SOC 2 Analyst
AI Summary
SOC 2 Analyst investigates security incidents and determines root causes, reviewing escalated alerts and leading investigations using threat intelligence and SIEM tools.
About this role
SOC 2 Contract
Through 2026
Supporting APAC Time zones
Responsible for investigating security incidents and determining their root causes. They review incidents that have been escalated by Tier 1 analysts, who are responsible for collecting data and reviewing alerts. Tier 2/3 analysts use threat intelligence, such as indicators of compromise , TTPs, and company host system/network data sets to assess the alerts, threats and potential incidents in more depth.
They have deep experience with SIEM tools specifically Crowdstrike SIEM, network data, host data, Identity and Access log data, developing SIEM use cases, reducing/tuning false alerts and leading investigations until issues have been resolved. They will also monitor systems and events across different operating systems, such as Windows, macOS, and Linux.
Must be proactive, problem solver and curious.
Must have 5+ years recent experience as Tier 2 or 3 analyst at a large organization; government and Critical Infrastructure company preferred.
Must have strong, demonstrated SIEM and data correlation experience
Must have demonstrated experience designing new SOC use cases and working with vendor on implementing new use cases.
Must have experience designing and implementing runbooks and use cases to mitigate security incidents
Experience designing Incident Response plan, including alert definition, runbooks, escalation, etc..
Must have extensive experience reviewing and managing alerts in Microsoft Defender, Splunk and or Crowdstrike
Must have experience conducting hunts across disparate data sets, to include host data, vulnerability data, threat data, network data, active directory data, among others to identify threats
Experience leading timely security operations response efforts in collaboration with stakeholders
Experience documenting incident response communications for technical and management audiences
Must have experience setting up alert rules and effective alert management
Demonstrated ability to create runbooks and conducting investigations with key application, IT Infra and other stakeholders
Experience designing custom SOC SIEM use cases in Defender, Splunk and CRWD
Experience conducting forensic work investigations
Most be a problem solver
Must be curious
Must be analytical, qualitative and quantitative abilities
Must be adaptive to dynamic environment
Strong security operations documentation abilities
Skills
Explore related jobs
More jobs at Plurilock
Regional Account Executive – Commercial EnterpriseToronto, Ontario
RS / High-Security L3 SOC Analyst (Secure Environment)Mumbai, Maharashtra
Mid-Level Cyber Threat Intelligence (CTI) AnalystMumbai, Maharashtra
Mid-Level SIEM EngineerMumbai, Maharashtra
SOC 3 AnalystMumbai, Maharashtra
Offshore Events and Marketing CoordinatorManila, Manila
Similar Active Directory jobs
Jobs in Sydney
- MContact Center Sales RepresentativeMci · Sydney, NS
- MContact Center Representative I (Entry-Level)Mci · Sydney, NS
- MContact Centre Representative II (Experienced)Mci · Sydney, NS
- MCall Centre AgentMci · Sydney, NS
- MSales Representative (Full-Time)Mci · Sydney, NS
- MCustomer Service Agent (Mid-Shift)Mci · Sydney, NS
Browse these categories
Market data for this role
All reports →- SeriesRole reportsOne role family at a time: how many openings, what changed this week, who is hiring, what it pays.
- SeriesSalary reportsWhat employers publish in job postings, by level and workplace. Not self-reported pay.
- Market overviewState of tech hiring, September 2026: up 4.8%Tech hiring rose 4.8% month over month in September 2026, with 411,122 new listings. Customer support and account executive roles led the growth.