and threat researchers work around the clock to deliver proactive, risk-focused security outcomes. We bring the attacker’s mindset to defense, helping clients detect threats earlier, respond faster, and continuously improve their security posture.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on recruiting.paylocity.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin ¡ World Congress 2022

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 ¡ LIVE

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber ¡ World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman ¡ World Congress 2022

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler ¡ LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 ¡ LIVE

Videos

See all

Related articles

See all