Cybersecurity Analyst – Tier 2

Vanderlande Industries GmbH

Vancouver

On-site

CAD 90,000 - 115,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Vanderlande Industries GmbH is seeking a Tier 2 Security Operations Center Analyst to lead complex investigations, coordinate incident response, and drive threat detection improvements.

You will mentor junior analysts, act as escalation for Tier 1, and work with threat intelligence to enrich investigations across customer environments within SLAs.

Qualifications

  • 5+ years in cybersecurity with at least 2 years in a SOC/IR role.
  • Advanced expertise in SIEM, EDR, and forensic tools.
  • Strong understanding of MITRE ATT&CK framework and threat actor TTPs.
  • Experience with scripting in Python and PowerShell.
  • Ability to lead incident response efforts under pressure and communicate clearly.

Responsibilities

  • Perform advanced analysis of escalated security incidents and support investigation efforts.
  • Act as an escalation point for Tier 1 analysts and provide expert guidance during incident response activities.
  • Develop and tune detection rules and use cases in SIEM and other platforms.
  • Perform threat hunting based on intelligence and behavioral analysis.
  • Conduct forensic analysis and reverse engineering of malware when needed.
  • Collaborate with threat intelligence teams to enrich investigations.
  • Provide strategic recommendations to improve SOC processes and technologies.
  • Mentor junior analysts and contribute to training programs.
  • Participate in detection validation and lessons‑learned activities to enhance SOC detection and response.

Skills

IR leadership in IR
SIEM, EDR, forensic tools
MITRE ATT&CK knowledge
Scripting (Python, PowerShell)
Incident response under pressure

Education

Bachelor's degree IT/Cybersecurity/CS

Job description

TheSecurity Operations Center – Tier 2 Analystwill lead complex investigations, coordinate incident response efforts, and drive continuous improvement in threat detection and response capabilities. You will serve as a technical expert and escalation pointforTier 1analysts,customersor otherdepartments.This role supports incident detection, escalation, and responseactivities withincustomer environments, in line with agreed SOC service scope and service level agreements (SLAs).Youwill have hadpreviousexperience in handling escalation from Tier 1 and direct work in security monitoring, threat intelligence, or incident response

Key Responsibilities
  • Perform advanced analysis of escalated security incidents and support investigation efforts.
  • Act as an escalation point for Tier 1 analysts andprovideexpert guidance during incident response activities.
  • Develop and tune detection rules and use cases in SIEM and other platforms.
  • Perform threat hunting based on intelligence and behavioral analysis.
  • Conduct forensic analysis and reverse engineering of malware when needed.
  • Collaborate with threat intelligence teams to enrich investigations.
  • Provide strategic recommendations to improve SOC processes and technologies.
  • Mentor junior analysts and contribute to training programs.
  • Participate in detection validation and lessons‑learned activities to enhance SOC detection and response.
Additional Responsibilities
Monitoring & Detection
  • ValidatecomplexalertsescalatedbyTier 1
  • Determinescope, impact, and severity of confirmed incidents.
  • Perform deep log analysis, forensic investigations, and develop custom detection rules.
  • Implement containment,mitigationand remediationactions.in accordance with playbooks and customer agreements
  • Understanding TTPs (tactics, techniques, procedures) of threat actors
  • Ability to develop custom detection rulesand correlation logic
Investigation & Analysis
  • Analyze data patterns and outliers toidentifythreat actor behaviors and insider threats.
  • Conduct deep investigations into logs, network telemetry, and endpoint activity.
  • Document findings, actions taken, and recommended next steps.
Incident Response Support
  • Assist the SOC team during active security incidents by collecting evidence andcontaininglow‑severity threats as per playbooks.
  • Follow established runbooks to ensure consistent and compliant response actions.
  • Respond to escalated security incidents requiring advanced analysis.
  • Provide containment recommendations and support remediation.
Access Management
  • Processing user access requests (add, remove,modify) following established workflows.
  • Enforcing least‑privilege principles and role‑based access standards.
  • Conducting periodic access reviews (user accounts, permissions, group memberships).
  • Investigating and escalating suspicious access activities or unauthorized access attempts.
Patch Management
  • Assistwith tracking and verifying system patch status as part of vulnerability review activities.
  • Monitor patch‑related alerts (failed deployments, outdated versions) within security tools and coordinate remediation with IT operations.
  • Support the vulnerability management process byvalidatingmissing patchesidentifiedduring scans and escalating high‑risk findings.
    (This is aligned with Tier 1’s documented tasks involving vulnerability scans and reporting.)
Reporting & Communication
  • Generate clear,accurateincident reports and daily shift summaries.
  • Communicate event details with internal teams in a professional andtimelymanner.
Continuous Improvement
  • Recommend improvements to detection rules, response processes, and SOC procedures.
  • Stay current on cyber threat trends, attacker techniques (TTPs), and security best practices.
Required Qualifications
  • 5+ years of experience in cybersecurity, with at least 2 years in a SOC or IR role.
  • Advancedexpertisein SIEM, EDR, and forensic tools.
  • Strong understanding of MITRE ATT&CK framework and threat actor TTPs.
  • Experience with scripting and automation (e.g., Python, PowerShell).
  • Ability to lead and manage incident response efforts under pressure.
  • Relevantsecurity certifications from ISC2 or ISACA
  • Excellent communication and leadership skills.
Preferred Qualifications
  • Bachelor’s degree in IT, Cybersecurity, or CS
  • Certifications such as:
  • CompTIA Security+
  • Microsoft SC-200
  • CEH,CySA+
  • GIAC certifications (GSEC, GCIH, GMON)
  • Experience with:
  • EDR, IDS/IPS, and network security tools
  • SIEM/SOAR workflows/playbooks
  • Threat intelligence platforms
Key Competencies
  • Strong analytical and problem‑solving skills
  • Attention to detail
  • Ability to work under pressure during incidents
  • Team‑first mindset and willingness to learn
  • Ability to recognize patterns and anomalies
  • Prior SOC or IR experience
  • Strong analysis and investigation skills
  • Familiarity with threat intelligence and adversary behavior
  • Ability to perform forensic/log analysis
  • More advanced certifications preferred
Work Environment
  • 24/7 SOC environment - day shift with weekend coverage
  • Fast‑paced operational setting with tight response timelines
  • Collaboration with cross‑functional IT and security teams
Salary range:

This is a full-time, exempt position, eligible to receive a base salary and to participate in an annual performance bonus program. The salary range listed represents the maximum and minimum starting base pay for this position as of the time of posting. Final salary offered will be determined based on factors including but not limited to the candidate's skills and experience. The annual performance bonus program is preset and not candidate dependent.

Salary range for this position is CAD$90,000 to CAD$115,000.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Analyst - Tier 2
Cybersecurity Analyst - Tier 2

Vanderlande • Vancouver

On-site
CAD 90,000 - 130,000
L3 SOC Analyst - Calgary
L3 SOC Analyst - Calgary

Integrity360 • Calgary

Hybrid
CAD 80,000 - 110,000
L3 SOC Analyst / Incident Responder
L3 SOC Analyst / Incident Responder

act digital • Montreal (administrative region)

On-site
CAD 90,000 - 120,000
Remote working available
Flex Office work environment
Annual training and certification
Soc Analyst
Soc Analyst

Altis Technology • Toronto

Hybrid
CAD 90,000 - 130,000
Junior SOC Analyst - Systems Integrator
Junior SOC Analyst - Systems Integrator

Hamilton Barnes Associates Limited • Golden Horseshoe

On-site
CAD 50,000 - 57,000
Health insurance after 90 days
Dental insurance after 90 days
Vision insurance after 90 days
+1
Cybersecurity Analyst - IT Security Services
Cybersecurity Analyst - IT Security Services

RiseMe • Victoria

On-site
CAD 90,000 - 130,000
Security Analyst
Security Analyst

EIZIE • West Hawk Lake

On-site
CAD 80,000 - 110,000
Competitive salary
Health and dental benefits
Professional development
+5
Remote Security Operations Center (SOC) Analyst
Remote Security Operations Center (SOC) Analyst

Placements24 • Kimberley

Hybrid
CAD 65,000 - 95,000
Fully remote work arrangement
Competitive salary and benefits
Global collaboration
Information Security Analyst
Information Security Analyst

Glocomms • Montreal (administrative region)

On-site
CAD 70,000 - 110,000
Bonus opportunity
Generous paid time off
Wellness reimbursement programs
+3
Incident Response Analyst, Digital Forensics & Incident Response
Incident Response Analyst, Digital Forensics & Incident Response

ISA Cybersecurity Inc • Toronto

On-site
CAD 75,000 - 105,000
Flexible sick days
Health plan
Education reimbursement
+5