Security Operations Analyst II

Tegus, Inc.

Vancouver

Hybrid

CAD 90,000 - 120,000

Full time

37 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

AlphaSense is seeking a Security Operations Analyst II to join our Security Operations team from Canada in a fully remote capacity. You will handle triage, structured investigations, and containment of incidents as part of Tier 1–2, collaborating with senior analysts to close coverage gaps.

You will monitor endpoint, network, cloud, and identity data, classify alerts with rationale, and contribute to detection quality improvements and runbooks.

Qualifications

  • 2–4+ years hands-on experience in a SOC or security operations role with alert triage responsibility.
  • Strong understanding of MITRE ATT&CK framework and how to label attacker behavior.
  • Working knowledge of EDR tooling: process tree analysis and detection review.
  • Familiarity with SIEM-based investigations: querying logs and building timelines.
  • Understanding of foundational network protocols (TCP/IP, DNS, HTTP/S, TLS).
  • Exposure to cloud security monitoring (AWS/GCP) including IAM alert investigation.
  • Experience investigating identity-based alerts in enterprise identity providers (e.g., Okta, Entra ID).
  • Strong written communication; case notes should be clear and structured.

Responsibilities

  • Monitor and triage alerts across endpoint, network, cloud, and identity data sources.
  • Perform structured investigations on escalated alerts and build coherent timelines.
  • Classify alerts with rationale and assess true/false positives.
  • Identify scope and blast radius of incidents and escalate with a complete package.
  • Participate in active incident response under direction; collect evidence and reconstruct timelines.
  • Execute containment actions with documented rationale.
  • Maintain accurate case documentation throughout incident lifecycles.
  • Contribute to post-incident timelines and root cause documentation.
  • Monitor cloud audit logs and IAM activity for suspicious events.
  • Flag false positives and assist with tuning detections; apply MITRE ATT&CK labels.
  • Prepare clear incident updates for leadership and runbooks.

Skills

SOC experience
MITRE ATT&CK
EDR tooling
SIEM investigations
Network protocols
Cloud security
Identity alerts
Written comms

Tools

CrowdStrike Falcon
SentinelOne
Google Chronicle
Microsoft Sentinel
Wiz
Prisma Cloud
CloudTrail

Job description

The world’s most sophisticated companies rely on AlphaSense to remove uncertainty from decision-making. With market intelligence and search built on proven AI, AlphaSense delivers insights that matter from content you can trust. Our universe of public and private content includes equity research, company filings, event transcripts, expert calls, news, trade journals, and clients’ own research content.

The acquisition of Tegus by AlphaSense in 2024 advances our shared mission to empower professionals to make smarter decisions through AI-driven market intelligence. Together, AlphaSense and Tegus will accelerate growth, innovation, and content expansion, with complementary product and content capabilities that enable users to unearth even more comprehensive insights from thousands of content sets. Our platform is trusted by over 6,000 enterprise customers, including a majority of the S&P 500. Founded in 2011, AlphaSense is headquartered in New York City with more than 2,000 employees across the globe and offices in the U.S., U.K., Finland, India, Singapore, Canada, and Ireland. Come join us!

Remote within Canada, able to work in the Pacific time zone

ABOUT THE ROLE

We are hiring Security Operations Analyst IIto join our Security Operations team in a fully remote capacity from Canada. This role sits at Tier 1–2 in our operating model — you are past the stage of learning what alerts look like and ready to own triage, perform structured investigations, and contribute to detection quality. You will handle the day-to-day alert queue, investigate escalated or ambiguous cases, handle incidents and work closely with senior analysts and the Security Operations Manager to close coverage gaps.

We expect you to think analytically, document thoroughly, and operate with growing independence. You will be supported by experienced colleagues and a mature toolset, but you are expected to bring real investigative instinct and a curiosity to grow to the role from day one.

WHAT YOU WILL DO

  • Monitor and triage alerts across endpoint, network, cloud, runtime and identity data sources with accuracy and appropriate urgency
  • Perform structured investigations on escalated or ambiguous alerts: pivot across log sources, correlate events, and build a coherent timeline
  • Classify alerts correctly — true positive, false positive, or benign — with documented rationale, not just a verdict
  • Identify scope and blast radius on confirmed incidents: affected users, systems, and data before escalating or containing
  • Escalate to senior analysts with a complete investigation package — context, evidence, timeline, and a hypothesis
  • Participate in active incident response under senior analyst or manager direction: evidence collection, log pulls, timeline reconstruction
  • Execute containment actions — endpoint isolation, account suspension, token revocation — as directed with documented rationale
  • Maintain accurate and timely case documentation throughout the incident lifecycle
  • Contribute to post-incident timelines and assist with root cause documentation

Cloud & Identity Security Monitoring

  • Monitor cloud audit logs and native threat detection findings for suspicious IAM activity, unusual API calls, and access anomalies
  • Investigate identity provider events: suspicious logins, MFA bypass attempts, session anomalies, and unauthorized app assignments
  • Recognize common cloud-native attack patterns: credential abuse via metadata service, privilege escalation via IAM role assumption, and storage misconfiguration access
  • Correlate cloud-side events with endpoint and network telemetry to build a fuller picture of attacker activity

Detection & Quality Improvement

  • Flag false positives and noisy detections with enough context for a senior analyst or detection engineer to tune them
  • Identify gaps in existing detection coverage based on alert patterns you observe during triage
  • Apply knowledge of MITRE ATT&CK to label attacker techniques and communicate findings consistently
  • Contribute to runbook accuracy by flagging outdated steps or missing guidance encountered during investigations
  • Participate with Detections Engineers to build detections and contribute to automating activity with an Engineering mindset

Documentation & Communication

  • Write clear, concise case notes that a colleague could pick up mid-investigation without needing to re-investigate from scratch
  • Produce shift handoff summaries that accurately represent open cases, pending actions, and investigation status
  • Communicate incident updates to the Security Operations Manager with sufficient clarity to brief upward without re-investigation

WHAT WE ARE LOOKING FOR

Required

  • 2–4+ years of hands-on experience in a SOC, or security operations role with direct alert triage responsibility
  • Solid understanding of the MITRE ATT&CK framework — you use it to label and communicate attacker behavior, not just reference it
  • Working knowledge of EDR tooling: process tree analysis, behavioral detection review, and basic endpoint artifact interpretation
  • Familiarity with SIEM-based investigation: querying logs, correlating events across sources, and building timelines from normalized data
  • Understanding of foundational network protocols (TCP/IP, DNS, HTTP/S, TLS) and how attackers abuse them
  • Exposure to cloud security monitoring ex. AWS or GCP — including audit log review and IAM-related alert investigation
  • Experience investigating identity-based alerts in an enterprise identity provider (e.g., Okta, Entra ID, or equivalent)
  • Strong written communication: your case notes are accurate, structured, and useful to someone who wasn’t there

Preferred

  • Experience with next-gen EDR platforms (e.g., CrowdStrike Falcon, SentinelOne, or equivalent) beyond basic alert review — RTR, process trees, custom detections
  • Hands-on SIEM experience with a cloud-native platform (e.g., Google SecOps/Chronicle, Microsoft Sentinel, or equivalent)
  • Exposure to CSPM or cloud security tooling (e.g., Wiz, Prisma Cloud, or equivalent) as an investigation data source
  • Familiarity with AWS IR fundamentals: CloudTrail, GuardDuty, VPC Flow Logs, IAM chain analysis
  • Understanding of encoding vs. encryption vs. hashing and their relevance to attacker obfuscation techniques
  • Experience working alongside or receiving escalations from a managed detection and response (MDR) partner
  • Relevant certifications: CompTIA CySA+, Security+, BTL1, GCIH, or equivalent practical security credential

AlphaSense is an equal-opportunity employer. We are committed to a work environment that supports, inspires, and respects all individuals. All employees share in the responsibility for fulfilling AlphaSense’s commitment to equal employment opportunity. AlphaSense does not discriminate against any employee or applicant on the basis of race, color, sex (including pregnancy), national origin, age, religion, marital status, sexual orientation, gender identity, gender expression, military or veteran status, disability, or any other non-merit factor. This policy applies to every aspect of employment at AlphaSense, including recruitment, hiring, training, advancement, and termination.

In addition, it is the policy of AlphaSense to provide reasonable accommodation to qualified employees who have protected disabilities to the extent required by applicable laws, regulations, and ordinances where a particular employee works.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Product Security Engineer Remote - Canada
Staff Product Security Engineer Remote - Canada

AlphaSense, Inc. • Canada

Hybrid
CAD 134,000 - 184,000
Competitive compensation
Generous benefits
Career growth opportunities
Associate, Customer & Product Support
Associate, Customer & Product Support

Tegus, Inc. • Canada

Hybrid
CAD 65,000 - 75,000
Generous benefits program
Disclosed salary range
Senior Product Manager, Financial Data Remote - Canada
Senior Product Manager, Financial Data Remote - Canada

AlphaSense, Inc. • Canada

Hybrid
CAD 129,000 - 165,000
Bonus
Equity
Benefits
Product Manager II - Financial Data
Product Manager II - Financial Data

Alphasense • Vancouver

On-site
CAD 111,000 - 145,000
Bonus eligibility
Generous benefits
Equity options
Product Manager II - Financial Data AlphaSense · Canada · fintech $111k–145k/yr $111k–145k/yr ● New
Product Manager II - Financial Data AlphaSense · Canada · fintech $111k–145k/yr $111k–145k/yr ● New

Scrolllaunch • Canada

Hybrid
CAD 111,000 - 145,000
Senior SOC Analyst
Senior SOC Analyst

Socket.dev • Montreal (administrative region)

On-site
CAD 90,000 - 130,000
Senior SOC Analyst
Senior SOC Analyst

Coveo • Montreal (administrative region)

On-site
CAD 90,000 - 120,000
Senior Research Engineer, Threat Intelligence
Senior Research Engineer, Threat Intelligence

Limelight Health • Canada

On-site
CAD 127,000 - 163,000
Health benefits
Unlimited PTO
Parental leave
+1
Senior Security Engineer
Senior Security Engineer

EQ Bank | Equitable Bank • Toronto

Hybrid
CAD 100,000 - 140,000
Competitive discretionary bonus
Market-leading RRSP match program
Medical, dental, vision, life, and disability benefits
+3
Senior Information Security Analyst
Senior Information Security Analyst

IKO North America • Mississauga

On-site
CAD 106,000 - 120,000
Competitive compensation
Health care
Challenging workplace
+1