Job Description
The Cybersecurity Analyst (L2) owns escalated alerts and confirmed incidents that clear front-line triage, investigating and driving
them to resolution.
Essential Duties and Responsibilities include the following. Other duties may be assigned.
* Own escalated alerts and confirmed incidents that clear front-line triage ? investigate, scope impact, and drive them to
resolution.
* Serve as the escalation point for the L1 triage analysts, including phishing intake, providing guidance and quality control.
* Investigate across the full appliance stack Eng maintains ? EDR, SIEM, firewall, email security, and identity/access ?
correlating signal across tools rather than working alerts in isolation.
* Participate in coverage that spans business hours.
* Feed real investigation findings back to Detection Engineering so tuning reflects what's actually happening on the floor,
not just theoretical use-cases.
* Work alongside the Cybersecurity Engineer team to validate and refine agent-assisted alert triage.
* Document findings clearly enough to support incident response, audit, and handoff to after-hours team.
* Work with the SOC Lead to create documented alert triage workflows.
Required Knowledge and Attributes
* Sound judgment on when to dig in independently versus loop in Detection Engineering, Eng, or the automation team.
* Willingness to work alongside AI-assisted triage tooling and give the engineers building it real, specific feedback.
* Clear written communication; documenting incidents that other teams and auditors will read.
Required Education and Experience
* 2-4 years hands-on experience triaging, investigating, and escalating security alerts in a SOC or equivalent operations
environment.
* Working fluency across core security tooling ? EDR, SIEM/log analysis, network/firewall traffic, email security, and identity systems.
* Working Knowledge of Crowdstrike, Darktrace and/or Splunk is a big plus.