Tier 2 SOC Analyst / Engineer

Location
D03 Queenstown, Bukit Merah, Tiong Bahru
Job Type
Full-time
Experience
Mid
Category
General
Salary
$4,000 - $5,000
Posted
20 hours ago
Expires
Sep 1, 2026
Views
1

Job Details

Vacancies

1 position

Experience Required

No experience required

Job Description

We are looking for a Tier 2 SOC Analyst/Engineer to serve as the escalation point for our Tier 1 SOC team. This role owns in-depth investigation of escalated alerts, performs root cause analysis, leads incident response activities, and drives detection engineering and threat hunting initiatives to continuously mature our security monitoring program. You will be a technical anchor for the SOC — turning raw alerts into confirmed incidents, confirmed incidents into lessons learned, and lessons learned into better detections.

Department: Security Operations Center (SOC)

Reports to: SOC Manager

Works closely with: Tier 1 SOC Analysts (escalation point), Detection Engineering, IT Infrastructure, Application Development

## Key Responsibilities

**Escalation & Investigation**

- Serve as the primary technical escalation point for Tier 1 analysts on alerts requiring deeper analysis

- Conduct in-depth investigations across endpoint, network, cloud, identity, and application telemetry

- Correlate data across multiple tools/log sources (SIEM, EDR, NDR, cloud logs, identity providers) to determine scope and impact

- Distinguish true positives from false positives and refine triage logic accordingly

**Root Cause Analysis**

- Perform root cause analysis on confirmed incidents to determine initial vector, method, and any control gaps

- Document attack timelines/kill chains and produce clear technical findings for stakeholders

- Identify systemic issues (misconfigurations, missing patches, process gaps) surfaced during investigations

**Incident Response**

- Lead or co-lead containment, eradication, and recovery activities for security incidents

- Coordinate with IT, engineering, legal, and management during active incidents per the IR plan

- Author incident reports, timelines, and post-incident/lessons-learned reviews

- Support tabletop exercises and continuous improvement of IR playbooks and runbooks

**Detection Engineering**

- Design, build, test, and tune detection rules/use cases (SIEM correlation rules, EDR detections, Sigma rules, etc.)

- Translate threat intel, incident findings, and threat hunt results into new or improved detections

- Reduce alert fatigue by improving detection fidelity and eliminating noisy/low-value alerts

- Map detections to a framework such as MITRE ATT&CK to identify and close coverage gaps

**Threat Hunting**

- Conduct proactive, hypothesis-driven threat hunts using threat intelligence, ATT&CK TTPs, and anomaly analysis

- Identify indicators of compromise or adversary behavior not caught by existing detections

- Convert hunt findings into new detection logic and share findings with the broader team

**Mentorship & Process**

- Mentor and provide technical guidance to Tier 1 analysts, including escalation reviews and knowledge transfer

- Contribute to and maintain SOC playbooks, runbooks, and standard operating procedures

- Support onboarding of new log sources, tools, and data feeds into the SOC's monitoring scope

- Participate in an on-call/escalation rotation as needed

## Required Qualifications

- 3+ years of hands-on SOC experience, with demonstrated progression into Tier 2/senior analyst responsibilities

- Strong understanding of the attack lifecycle, common TTPs, and the MITRE ATT&CK framework

- Hands-on experience with SIEM platforms (e.g., Splunk, Sentinel, QRadar, Elastic) — writing/tuning correlation rules and queries

- Experience with EDR/XDR tools (e.g., CrowdStrike, Microsoft Defender, SentinelOne, TrendAI) for endpoint investigation

- Solid grasp of networking fundamentals (TCP/IP, DNS, HTTP/S, proxies) and ability to read packet captures

- Experience with incident response processes: containment, eradication, recovery, and post-incident reporting

- Familiarity with cloud security monitoring (AWS/Azure/GCP logs, IAM, CloudTrail or equivalent)

- Scripting/automation skills (Python, PowerShell, or similar) for detection logic, parsing, or workflow automation

- Excellent written and verbal communication skills — able to translate technical findings for non-technical stakeholders

- Ability to remain calm and methodical under pressure during active incidents

## Preferred Qualifications

- Certifications such as GCIH, GCIA, GCFA, CySA+, OSCP, or equivalent

- Experience writing Sigma, YARA, or Snort/Suricata rules

- Experience with SOAR platforms for playbook automation

- Familiarity with digital forensics tools and techniques (memory/disk forensics)

- Experience with threat intelligence platforms and integrating IOC feeds

- Prior experience mentoring or training junior analysts

## What Success Looks Like

- Reduced mean-time-to-detect (MTTD) and mean-time-to-respond (MTTR) for escalated incidents

- Measurable improvement in detection coverage against ATT&CK techniques relevant to the organization

- A steady cadence of proactive threat hunts with documented findings and resulting detections

- Well-documented incidents with clear root cause and remediation tracking

- Stronger, more capable Tier 1 team through consistent mentorship and escalation feedback

Similar Jobs

💬 People Engagement Associate

SKILLMATCH RECRUITMENT Islandwide 20 hours ago
EMINENCE ORGANIZATION PTE. LTD.

🚀 Ambitious? Join Our Growing Team!🚀

EMINENCE ORGANIZATION PTE. LTD. D01 Marina, Raffles Place, People's Park, Cecil 20 hours ago
ROYAL ORG PTE. LTD.

Sales Representative (Entry-level, Travel Opportunities)

ROYAL ORG PTE. LTD. D01 Marina, Raffles Place, People's Park, Cecil 20 hours ago

Event Marketing Associate (No experience is welcome!)

ATRIX MARKETING SOLUTIONS Islandwide 20 hours ago
ROYAL ORG PTE. LTD.

Business Development (Entry-level)

ROYAL ORG PTE. LTD. D01 Marina, Raffles Place, People's Park, Cecil 20 hours ago

Response Reality Check

Quality: 95%
Response N/A
Company Stats
Response metrics N/A
Platform Spread
mycareersfuture
95%
Quality Score
N/A
Response Rate

INSYGHTS SECURITY PTE. LTD.

Ready to Apply?

This is a direct application to INSYGHTS SECURITY PTE. LTD.. No recruitment agencies involved.

Apply for this Position

Response rate not available - Direct application to employer