[Hiring] SOC Security Analyst L2 @BlueVoyant
SOC Security Analyst L2 @BlueVoyant
All Others
Salary unspecified
Remote Location
๐Ÿ‡บ๐Ÿ‡ธ USA Only
Employment Type full-time
Posted 2d ago

[Hiring] SOC Security Analyst L2 @BlueVoyant

2d ago - BlueVoyant is hiring a remote SOC Security Analyst L2. ๐Ÿ’ธ Salary: unspecified ๐Ÿ“Location: USA

Role Description

BlueVoyant is seeking a Security Operations Center (SOC) Security Analyst L2 to help global customers manage and improve their cybersecurity posture. You will work in a fast-paced environment focused on minimizing the impact of security incidents and ensuring critical business operations remain uninterrupted.

As a senior analyst, you serve as the technical expert and escalation point for junior analysts. Your deep understanding of modern attacks, intrusion data analysis, and remediation techniques ensures that threats are identified, escalated, and remediated with urgency and precision. You will mentor junior team members, support customers directly, and contribute to ongoing process and technology improvements.

Key Responsibilities

  • Ensure the safety and security of customer environments through expert analysis, escalation handling, and effective communication.
  • Monitor and analyze security events and alerts from SIEM platforms, endpoint logs, network telemetry, and EDR tools.
  • Research indicators of compromise (IOCs) and malicious activity to determine reputation and risk.
  • Conduct malware analysis, attacker infrastructure investigation, and forensic analysis.
  • Execute complex investigations and declare incidents when appropriate.
  • Perform live response and remote forensics on compromised endpoints.
  • Conduct threat hunting activities based on behavioral anomalies and curated intelligence.
  • Participate in and support incident response, investigation, and documentation.
  • Collaborate closely with BlueVoyant Incident Response teams during active intrusions.
  • Ensure events are accurately identified, analyzed, escalated, and documented.
  • Identify and tune false positives and benign detections.
  • Perform peer reviews and QA checks on junior analystsโ€™ investigations.
  • Mentor lower-level analysts and act as the technical escalation point.
  • Communicate regularly with clients regarding incidents, findings, and remediation steps.
  • Support Customer Success teams during client engagements as required.
  • Assist in improving security policies, procedures, tooling, and automation.

Qualifications

  • Ability to remain calm and effective in high-pressure security incident situations.
  • Ability to work directly with customers to gather requirements and provide feedback on security services.
  • Strong written and verbal communication skills with the ability to translate complex technical concepts into clear, understandable language.
  • Strong teamwork and interpersonal skills; comfortable working with a globally distributed team.
  • Willingness and ability to work a 24/7/365 rotating shift schedule.
  • Experience using SIEM solutions, Cloud App Security tools, and EDR platforms.
  • Advanced understanding of network protocols and network telemetry.
  • Knowledge of Windows and Unix forensic artifacts and analysis methods.
  • Expertise in endpoint, web, and authentication log analysis.
  • Experience creating SIEM/EDR detections.
  • Experience responding to modern authentication attacks (AD, Entra, OATH, etc.).
  • Deep knowledge of common attack paths, including LOLBins, adversary tools, BEC attacks, AiTM, and lateral movement techniques.
  • Strong knowledge of SIEM workflows (preferably Microsoft Sentinel or Splunk).
  • Modern authentication systems and attacks (SSO, OATH, Entra).
  • Malware detection and analysis (dynamic and light static).
  • Network and firewall logs, IDS/WAF, web traffic logs.
  • Email security and BEC attack methodologies.
  • Windows and Unix forensic artifacts (registry, wtmp/btmp, etc.).
  • Windows PE and malicious document analysis.
  • Legitimate and malicious remote access methods.
  • O365 attack paths and common adversary techniques.
  • Network metadata and commonly abused protocols.
  • Credential harvesting tools and methodologies.
  • Experience countering ransomware threat actors (preferred).

Requirements

  • Experience in intrusion analysis, incident response, digital forensics, penetration testing, or similar fields.
  • 3+ years of hands-on SOC/TOC/NOC experience.
  • GIAC certification(s) strongly preferred.
  • Additional certifications such as CISSP, Security+, Network+, CEH, RHCA, RHCE, MCSA, MCP, MCSE.
  • Familiarity with tools such as Microsoft Sentinel, Splunk, Microsoft Defender suite, CrowdStrike Falcon, SentinelOne.
  • Familiarity with GPO, LANDesk, or other IT infrastructure tools.
  • Experience with one or more programming languages (JavaScript, Python, Lua, Ruby, Go, Rust).

Education

  • Bachelorโ€™s degree in Information Security, Computer Science, or related IT field, or equivalent experience.
Before You Apply
๏ธ
๐Ÿ‡บ๐Ÿ‡ธ Be aware of the location restriction for this remote position: USA Only
โ€ผ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
SOC Security Analyst L2 @BlueVoyant
All Others
Salary unspecified
Remote Location
๐Ÿ‡บ๐Ÿ‡ธ USA Only
Employment Type full-time
Posted 2d ago
Apply for this position
Did not apply โœ“
Applied โœ“
Sent Follow-Up โœ“
Interview Scheduled โœ“
Interview Completed โœ“
Offer Accepted โœ“
Offer Declined โœ“
Application Denied โœ“
Unlock 160,000+ Remote Jobs
๏ธ
๐Ÿ‡บ๐Ÿ‡ธ Be aware of the location restriction for this remote position: USA Only
โ€ผ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply โœ“
Applied โœ“
Sent Follow-Up โœ“
Interview Scheduled โœ“
Interview Completed โœ“
Offer Accepted โœ“
Offer Declined โœ“
Application Denied โœ“
Unlock 160,000+ Remote Jobs
ร—

Apply to the best remote jobs
before everyone else

Access 160,000+ vetted remote jobs and get daily alerts.

4.9 โ˜…โ˜…โ˜…โ˜…โ˜… from 500+ reviews
Unlock All Jobs Now

Maybe later