SOC 2 Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+3 more
Job description
The Security Specialist role is responsible for managing services for Managed Security Service customers. The Security Specialist has the remit of discovering, assessing and directing remediation of security threats & vulnerabilities within client environments whilst working as part of a managed security team on various cyber security projects and tasks.
This role involves working at all levels with Solution Architects, Development Operations, Security Engineers, SOC Analysts, clients and other stakeholders in building and managing security architecture and systems which are kept up-to-date and relevant in the rapidly evolving Managed Security Services industry.
This is a technical SOC role and the role holder is expected to provide Tier 2 analysis and escalation support across managed security services, while supporting, mentoring and coaching junior colleagues. There will also be a requirement to liaise with clients, internal teams, channel partners and vendors., * Handles internal and client escalations by engaging with key stakeholders.
- Follows published SOC policies and procedures.
- Works alongside subject matter experts across the Managed Security Service portfolio and be able to clearly articulate deliverables, limitations, feasibility, etc.
- Analyzes configuration, tuning, and maintenance of SOC tools to improve detective capability and building re-usable visualisations / dashboards for security alert triage, threat hunting and similar use cases, etc.
- Develops Standard Operating Procedures (SOPs) and use cases for monitoring and handling different types of security events.
- Performs threat intelligence gathering to ensure that detection methods are effective against current threats.
- Hunts for suspicious activity based on anomalous activity.
- Handles events as part of the Security Incident Management Process.
- Works with both internal and external partners to investigate and advise on security incidents and anomalies.
- Prepares detailed reports, providing information on findings, status and progress of investigations, as well as vulnerability and risk factors.
- Serves as the technical escalation point and mentor for junior colleagues.
- Produces incident response playbooks to drive a consistent approach to handling common incidents and improve operational processes.
- Analyses structured security log data through the creation of aggregated / correlated reports or visualizations.
- Identify and implement opportunities for innovative and continuous improvement.
- Demonstrates and actively promotes an understanding and commitment to the mission of Logicalis through performing behaviors consistent with the organization’s values.
- Maintains a working knowledge of applicable Federal, State, and Local laws and regulations as well as policies and procedures of Logicalis in order to ensure adherence in a manner that reflects honest, ethical and professional behaviors.
- Supports and conducts self in a manner consistent with customer service expectations.
Requirements
To perform this job successfully, an individual should be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions., * Bachelor’s Degree in a related field., * Previous hands-on experience working in SOC environments is mandatory.
- Experience working within managed services, including SLAs, KPIs, operational reporting and continuous service improvement.
- Strong incident analysis and incident handling experience, including triage, escalation, containment support and structured documentation.
- Experience with SIEM platforms such as Microsoft Sentinel and/or Splunk.
- Knowledge of MITRE ATT&CK and common incident response frameworks.
- Experience with endpoint and XDR technologies is a strong plus, particularly Cisco XDR and Microsoft Defender.
- Experience with MISP, n8n or SOAR platforms is a plus.
- Ability to collaborate with Tier 1 analysts, engineers, threat intelligence teams and customer stakeholders.
- Excellent analytical and problem-solving skills, with the ability to work under pressure and maintain attention to detail.
- Excellent written and oral communication skills, with the ability to document findings clearly and communicate operational status effectively.
- Self-motivated, outcome-focused and committed to continual service improvement.
Certifications
- Certifications from Microsoft, Splunk and GIAC are highly valued, for example Microsoft SC-200, Microsoft SC-100, Splunk Core Certified Power User, Splunk Enterprise Certified Admin, GIAC GCIH, GCIA, GCFA or GNFA.
Other Skills and Abilities
- Typically 5+ years of experience in cybersecurity, including significant experience in SOC, MSSP or mature internal security operations environments.
- Hands-on experience analyzing security logs from SIEM, EDR/XDR, endpoint, identity, cloud and network security sources.
- Experience with Microsoft Sentinel and/or Splunk is highly valued.
- Experience with Cisco XDR, MISP, n8n and security automation/orchestration is highly valued.
- Experience with Azure and/or AWS security monitoring is valued.
- Awareness of security standards and frameworks such as ISO 27001, NIST, MITRE ATT&CK and common vulnerability management practices.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Is Software Engineering Over-Saturated?
Data Analyst Salary in the UK
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.