Tier 2 Cybersecurity Engineer - Core Responsibilities
- Perform advanced investigation and triage of security alerts generated by the SIEM
- Analyze correlated alerts across endpoint, identity, email, and network telemetry
- Distinguish true positives from false positives and document findings clearly
- Lead incident response actions including containment, eradication, and recovery support
- Escalate high-severity incidents with clear impact analysis and recommended actions
- Perform advanced investigation and triage of security alerts generated by the EDR, SIEM, Firewalls, Sentinel, and other security tools.
- Install and configure security solutions as needed
Soc Operations
- Monitor and respond to alerts generated by SOC MDR
- Provide contextual enrichment and validation of SIEM findings
- Act as the internal escalation point for complex or ambiguous detections
- Collaborate with application/SOC support for detection feedback and escalations
Incident Management & Reporting
- Own Tier 2-level incidents from investigation through resolution
- Maintain accurate case documentation and timelines
- Produce clear, customer-facing incident summaries when required
- Contribute to post-incident reviews and lessons learned
Collaboration & Continuous Improvement
- Mentor Tier 1 SOC analysts and assist with escalation handling
- Participate in tabletop exercises and incident simulations
- Stay current on emerging threats, attacker techniques, and tool capabilities
- Recommend improvements to SOC processes, tooling, and response workflows
Required Qualifications
- 5 or more years of hands-on SOC, IR, or security operations experience
- Strong understanding of:
- Endpoint security concepts
- Email and phishing attack chains
- Identity-based attacks (credential abuse, MFA bypass)
- Experience working with:
- SIEM platforms (querying, investigations, rule tuning)
- Endpoint detection and response tools
- Ability to clearly document technical findings for both technical and non-technical audiences
Required Certifications
- Valid and current CompTIA Security +
- Nice to Have - GCIH (GIAC Certified Incident Handler)
- Nice to Have - CompTIA CySA+