Tier 2 Security Operations Analyst

Ostra SecurityMN, MN
$95,000 - $120,000Remote

About The Position

As a Tier 2 Security Operations Analyst, you are the investigative backbone of Ostra's managed SOC. You take ownership of escalated alerts and incidents across our clients' environments, driving them from detection through root-cause analysis and containment. You go beyond triage: you dig into endpoint, network, and log data to determine what happened, how far it reached, and what to do next—then you translate those findings into clear guidance for clients and durable detections for the team. This is a multi-tenant role. You will work across many client environments, prioritize based on risk and service-level agreements (SLAs), and communicate effectively with both technical and non-technical stakeholders. You will also mentor Tier 1 analysts, sharpen our detection and response playbooks, and serve as an escalation point during on-call rotations.

Requirements

  • 3–5 years of hands-on experience as a SOC analyst, incident responder, or security-focused network analyst, ideally in a fast-paced or multi-client environment.
  • Demonstrated experience investigating and escalating security incidents beyond initial triage—establishing root cause, scope, and impact.
  • Working knowledge of TCP/IP and common network protocols, Windows event logs, nix audit logs, and IDS/IPS alerting.
  • Hands-on experience with core security tooling categories: SIEM, SOAR, EDR/XDR, next-generation firewalls (NGFW), IDS/IPS, HIDS/HIPS, antivirus, and vulnerability scanners.
  • Proficiency with at least one SIEM query language and the ability to build, tune, and troubleshoot detections.
  • Proficiency in at least one common scripting language (PowerShell, Bash, Python, or similar) to automate analysis and response.
  • Solid understanding of the MITRE ATT&CK framework and experience building use cases and SOPs around relevant TTPs.
  • Familiarity with the NIST Cybersecurity Framework and the ability to apply its principles in practice.
  • Strong technical writing skills—able to document processes, procedures, and incident findings clearly for varied audiences.
  • Excellent problem-solving skills and comfort working through ambiguity and incomplete information.
  • Self-motivated, dependable, and able to deliver end-to-end results in a high-tempo environment.
  • Bachelor's degree in a related field, or equivalent practical experience.
  • Willingness to participate in a rotating on-call schedule and provide off-hours support as needed.

Nice To Haves

  • Prior experience at a managed security service provider (MSSP) or in a multi-tenant SOC.
  • Relevant certifications (preferred, not required): CompTIA Security+, CompTIA CySA+, GIAC (GCIH, GCIA, GCFA), or CISSP.
  • Cloud security experience across AWS, Azure, Google Cloud, and/or Microsoft 365.
  • Experience developing new detection use cases and SOAR automations from scratch.
  • Experience working with a geographically distributed team across multiple time zones.
  • Expert-level understanding of common and emerging security threats, vulnerabilities, and attacker tradecraft.

Responsibilities

  • Investigate & classify incidents. Own escalated alerts and incidents across client environments; classify them, determine severity, and analyze data and systems to establish cause, scope, and impact.
  • Lead response & containment. Act as an incident handler for sensitive and need-to-know incidents, applying CSIRT best practices and Ostra's incident response model; coordinate with clients and external parties to drive incidents to closure.
  • Threat hunt. Proactively hunt for novel and evasive threats using sound hunt methodology.
  • Engineer & tune detections. Understand, monitor, and optimize SIEM detection rules and SOAR playbooks; continuously improve detection accuracy, reduce false positives, and accelerate or automate response.
  • Author & maintain playbooks. Develop, document, and maintain playbooks and standard operating procedures (SOPs) for recurring incidents and tasks so the SOC can respond consistently and quickly.
  • Produce & apply threat intelligence. Ingest threat data from open and closed sources, correlate it against client context to produce actionable intelligence, and take appropriate action to mitigate risk.
  • Communicate with clients. Clearly explain technical findings, risk, and recommended actions to client stakeholders; deliver timely, well-written incident updates and reports within SLA.
  • Mentor Tier 1 analysts. Guide and upskill Tier 1 analysts, review their work, and help raise the overall quality and speed of the SOC.
  • Improve continuously. Refine processes and procedures to improve speed and accuracy, and contribute to a culture of measurable improvement.
  • Provide on-call escalation. Serve as an escalation point during a rotating on-call schedule, supporting a global SOC and off-hours coverage as required by the business.

Benefits

  • Competitive pay
  • Comprehensive benefits
  • Professional growth opportunities
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service