> Markdown version of [/jobs/ext/1471227-tier-2-soc-analyst](https://www.wearedevelopers.com/jobs/ext/1471227-tier-2-soc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Tier 2 SOC Analyst - **Company:** Paylocity - **Location:** Houston, TX, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, Security Information and Event Management, Software Vulnerability Management, Mitre Att&ck, Splunk, SentinelOne Expertise - **Published:** July 28, 2026 - **Apply:** https://recruiting.paylocity.com/Recruiting/Jobs/Apply/4365775 ## About the Role * 5+ Years Security Operations or Equivalent Experience * Experience with Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) tools * Experience mapping detections to common frameworks and risk reduction models * Familiarity with the latest trends in attacker TTPs ## Description Binary Defense is seeking a client-facing Tier 2 SOC Analyst to serve as a hands-on contributor within a client's Security Operations team. This is a technical position responsible for transforming the client's detection strategy, organizing detections, tuning rules, and creating and maintaining cross functional feedback loops. Additionally, leading analysis, design, and hands-on analysis and remediation for Attack Surface Reduction functions such as vulnerability management and penetration test remediation. You'll play a key role in growing capabilities with leading tools in the client's environment such as Splunk, Proofpoint, SentinelOne, and more. This role requires deep technical expertise, strong cross-functional communication, and the ability to deliver operational results. Responsibilities * Create internal alert strategy and process documentation for how client identifies alerting opportunities, prioritizes based on threat level, with a focus and priority on gaps * Review alerts that are too noisy to tune and drive down alert fatigue * Assess alerts that haven't triggered to determine whether logic needs to * Be the main point of contact to the MDR Provider's Detection team * Work with the client's Incident Responders on alert feedback loops; analyze true and false positive alerts * Create regular reporting cadence for of all detections created, rules tuned * Contribute to client's homegrown "Signal to Noise ratio" detection metric * Coordinate with MDR Threat Hunting team to request and implement Sentinel One STAR rules * Map detections to standard frameworks such as the Cyber Kill Chain * Work with MDR provider on an ongoing tuning of the on-call criteria * Perform attack surface reduction including full-scope change management, cross functional coordination, enterprise communication planning/execution, execution of changes in support of security remediation * Provide vulnerability prioritization and analysis, ticketing, reporting, trending, metrics, assistance to patch teams on troubleshooting root cause of patching challenges * Analyze stale identities and accounts, admin privileges, and recommend and implement improvements ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk)