Cybersecurity Analyst Tier 2

University of Utah

Salt Lake City (UT)

On-site

USD 73,000 - 93,000

Full time

5 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

The University of Utah is seeking a Cybersecurity Analyst Tier 2 (Security Operations Center) to drive mid-tier incident investigations and act as the escalation bridge between Tier 1 monitoring and Tier 3 engineering.

You will tune detection rules with Tier 3, refine response playbooks, mentor junior analysts, and collaborate with IT, cloud, and identity teams to harden the environment.

Qualifications

  • Bachelor's degree (or equivalent) + 4 years related work experience.
  • Master's degree (or equivalent) + 2 years related work experience.
  • 4 years cybersecurity operations, threat triage, or incident response in a SOC.
  • Strong logs analysis across Windows/Linux, cloud, network, and identity platforms.
  • Practical use of MITRE ATT&CK framework in investigations and post-incident reporting.

Responsibilities

  • Perform in-depth investigations and root-cause analysis for escalated security incidents.
  • Triage and guide Tier 1 analysts during active incidents.
  • Tune detections across SIEM/EDR and cloud platforms to reduce false positives.
  • Lead post-incident reporting and improve SOC workflows.

Skills

Incident response
Threat triage
SOC operations
Log analysis
MITRE ATT&CK

Education

Bachelor's degree
Master's degree

Tools

SIEM
EDR
SOAR
Cloud platforms (AWS/Azure/GCP)
KQL
SPL
YARA

Job description

Cybersecurity Analyst Tier 2
Job Summary
Information Security Analysts

The University of Utah has an opportunity for a CybersecurityAnalyst Tier 2 (Security Operations Center) to help support ourInformation Security and Compliance goals. The Tier 2 SOC analystwill drive mid-tier incident investigations, perform root causeanalysis, and help optimize our operational capabilities. Operatingas the primary escalation bridge between Tier 1 monitoring and Tier3 engineering, you will handle complex security events, collaborateclosely with Tier 3 analysts to tune detection rules, refineresponse playbooks, and mentor junior analysts.

About UIT

University Information Technology(UIT), the central IT service provider for theUniversity of Utah, reports to the U's Chief InformationOfficer and is responsible for many of the U's sharedIT services including the wired and wireless network; CampusInformation Services (CIS) portal; UMail, telephone, and onlinecollaboration; digital learning technologies; information security;software licensing; and a host of other IT systems andservices.

About the University of Utah

Located in Salt LakeCity, the U is the flagship institution of the State of Utah'ssystem of higher education, home to arts and museumvenues and a member of the BIG-12 Conference. Skiing andsnowboarding opportunities are a short distance fromcampus, and opportunities to pursue activities from biking to hiking to fishing abound. Salt Lake City ishome to the Utah Symphony andOpera, Ballet West, professional sports teams, and a wide range ofother cultural and recreational activities.

Responsibilities
Information Security Analyst II
Incident Response:
  • Perform in-depth investigations, root cause analysis, andcontainment activities for escalated, complex, or multi-vectorsecurity incidents across endpoint, network, cloud, and identitydomains
  • Serve as the primary escalation point for Tier 1 analysts,providing technical guidance during active triage and validatingescalation quality.
  • Perform initial scoping and technical artifact analysis tosupport response actions and prevent incident propagation.
  • Draft clear, detailed incident postmortem reports and documenttechnical findings for internal stakeholders.
Detection & Playbook Optimization:
  • Partner with Tier 3 analysts to tune, refine, and update existingdetection logic across SIEM, EDR, and cloud security platforms toreduce false positives and improve alert fidelity.
  • Identify detection coverage gaps and telemetry blind spots duringinvestigations, providing actionable recommendations to Tier 3 fornew rules or detection enhancements.
  • Assist Tier 3 analysts in testing, providing feedback on, andmaintaining automated response workflows (SOAR) to streamlineroutine SOC tasks.
Threat Analysis:
  • Analyze complex adversary behavior from escalated alerts, mappingattack paths to the MITRE ATT&CK framework.
  • Assist Tier 3 analysts in executing structured, hypothesis-driventhreat hunting campaigns across corporate and cloudenvironments.
  • Operationalize threat intelligence updates by executingindicator-of-compromise (IOC) sweeps (threat hunting) andvalidating threat exposure.
Leadership & Team Support:
  • Mentor and develop Tier 1 SOC analysts through regular shifthandovers, technical guidance, and investigation peerreviews.
  • Identify operational bottlenecks and propose improvements to SOCworkflows and triage procedures.
  • Partner with internal IT and platform teams to address logginggaps and remediate host- or network-level securityweaknesses.

Job Code: P34212Grade: P17

Minimum Qualifications

EQUIVALENCY STATEMENT: 1 year of higher educationcan be substituted for 1 year of directly related work experience(Example: bachelor's degree = 4 years of directly related workexperience).

Information Security Analyst, II: Requires abachelor's (or equivalency) + 4 years or a master's (orequivalency) + 2 years of directly related work experience.

Preferences

Experience: 4 years dedicated cybersecurityoperations, threat triage, or incident response experience in a SOCenvironment.

Technical mastery: Strong expertise analyzing logsacross Windows/Linux, cloud environments (AWS, Azure, GCP), networktraffic (PCAP, NetFlow), and identity platforms (Entra ID,Okta).

Querying & Log Analysis: Proficiency usingplatform query languages (e.g. KQL, SPL, YARA) for deepinvestigation, log correlation, and evaluating ruleperformance.

Framework Alignment: Practical working knowledgeof applying the MITRE ATT&CK framework to real-worldinvestigations, triage workflows, and post-incidentreporting.

Certifications (Preferred): GCIH, GCFA, GSOC,SC-200, CCSP.

Soft Skills: Excellent analytical problem-solvingskills and a strong passion for teaching and elevating junior teammembers. A demonstrated ability to write complex technical reportsfor a non-technical audience.

Requisition Number

PRN46212B

Full Time or Part Time?

Full Time

Work Schedule Summary

Four ten hour shifts a week. Positionwill rotate between day and evening shifts to include holidays andweekends.

Department

00954 - UIT Systems & Security

Location

Campus

Pay Rate Range

$73,000.00 - 93,000.00

Close Date

09/22/2026

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Analyst Tier 2
Cybersecurity Analyst Tier 2

Utah • Salt Lake City (UT), Northern (KY)

Hybrid
USD 73,000 - 93,000
Information Security Analysts
Information Security Analysts

University of Utah • Campus (IL)

On-site
USD 73,000 - 93,000
UR retirement plan information not in
SOC Analyst II — Incident Response & Threat Hunting
SOC Analyst II — Incident Response & Threat Hunting

University of Utah • Campus (IL)

On-site
USD 73,000 - 93,000
UR retirement plan information not in
Cybersecurity SOC Analyst II: Incident Response & Mentoring
Cybersecurity SOC Analyst II: Incident Response & Mentoring

Utah • Salt Lake City (UT), Northern (KY)

Hybrid
USD 73,000 - 93,000
Information Security Analyst IV
Information Security Analyst IV

University of Utah • Salt Lake City (UT)

On-site
USD 102,000 - 117,000
Information Security Analyst
Information Security Analyst

Syracuse University • New York (NY)

On-site
USD 87,000 - 92,000
IT Security Analyst Tier 2
IT Security Analyst Tier 2

Philadelphia Comapny • Chicago (IL)

On-site
USD 70,000 - 100,000
Senior Information Security Analyst
Senior Information Security Analyst

UMass Amherst • Amherst (MA)

Hybrid
USD 120,000 - 150,000
Security Operations Center (SOC) Analyst – Tier II
Security Operations Center (SOC) Analyst – Tier II

Sunset Search LLC • Austin (TX), Northern (KY)

Hybrid
USD 85,000 - 120,000
Health benefits
401(k)
Paid certifications
+1
Security Analyst (Tier 2 SOC)
Security Analyst (Tier 2 SOC)

Tgi Main Company • West Caldwell (NJ), Cherry Hill Township (NJ), Boca Raton (FL)

On-site
USD 75,000 - 95,000
Dental insurance
Health insurance
Vision insurance
+3