SIEM - SOC Engg Analyst - Tier 2

Remote • Posted 2 hours ago • Updated 2 hours ago
Contract Corp To Corp
Contract Independent
3 Years
No Travel Required
Remote
Depends on Experience
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • SentinelOne
  • WireSpeed
  • SIEM
  • EDR/XDR
  • Splunk
  • CrowdStrike
  • MITRE
  • CompTia
  • CISSP
  • CEH

Summary

 

SIEM / SOC Engineering Analyst – Tier 2

Location: REMOTE [No Second Jobs]

Visa Type:  H1B1 / / Citizen / OPT’s – No Sponsorship

 Contact:  /

Contact Name:  Sri

Position Summary

The SIEM / SOC Engineering Analyst – Tier 2 is responsible for advanced security monitoring, incident investigation, SIEM engineering, detection development, threat hunting, and security operations support. This position serves as a Tier 2 escalation point for complex security alerts and incidents and works closely with Tier 1 SOC Analysts, Incident Response, Threat Intelligence, Network Security, Infrastructure, and Cloud Security teams.

The ideal candidate will have hands-on experience with SentinelOne, SIEM platforms, endpoint detection and response (EDR), security analytics, and log management. Wirespeed experience is strongly preferred, particularly in environments involving security monitoring, network visibility, telemetry, or security operations engineering.

Key Responsibilities

SIEM & SOC Engineering

  • Administer, configure, and optimize enterprise SIEM and SOC platforms.
  • Configure and maintain security log sources, collectors, agents, and integrations.
  • Monitor and troubleshoot log ingestion, parsing, normalization, and data quality issues.
  • Develop and maintain dashboards, reports, security metrics, and SOC operational views.
  • Identify gaps in security telemetry and work with infrastructure and application teams to improve logging coverage.
  • Support SIEM architecture, integrations, upgrades, and ongoing platform improvements.
  • Optimize security monitoring capabilities while balancing performance, coverage, and operational cost.

Tier 2 Security Operations

  • Serve as a Tier 2 escalation point for complex security alerts and incidents.
  • Investigate escalated alerts involving endpoints, servers, networks, identities, applications, and cloud environments.
  • Analyze security events and correlate information across SIEM, EDR, network, identity, and other security platforms.
  • Determine incident severity, scope, affected systems, potential business impact, and recommended response actions.
  • Perform detailed investigation and root-cause analysis.
  • Escalate confirmed or highly complex incidents to Incident Response/Tier 3 teams.
  • Provide technical guidance to Tier 1 SOC Analysts during investigations.
  • Document investigation findings, timelines, evidence, and remediation recommendations.

SentinelOne / EDR Operations

  • Monitor and investigate security events using SentinelOne EDR/XDR.
  • Investigate endpoint alerts involving malware, ransomware, suspicious processes, persistence, privilege escalation, lateral movement, and command-and-control activity.
  • Analyze endpoint telemetry, process trees, behavioral indicators, network connections, and threat intelligence.
  • Perform endpoint threat hunting using SentinelOne capabilities.
  • Support containment and remediation activities, including endpoint isolation and threat mitigation in accordance with security procedures.
  • Develop and improve endpoint detection and response processes.
  • Tune detection policies and reduce false positives while maintaining effective security coverage.
  • Coordinate with Incident Response and endpoint engineering teams on complex endpoint investigations.

Wirespeed / Network Security

  • Utilize Wirespeed experience to support network visibility, security monitoring, troubleshooting, and SOC operations.
  • Analyze network telemetry and security events to identify suspicious communication patterns and potential threats.
  • Correlate network activity with endpoint, identity, and SIEM data during investigations.
  • Assist with network-based threat detection and investigation.
  • Troubleshoot security monitoring and network telemetry issues.
  • Collaborate with Network Engineering and Security Engineering teams to improve network visibility and detection capabilities.

Detection Engineering

  • Develop, test, tune, and maintain SIEM detection rules and security analytics.
  • Create queries and correlation logic to identify suspicious and malicious activity.
  • Reduce false positives and improve detection fidelity.
  • Map detection use cases to the MITRE ATT&CK framework.
  • Develop detections for common attack techniques including:
    • Credential theft
    • Privilege escalation
    • Lateral movement
    • Persistence
    • Command and control
    • Malware/ransomware
    • Data exfiltration
    • Suspicious authentication
    • Insider threat indicators
  • Continuously improve detection coverage based on threat intelligence and emerging attack techniques.

Threat Hunting

  • Conduct proactive threat hunting across endpoint, network, identity, and SIEM telemetry.
  • Develop hunting hypotheses based on threat intelligence, vulnerabilities, and emerging attack campaigns.
  • Investigate indicators of compromise and suspicious behavior.
  • Identify previously undetected threats and recommend new detection rules.
  • Support MITRE ATT&CK-based threat hunting and detection validation.

Automation & Continuous Improvement

  • Identify repetitive SOC processes suitable for automation.
  • Develop scripts, workflows, or integrations to improve SOC efficiency.
  • Support integration between SIEM, SentinelOne, SOAR, ITSM, threat intelligence, and other security technologies.
  • Develop and maintain SOC runbooks, playbooks, procedures, and technical documentation.
  • Participate in incident reviews and recommend improvements to monitoring and response processes.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field, or equivalent professional experience.
  • 3–7+ years of experience in SOC, cybersecurity operations, SIEM, EDR, security engineering, or incident response.
  • Experience working in a Tier 2 SOC or security operations environment.
  • Hands-on experience with SIEM platforms and security monitoring technologies.
  • Strong experience with SentinelOne or comparable EDR/XDR platforms.
  • Wirespeed experience strongly preferred.
  • Strong understanding of security event analysis, incident investigation, and threat detection.
  • Experience analyzing endpoint, network, authentication, and application logs.
  • Knowledge of common attack techniques and cybersecurity frameworks.
  • Strong troubleshooting and analytical skills.
  • Ability to work independently on escalated security incidents.

Preferred Technical Skills

  • SentinelOne
  • Wirespeed
  • SIEM platforms
  • EDR/XDR
  • Microsoft Sentinel
  • Splunk
  • CrowdStrike
  • Microsoft Defender
  • Security Operations / SOC tools
  • Network security monitoring
  • Threat Intelligence
  • MITRE ATT&CK
  • Active Directory / Entra ID
  • Windows and Linux security
  • TCP/IP, DNS, HTTP/HTTPS
  • Firewall and VPN technologies
  • Vulnerability management
  • Python, PowerShell, or Bash
  • REST APIs
  • SOAR and security automation
  • ServiceNow or other ITSM platforms

Preferred Certifications

  • CompTIA Security+
  • CompTIA CySA+
  • Microsoft SC-200
  • Microsoft AZ-500
  • GIAC certifications
  • CISSP
  • CEH
  • SentinelOne-related certifications/training
  • Splunk or other SIEM certifications

Core Competencies

  • Tier 2 SOC Operations
  • SIEM Engineering
  • Security Monitoring
  • SentinelOne EDR
  • Network Security Monitoring
  • Wirespeed
  • Incident Investigation
  • Detection Engineering
  • Threat Hunting
  • Malware Analysis
  • Endpoint Security
  • Log Analysis
  • Alert Triage & Escalation
  • Root-Cause Analysis
  • Incident Response
  • Security Automation
  • MITRE ATT&CK
  • Technical Troubleshooting
  • Documentation
  • Cross-functional Collaboration

Work Environment

  • Participate in a 24x7 SOC/on-call rotation, as required.
  • Handle high-priority security incidents under time-sensitive conditions.
  • Work collaboratively with geographically distributed security and technology teams.
  • Maintain strict confidentiality and follow organizational security, privacy, and compliance requirements.

Ideal Candidate

The ideal candidate is a hands-on Tier 2 SOC professional with strong SIEM, EDR, and security investigation experience. The candidate should be capable of progressing beyond basic alert monitoring into deeper investigation, threat hunting, detection engineering, and SOC platform improvement.

Experience with SentinelOne is highly desirable, while Wirespeed experience is preferred. The successful candidate will combine strong technical troubleshooting skills with the ability to investigate complex security events, identify threats, improve detection capabilities, and collaborate effectively across cybersecurity and IT teams.

 

Contact:  /

 

 

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91173010
  • Position Id: 9081429
  • Posted 2 hours ago
Contact the job poster
Srikanth Vasireddy

Srikanth Vasireddy

Recruiter @ TEKNEWGEN LLC
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote

Today

Easy Apply

Full-time, Part-time, Contract, Third Party

Remote

2d ago

Easy Apply

Contract

$80 - $90

Remote

Today

Full-time

Remote

Today

Full-time

USD 80,001.00 - 120,000.00 per year

Search all similar jobs