Overview
The Enterprise Security Analyst II is a hands-on Security Operations Center (SOC) role responsible for monitoring alerts, investigating security events, supporting incident response, and improving security operations. This role also applies cyber threat intelligence and threat hunting practices to add context to investigations, identify emerging threats, and strengthen detection and response capabilities. Primary schedule is business hours, Monday through Friday. Participation in an after-hours on-call rotation is expected after onboarding and demonstrated familiarity with systems, tools, and response procedures.
Responsibilities
Security Operations and Incident Response
- Monitor and manage the SOC alert queue across endpoint, identity, network, email, cloud, and log monitoring platforms
- Independently triage and investigate security alerts and events, distinguishing confirmed threats from benign activity using available evidence and telemetry
- Support the full incident lifecycle, including investigation, escalation, containment support, remediation follow-up, documentation, and closure
- Escalate incidents with clear evidence, impact assessment, and recommended next steps
- Apply playbooks and runbooks while identifying opportunities to improve alert quality, response consistency, automation, and analyst enablement
Threat Intelligence and Threat Hunting
- Analyze relevant threat intelligence to identify threats, campaigns, vulnerabilities, and adversary behaviors that may affect the organization
- Enrich alerts and investigations with context about threat