Tier 2 Cybersecurity Engineer

On Call Computer Solutions, LLC

$90K — $110K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of hands-on SOC, IR, or security operations experience
  • Strong understanding of endpoint security, email/phishing attacks, and identity-based attacks
  • Experience with SIEM platforms and endpoint detection tools
  • Ability to document technical findings for varied audiences
  • Valid and current CompTIA Security+ certification
  • Preferred: GCIH (GIAC Certified Incident Handler)
  • Preferred: CompTIA CySA+ certification

Responsibilities

  • Perform advanced investigation and triage of security alerts
  • Analyze alerts across various telemetry sources
  • Distinguish true positives from false positives and document findings
  • Lead incident response actions including containment and recovery
  • Escalate high-severity incidents with analysis and recommendations
  • Monitor alerts generated by SOC MDR and provide validation
  • Mentor Tier 1 SOC analysts and assist in escalation management

Benefits

  • Comprehensive health/dental benefits from multiple providers
  • Company-paid life insurance policy of $50,000 and disability plan
  • 128 hours of PTO annually
  • Potential bonuses and salary increases through certification achievements
  • Access to paid certifications and training programs
  • Work environment that promotes meaningful impact and professional growth
Full Job Description
Tier 2 Cybersecurity Engineer -

Core Responsibilities

  • Perform advanced investigation and triage of security alerts generated by the SIEM
  • Analyze correlated alerts across endpoint, identity, email, and network telemetry
  • Distinguish true positives from false positives and document findings clearly
  • Lead incident response actions including containment, eradication, and recovery support
  • Escalate high-severity incidents with clear impact analysis and recommended actions
  • Perform advanced investigation and triage of security alerts generated by the EDR, SIEM, Firewalls, Sentinel, and other security tools.
  • Install and configure security solutions as needed

Soc Operations

  • Monitor and respond to alerts generated by SOC MDR
  • Provide contextual enrichment and validation of SIEM findings
  • Act as the internal escalation point for complex or ambiguous detections
  • Collaborate with application/SOC support for detection feedback and escalations

Incident Management & Reporting

  • Own Tier 2-level incidents from investigation through resolution
  • Maintain accurate case documentation and timelines
  • Produce clear, customer-facing incident summaries when required
  • Contribute to post-incident reviews and lessons learned

Collaboration & Continuous Improvement

  • Mentor Tier 1 SOC analysts and assist with escalation handling
  • Participate in tabletop exercises and incident simulations
  • Stay current on emerging threats, attacker techniques, and tool capabilities
  • Recommend improvements to SOC processes, tooling, and response workflows

Required Qualifications

  • 5 or more years of hands-on SOC, IR, or security operations experience
  • Strong understanding of:
    • Endpoint security concepts
    • Email and phishing attack chains
    • Identity-based attacks (credential abuse, MFA bypass)
  • Experience working with:
    • SIEM platforms (querying, investigations, rule tuning)
    • Endpoint detection and response tools
  • Ability to clearly document technical findings for both technical and non-technical audiences

Required Certifications
  • Valid and current CompTIA Security +
  • Nice to Have - GCIH (GIAC Certified Incident Handler)
  • Nice to Have - CompTIA CySA+

Similar Jobs

More Jobs at On Call Computer Solutions, LLC

More Information Technology Jobs

Find similar Tier 2 Cybersecurity Engineer jobs: