Binary Defense logo
Binary Defense
Posted 34 days agoVerified live 2d ago

Tier 2 SOC Analyst with AI Tools Experience - REMOTE

Brief overview

Remote
3+ yrsMinimum
Artificial Intelligence (AI) ToolsSecurity Information and Event Management (SIEM)Endpoint Detection and Response (EDR)Detection Mapping to Security FrameworksAttacker Tactics, Techniques, and Procedures (TTPs)

About the company

Binary Defense logo
Binary Defensebinarydefense.com

Binary Defense is a cybersecurity company offering security solutions to monitor, detect, and respond to cyberattacks.

Job description

Summary

Binary Defense is a Managed Detection and Response provider that delivers proactive, risk-focused security outcomes through SOC analysts, threat hunters, detection engineers, and threat researchers. The Tier 2 SOC Analyst will transform client detection strategies, tune alerts and rules, manage feedback loops, and perform attack surface reduction activities including vulnerability management and penetration test remediation.

Responsibilities

  • Create internal alert strategy and process documentation for how client identifies alerting opportunities, prioritizes based on threat level, with a focus and priority on gaps
  • Review alerts that are too noisy to tune and drive down alert fatigue
  • Assess alerts that haven’t triggered to determine whether logic needs to
  • Be the main point of contact to the MDR Provider’s Detection team
  • Work with the client’s Incident Responders on alert feedback loops; analyze true and false positive alerts
  • Create regular reporting cadence for of all detections created, rules tuned
  • Contribute to client’s homegrown “Signal to Noise ratio” detection metric
  • Coordinate with MDR Threat Hunting team to request and implement Sentinel One STAR rules
  • Map detections to standard frameworks such as the Cyber Kill Chain
  • Work with MDR provider on an ongoing tuning of the on-call criteria
  • Perform attack surface reduction including full-scope change management, cross functional coordination, enterprise communication planning/execution, execution of changes in support of security remediation
  • Provide vulnerability prioritization and analysis, ticketing, reporting, trending, metrics, assistance to patch teams on troubleshooting root cause of patching challenges
  • Analyze stale identities and accounts, admin privileges, and recommend and implement improvements

Skills

  • 3+ Years Security Operations or Equivalent Experience
  • Artificial Intelligence (AI) tools experience
  • Experience with Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) tools
  • Experience mapping detections to common frameworks and risk reduction models
  • Familiarity with the latest trends in attacker TTPs

Qualifications

Must Haves

  • 3+ Years Security Operations or Equivalent Experience
  • Artificial Intelligence (AI) tools experience
  • Experience with Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) tools
  • Experience mapping detections to common frameworks and risk reduction models
  • Familiarity with the latest trends in attacker TTPs

Benefits

  • Competitive medical, dental and vision coverage for employees and dependents
  • 401k match which vests every payroll
  • Flexible and remote friendly work environment
  • Training opportunities to expand your skill set

More jobs like this