Tier 2 SOC Analyst / Engineer

INSYGHTS SECURITY PTE. LTD.

Singapore

On-site

SGD 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

INSYGHTS SECURITY PTE. LTD. seeks a Tier 2 SOC Analyst/Engineer to serve as the escalation point for Tier 1. You will own in-depth investigations, lead incident response activities, and drive detection engineering and threat hunting to mature the security monitoring program.

You will be a technical anchor for the SOC, translating raw alerts into incidents and lessons learned to improve detections, with collaboration across IT infrastructure, application development, and other SOC roles.

Qualifications

  • 3+ years of hands-on SOC experience with progression to Tier 2/senior responsibilities.
  • Strong understanding of attack lifecycle, MITRE ATT&CK framework.
  • Hands-on experience with SIEM platforms and writing/tuning correlation rules and queries.
  • Experience with EDR/XDR tools for endpoint investigations.
  • Solid networking knowledge and ability to read packet captures.
  • Experience with incident response processes and post-incident reporting.

Responsibilities

  • Serve as the primary escalation point for Tier 1 analysts on alerts requiring deeper analysis.
  • Conduct in-depth investigations across endpoint, network, cloud, identity, and application telemetry.
  • Correlate data across tools and logs to determine scope and impact.
  • Lead or co-lead containment, eradication, and recovery activities for incidents.
  • Design, build, test, and tune detection rules and use cases.
  • Conduct proactive threat hunts and translate findings into detections.
  • Mentor Tier 1 analysts and contribute to SOC playbooks and runbooks.

Skills

SOC analytics
Incident response
Threat hunting
Detection engineering
Scripting/automation
Communication

Tools

SIEM platforms (Splunk, Sentinel, QRadar, Elastic)
EDR/XDR tools (CrowdStrike, Defender, SentinelOne, TrendAI)

Job description

We are looking for a Tier 2 SOC Analyst/Engineer to serve as the escalation point for our Tier 1 SOC team. This role owns in-depth investigation of escalated alerts, performs root cause analysis, leads incident response activities, and drives detection engineering and threat hunting initiatives to continuously mature our security monitoring program. You will be a technical anchor for the SOC - turning raw alerts into confirmed incidents, confirmed incidents into lessons learned, and lessons learned into better detections.

Department: Security Operations Center (SOC)

Reports to: SOC Manager

Works closely with: Tier 1 SOC Analysts (escalation point), Detection Engineering, IT Infrastructure, Application Development

Key Responsibilities
Escalation & Investigation
  • Serve as the primary technical escalation point for Tier 1 analysts on alerts requiring deeper analysis
  • Conduct in-depth investigations across endpoint, network, cloud, identity, and application telemetry
  • Correlate data across multiple tools/log sources (SIEM, EDR, NDR, cloud logs, identity providers) to determine scope and impact
  • Distinguish true positives from false positives and refine triage logic accordingly
Root Cause Analysis
  • Perform root cause analysis on confirmed incidents to determine initial vector, method, and any control gaps
  • Document attack timelines/kill chains and produce clear technical findings for stakeholders
  • Identify systemic issues (misconfigurations, missing patches, process gaps) surfaced during investigations
Incident Response
  • Lead or co-lead containment, eradication, and recovery activities for security incidents
  • Coordinate with IT, engineering, legal, and management during active incidents per the IR plan
  • Author incident reports, timelines, and post-incident/lessons-learned reviews
  • Support tabletop exercises and continuous improvement of IR playbooks and runbooks
Detection Engineering
  • Design, build, test, and tune detection rules/use cases (SIEM correlation rules, EDR detections, Sigma rules, etc.)
  • Translate threat intel, incident findings, and threat hunt results into new or improved detections
  • Reduce alert fatigue by improving detection fidelity and eliminating noisy/low-value alerts
  • Map detections to a framework such as MITRE ATT&CK to identify and close coverage gaps
Threat Hunting
  • Conduct proactive, hypothesis-driven threat hunts using threat intelligence, ATT&CK TTPs, and anomaly analysis
  • Identify indicators of compromise or adversary behavior not caught by existing detections
  • Convert hunt findings into new detection logic and share findings with the broader team
Mentorship & Process
  • Mentor and provide technical guidance to Tier 1 analysts, including escalation reviews and knowledge transfer
  • Contribute to and maintain SOC playbooks, runbooks, and standard operating procedures
  • Support onboarding of new log sources, tools, and data feeds into the SOC's monitoring scope
  • Participate in an on-call/escalation rotation as needed
Required Qualifications
  • 3+ years of hands-on SOC experience, with demonstrated progression into Tier 2/senior analyst responsibilities
  • Strong understanding of the attack lifecycle, common TTPs, and the MITRE ATT&CK framework
  • Hands-on experience with SIEM platforms (e.g., Splunk, Sentinel, QRadar, Elastic) - writing/tuning correlation rules and queries
  • Experience with EDR/XDR tools (e.g., CrowdStrike, Microsoft Defender, SentinelOne, TrendAI) for endpoint investigation
  • Solid grasp of networking fundamentals (TCP/IP, DNS, HTTP/S, proxies) and ability to read packet captures
  • Experience with incident response processes: containment, eradication, recovery, and post-incident reporting
  • Familiarity with cloud security monitoring (AWS/Azure/GCP logs, IAM, CloudTrail or equivalent)
  • Scripting/automation skills (Python, PowerShell, or similar) for detection logic, parsing, or workflow automation
  • Excellent written and verbal communication skills - able to translate technical findings for non-technical stakeholders
  • Ability to remain calm and methodical under pressure during active incidents
Preferred Qualifications
  • Certifications such as GCIH, GCIA, GCFA, CySA+, OSCP, or equivalent
  • Experience writing Sigma, YARA, or Snort/Suricata rules
  • Experience with SOAR platforms for playbook automation
  • Familiarity with digital forensics tools and techniques (memory/disk forensics)
  • Experience with threat intelligence platforms and integrating IOC feeds
  • Prior experience mentoring or training junior analysts
What Success Looks Like
  • Reduced mean-time-to-detect (MTTD) and mean-time-to-respond (MTTR) for escalated incidents
  • Measurable improvement in detection coverage against ATT&CK techniques relevant to the organization
  • A steady cadence of proactive threat hunts with documented findings and resulting detections
  • Well-documented incidents with clear root cause and remediation tracking
  • Stronger, more capable Tier 1 team through consistent mentorship and escalation feedback
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity SOC Manager
Cybersecurity SOC Manager

NETWORK FOR ELECTRONIC TRANSFERS (SINGAPORE) PTE LTD • Singapore

On-site
SGD 120,000 - 180,000
L3 SOC analyst & SOC Manager
L3 SOC analyst & SOC Manager

INSYGHTS SECURITY PTE. LTD. • Singapore

On-site
SGD 120,000 - 160,000
Senior Analyst, Threat Detection and Response
Senior Analyst, Threat Detection and Response

SATS Ltd. • Singapore

On-site
SGD 90,000 - 130,000
Cybersecurity SOC Manager
Cybersecurity SOC Manager

NETS • Singapore

On-site
SGD 120,000 - 240,000
Senior SOC Analyst: Incident Response & Threat Hunting
Senior SOC Analyst: Incident Response & Threat Hunting

INSYGHTS SECURITY PTE. LTD. • Singapore

On-site
SGD 90,000 - 130,000
SOC Security Analyst: Threat Detection & Response
SOC Security Analyst: Threat Detection & Response

Gruve • Singapore

On-site
SOC Security Analyst
SOC Security Analyst

Gruve • Singapore

On-site
SGD 70,000 - 110,000
Cyber Monitoring Analyst (Tier 2)
Cyber Monitoring Analyst (Tier 2)

STEFANINI SINGAPORE PTE. LTD. • Singapore

On-site
SGD 70,000 - 100,000
Senior Lead Detection Engineer (Threat Hunting, Intel & Use Case Management)
Senior Lead Detection Engineer (Threat Hunting, Intel & Use Case Management)

NetS • Singapore

On-site
SGD 150,000 - 230,000
Security Analyst L2
Security Analyst L2

ENSIGN INFOSECURITY (CYBERSECURITY) PTE. LTD. • Singapore

On-site
SGD 70,000 - 95,000