> Markdown version of [/jobs/ext/2935995-cybersecurity-analyst-tier-2](https://www.wearedevelopers.com/jobs/ext/2935995-cybersecurity-analyst-tier-2). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Analyst Tier 2 - **Company:** UNIVERSITY OF UTAH - **Location:** Salt Lake City, UT, United States - **Experience:** Experienced - **Salary:** $73,000.0 - $93,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cyber Security, Computer Networks, Data Security, Query Languages, Linux, Identity and Access Management, Pcap, Log Analysis, NetFlow, Kusto Query Language, Security Information and Event Management, Data Logging, Google Cloud, Cloud Platform System, Okta, Mitre Att&ck, Cybercrime, 3-tier Architectures - **Published:** September 16, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e7288a9ca46147e8 ## About the Role EQUIVALENCY STATEMENT: 1 year of higher education can be substituted for 1 year of directly related work experience (Example: bachelor's degree = 4 years of directly related work experience). Information Security Analyst, II: Requires a bachelor's (or equivalency) + 4 years or a master's (or equivalency) + 2 years of directly related work experience. Preferences Experience: 4 years dedicated cybersecurity operations, threat triage, or incident response experience in a SOC environment. Technical mastery: Strong expertise analyzing logs across Windows/Linux, cloud environments (AWS, Azure, GCP), network traffic (PCAP, NetFlow), and identity platforms (Entra ID, Okta). Querying & Log Analysis: Proficiency using platform query languages (e.g. KQL, SPL, YARA) for deep investigation, log correlation, and evaluating rule performance. Framework Alignment: Practical working knowledge of applying the MITRE ATT&CK framework to real-world investigations, triage workflows, and post-incident reporting. Certifications (Preferred): GCIH, GCFA, GSOC, SC-200, CCSP. Soft Skills: Excellent analytical problem-solving skills and a strong passion for teaching and elevating junior team members. A demonstrated ability to write complex technical reports for a non-technical audience., The University of Utah values candidates who have experience working in settings with students and possess a strong commitment to improving access to higher education., + High School Diploma or Equivalent + Associate Degree + Bachelor's Degree + Master's Degree + Doctorate Degree * * How many years of related work experience do you have? + Less than 6 years + 6 years or more, but less than 9 years + 9 years or more, but less than 12 years + 12 years or more, but less than 15 years + 15 years or more * * I am a U.S. citizen ** It is anticipated that this position will involve access to federally funded research that is subject to federal sponsorship regulatory restrictions (e.g. certain export control, data security, acquisition regulations, or federal contract clauses) that mandate U.S. citizen participation only. ## Description Information Security Analyst II Incident Response: * Perform in-depth investigations, root cause analysis, and containment activities for escalated, complex, or multi-vector security incidents across endpoint, network, cloud, and identity domains * Serve as the primary escalation point for Tier 1 analysts, providing technical guidance during active triage and validating escalation quality. * Perform initial scoping and technical artifact analysis to support response actions and prevent incident propagation. * Draft clear, detailed incident postmortem reports and document technical findings for internal stakeholders. Detection & Playbook Optimization: * Partner with Tier 3 analysts to tune, refine, and update existing detection logic across SIEM, EDR, and cloud security platforms to reduce false positives and improve alert fidelity. * Identify detection coverage gaps and telemetry blind spots during investigations, providing actionable recommendations to Tier 3 for new rules or detection enhancements. * Assist Tier 3 analysts in testing, providing feedback on, and maintaining automated response workflows (SOAR) to streamline routine SOC tasks. Threat Analysis: * Analyze complex adversary behavior from escalated alerts, mapping attack paths to the MITRE ATT&CK framework. * Assist Tier 3 analysts in executing structured, hypothesis-driven threat hunting campaigns across corporate and cloud environments. * Operationalize threat intelligence updates by executing indicator-of-compromise (IOC) sweeps (threat hunting) and validating threat exposure. Leadership & Team Support: * Mentor and develop Tier 1 SOC analysts through regular shift handovers, technical guidance, and investigation peer reviews. * Identify operational bottlenecks and propose improvements to SOC workflows and triage procedures. - Partner with internal IT and platform teams to address logging gaps and remediate host- or network-level security weaknesses. Job Code: P34212 Grade: P17 ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk)