SOC Analyst 2 - Local tx

NexivaAustin, TX
Onsite

About The Position

This role involves active security monitoring and analysis of alerts, incident triage, investigation, and escalation per CSOC playbooks. The SOC Analyst 2 will also be responsible for SIEM rule tuning, alert optimization, and supporting detection engineering activities. A key aspect of the role is documenting actions taken and maintaining shift logs for handoff, including a mandatory handoff procedure at each shift change. Following each shift, the on-duty team will submit a detailed report summarizing all activities, including a chronological summary for each ticket handled. SOC Tier 2 Analysts act as intermediate incident responders, focusing on in-depth investigation, containment, and remediation of security threats escalated by Tier 1. They validate alerts, analyze the scope and impact of incidents using threat intelligence, and guide recovery efforts, bridging the gap between initial triage and expert-level threat hunting. Additional responsibilities include proactive security and threat management, and vulnerability management and tracking, which may involve reviewing and tracking vulnerabilities identified by scanning tools during non-business hours. This includes assessing and prioritizing vulnerabilities, updating tickets, coordinating with system owners for patching, and verifying remediation measures.

Requirements

  • Proficiency in security tools like SIEM, IDS/IPS, and threat intelligence platforms.
  • Understanding of network forensics, malware analysis, and system administration.
  • Strong analytical and problem-solving skills.

Responsibilities

  • Active security monitoring and analysis of alerts
  • Incident triage, investigation, and escalation per CSOC playbooks
  • SIEM rule tuning and alert optimization
  • Support detection engineering activities (e.g., creating and refining detection logic)
  • Document actions taken and maintain shift logs for handoff
  • Conduct forensic examinations, analyze raw logs, and correlate data from multiple sources to understand the root cause and impact of an attack.
  • Actively respond to high-priority incidents by developing and implementing strategies to contain threats (e.g., isolating systems, blocking IPs).
  • Leverage advanced threat intelligence to identify attacker behavior, mapping incidents to frameworks like MITRE ATT&CK to detect lateral movement or data exfiltration.
  • Handle complex security incidents passed from Tier 1, and escalate to Tier 3 (e.g., forensic experts) if further investigation is required.
  • Create detailed reports on findings, update documentation, and refine standard operating procedures (SOPs) or automation playbooks.
  • Proactive Security and Threat Management
  • Vulnerability Management and Tracking: During non-business hours, staff may review and track vulnerabilities identified by scanning tools. Staff can assess and prioritize these vulnerabilities based on factors such as severity, exploitability, and asset criticality. This process includes updating tickets, coordinating with system owners to facilitate patching, and verifying remediation measures.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service