Apply Now

Please mention DailyRemote when applying

AI Summary

Investigate escalated security alerts to distinguish genuine threats from false positives and drive incidents through containment and resolution. Contribute to the maturity of detection content, tuning rules, and enhancing incident response playbooks.
Our client in IT/Tech sector is seeking a seeking a SOC Analyst II to join the security operations team. This is a hands-on, second-line role at the center of the client's detection and response program.

Job Summary
The ideal candidate will spend each day investigating security alerts that have escalated beyond the initial triage layer, distinguishing genuine threats from false positives, and driving confirmed incidents through containment, remediation, and resolution. The ideal candidate will operate in a fast-paced, telemetry-rich environment spanning cloud and on-premises infrastructure, thousands of endpoints, and a modern security stack that includes SIEM, EDR, and email security platforms.

Beyond day-to-day monitoring, the ideal candidate will take ownership of improving the effectiveness of the security operations function. The ideal candidate will contribute to maturing detection content, reducing alert fatigue by tuning false positives, and enhancing incident response runbooks and playbooks to ensure consistent handling across shifts. Working closely with senior SOC analysts, threat hunters, and detection engineers, the ideal candidate will have the opportunity to strengthen technical expertise and progress toward a Tier 3 SOC Analyst or specialized Security Engineering career path. This is a fully remote opportunity available on either a full-time or contract basis.
Key Responsibilities
  • Monitor, triage, and investigate security alerts across SIEM, EDR, identity, and email security platforms
  • Own Tier 2 investigation, containment, eradication, and escalation of confirmed security incidents
  • Analyze logs, network traffic, endpoint telemetry, and user activity to identify indicators of compromise
  • Conduct root cause analysis and document incidents, findings, and response actions per established runbooks
  • Tune detection rules, suppress false positives, and recommend new detection logic in partnership with engineering
  • Participate in proactive threat hunting based on current threat intelligence and emerging tactics
  • Support and contribute to post-incident reviews, lessons learned, and continuous improvement of response playbooks
  • Maintain shift handoff notes and ensure continuity of monitoring across a 24/7 coverage model

Required Qualifications
  • 2 to 4 years of hands-on SOC, incident response, or security analyst experience
  • Working knowledge of SIEM platforms such as Splunk, Microsoft Sentinel, or QRadar
  • Familiarity with EDR tooling including CrowdStrike, SentinelOne, or Microsoft Defender
  • Solid grounding in networking fundamentals, TCP/IP, DNS, and common attack techniques
  • Ability to interpret logs and telemetry to reconstruct an attack timeline
  • Strong written documentation and clear communication under time pressure

Preferred Qualifications
  • Security+, CySA+, GCIH, or equivalent certification
  • Experience with SOAR platforms and automation scripting in Python or PowerShell
  • Working familiarity with the MITRE ATT&CK framework and threat-informed defense
  • Exposure to cloud security monitoring in AWS or Azure


Similar Jobs

See all Remote Others jobs β†’

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Others

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified