Summary
Binary Defense is a Managed Detection and Response provider that delivers proactive, risk-focused security outcomes through SOC analysts, threat hunters, detection engineers, and threat researchers. The Tier 2 SOC Analyst will transform client detection strategies, tune alerts and rules, manage feedback loops, and perform attack surface reduction activities including vulnerability management and penetration test remediation.
Responsibilities
- Create internal alert strategy and process documentation for how client identifies alerting opportunities, prioritizes based on threat level, with a focus and priority on gaps
- Review alerts that are too noisy to tune and drive down alert fatigue
- Assess alerts that haven’t triggered to determine whether logic needs to
- Be the main point of contact to the MDR Provider’s Detection team
- Work with the client’s Incident Responders on alert feedback loops; analyze true and false positive alerts
- Create regular reporting cadence for of all detections created, rules tuned
- Contribute to client’s homegrown “Signal to Noise ratio” detection metric
- Coordinate with MDR Threat Hunting team to request and implement Sentinel One STAR rules
- Map detections to standard frameworks such as the Cyber Kill Chain
- Work with MDR provider on an ongoing tuning of the on-call criteria
- Perform attack surface reduction including full-scope change management, cross functional coordination, enterprise communication planning/execution, execution of changes in support of security remediation
- Provide vulnerability prioritization and analysis, ticketing, reporting, trending, metrics, assistance to patch teams on troubleshooting root cause of patching challenges
- Analyze stale identities and accounts, admin privileges, and recommend and implement improvements
Skills
- 3+ Years Security Operations or Equivalent Experience
- Artificial Intelligence (AI) tools experience
- Experience with Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) tools
- Experience mapping detections to common frameworks and risk reduction models
- Familiarity with the latest trends in attacker TTPs
Qualifications
Must Haves
- 3+ Years Security Operations or Equivalent Experience
- Artificial Intelligence (AI) tools experience
- Experience with Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) tools
- Experience mapping detections to common frameworks and risk reduction models
- Familiarity with the latest trends in attacker TTPs
Benefits
- Competitive medical, dental and vision coverage for employees and dependents
- 401k match which vests every payroll
- Flexible and remote friendly work environment
- Training opportunities to expand your skill set