SOC Security Analyst L2

BlueVoyant
United States
2 days ago
Apply on bluevoyant.applytojob.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Shift work

Tech stack

Microsoft Windows Microsoft Antivirus Unix Cloud Computing Cyber Security Intrusion Detection Systems Python (Programming Language) Log Analysis Network Monitoring Network Protocols Windows PowerShell Anti-Phishing
+10 more
Kusto Query Language Security Information and Event Management Data Logging Scripting Malware Firewalls (Computer Science) Information Technology Microsoft Sentinel Splunk SentinelOne Expertise

Job description

BlueVoyant is seeking a SOC Security Analyst L2 to join our Security Operations Center, defending our global customers against constant and evolving adversary activity. In this role you will own and work through a queue of security alerts and tickets, carrying out thorough investigations, resolving cases accurately and efficiently, and escalating confirmed or complex incidents to L3 analysts with clear, well-documented findings. You will work closely with senior analysts and clients to reduce the impact and dwell time of security incidents. This role reports into BlueVoyant SOC leadership and operates under BlueVoyant processes, tooling, and supervision at all times, including when working within client environments.

What You’ll Do:

  • Monitor, triage, and investigate security alerts and tickets from multiple sources, including SIEM logs, endpoint logs, and EDR telemetry.
  • Own assigned tickets through to resolution, working within defined SLAs and prioritizing by severity and client impact.
  • Research indicators and activities to determine reputation and suspicious attributes.
  • Perform analysis of suspicious files, emails, URLs, and attacker infrastructure to support investigations.
  • Determine whether activity is malicious, benign, or a false positive, and escalate confirmed or complex incidents to L3 analysts with clear supporting evidence.
  • Document investigation steps, findings, and recommended actions accurately within the ticketing and case management system.
  • Take initial response actions in line with runbooks and client-approved procedures, such as isolating endpoints or disabling compromised accounts.
  • Communicate with clients to provide ticket updates, request information, and share remediation guidance.
  • Identify false-positive or benign detections and recommend tuning improvements.
  • Contribute to the improvement of runbooks, procedures, and automation.
  • Support and share knowledge with L1 analysts and incorporate feedback from L3 peer review and QA.
  • Operate across BlueVoyant-managed systems and client-provided environments in accordance with client-approved access controls, logging, and BlueVoyant operating procedures, maintaining strict separation and adherence to security policies.

Requirements

  • Ability to manage a high-volume ticket queue in a fast-paced environment while maintaining accuracy and attention to detail.
  • Strong written and verbal communication skills, with the ability to document findings clearly and explain technical issues in easy-to-understand language.
  • Strong teamwork and interpersonal skills, including working effectively within a globally distributed team.
  • Ability to work directly with clients to provide updates and gather information.
  • Knowledge and experience with SIEM solutions, Cloud App Security tools, and EDR.
  • Experience in endpoint, web, email, and authentication log analysis.
  • Solid understanding of network protocols and network telemetry.
  • Knowledge of common attack techniques, including phishing, business email compromise (BEC), credential harvesting, LOLBin use, and lateral movement.
  • Working knowledge of:
  • SIEM workflows (preferably Microsoft Sentinel and Splunk)
  • Microsoft 365 and Entra ID security alerts and sign-in logs
  • Email security and phishing analysis
  • Network monitoring metadata (web logs, firewall logs, WAF/IDS)
  • Windows and Unix operating system fundamentals and common forensic artifacts
  • Ticketing and case management systems
  • Ability to successfully complete a background check and any client-required security vetting.

Nice to Have:

  • 3+ years of hands-on SOC/TOC/NOC experience.
  • Experience in an MSSP/MSP environment supporting multiple clients.
  • Basic malware analysis or sandboxing experience.
  • Experience writing SIEM queries (KQL or SPL).
  • Familiarity with Microsoft Sentinel, Splunk, Microsoft Defender suite, CrowdStrike Falcon, and SentinelOne.
  • Understanding of a scripting language such as Python or PowerShell.
  • Relevant certifications such as: Security+, CySA+, Network+, GIAC (e.g. GSEC, GCIH), Microsoft SC-200, CEH

Education:

  • Bachelor’s degree in Information Security, Computer Science, or another IT-related field, or equivalent professional experience.

About the company

Why BlueVoyant?

  • Investigate real-world threats across a diverse global client base, building hands-on experience with leading Microsoft Security, SIEM, and EDR technologies.
  • Develop your skills alongside senior L3 analysts and incident responders, with clear opportunities to grow toward advanced investigation and response.
  • Join a global, mission-driven cybersecurity company defending organizations worldwide with cutting-edge data, technology, and expertise.
  • Competitive compensation and a comprehensive benefits package, with support for wellbeing, development, and career growth.

About BlueVoyant BlueVoyant is an AI-driven cybersecurity company dedicated to standing between our customers and cyber threats. By combining human, artificial, and proprietary intelligence, we deliver a unified solution that protects every organization’s network, identities, vendors, and digital footprints as a single attack surface. The company’s award-winning Microsoft Security expertise helps organizations maximize their security investments while reducing risk and ensuring compliance.

Led by CEO, John Hernandez, BlueVoyant’s highly skilled team includes former government cyber officials with extensive frontline experience in responding to advanced cyber threats on behalf of the National Security Agency, Federal Bureau of Investigation, Unit 8200, and GCHQ, together with private sector experts. BlueVoyant services utilize large real-time datasets with industry leading analytics and technologies.

Founded in 2017 by Fortune 500 executives, including Chairman of the Board, Jim Rosenthal, Vice Chairman, Tom Glocer, and former Government cyber officials, BlueVoyant is headquartered in New York City and has offices in Maryland, Tel Aviv, London, Budapest, and Latin America and is committed to building a workplace where talented people are empowered to do their best work in the fight against global cyber threats.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on bluevoyant.applytojob.com
Prepare application

Good distractions

Loading talks and stories from around this role…