Skip to content

Open nowPosted 13 hours ago

SOC Analyst (Tier 1, Tier 2 & Tier 3)

Aspenview Technology Partners58 open roles

Where
LATAM
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSOC Analyst (Tier 1, Tier 2 & Tier 3)Aspenview Technology Partners · LATAM
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Aspenview Technology Partners's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.2%30 days
This job: posted 13 hours ago

The posting

Build the Future with AspenView Technology Partners

At AspenView, we are passionate about transforming the way organizations approach technology. We specialize in creating high-performing, nearshore IT teams to help North American clients innovate faster and more efficiently.

As we continue to grow, we’re looking for exceptional people to join our team and help drive impactful change across industries.

About the Role

AspenView is building a dedicated, 24/7 Security Operations Center team for a large U.S. consumer lender in the financial services sector, and we are hiring at three levels: Tier 1 Monitoring Analysts (junior), Tier 2 Analysts and Shift Leads (mid-level), and Tier 3 Senior SOC Analysts (senior). All roles are full-time, on site in Bogotá or Buenos Aires, and dedicated to a single client, working on U.S. Eastern Time with senior leads in the United States.

Alerts arrive in ServiceNow already enriched. Tier 1 validates, classifies and escalates them following the runbook; Tier 2 decides which escalations are real and owns them through to client notification; Tier 3 takes every P1, major incident and Tier 2 request for support, scoping the impact, building the timeline, recommending containment and performing first-response forensics before the U.S.-based Incident Response Lead steps in. Incident declaration and containment execution sit with the client; the team escalates with evidence and a recommendation.

The team is built for round-the-clock coverage. Six Tier 1 analysts cover three rotating 8-hour shifts (07:00–15:00, 15:00–23:00 and 23:00–07:00) seven days a week, including nights, weekends and public holidays. Three Tier 2 analysts rotate across the day and evening shifts and share the overnight on-call. Two Tier 3 analysts work business hours and share a 24/7 on-call rotation with the Incident Response Lead. All analysts report to the on-site SOC Manager. All analysts work from AspenView's access-controlled delivery suite, which operates under a clean-desk rule with VDI-only access to the client's environment and tooling. Access to the client environment requires identity, criminal-background, employment and education checks, repeated periodically.

Tier 1 to Tier 3 is a defined career path, and detection engineering, threat hunting and incident response lead work all sit within the same team.

What You Will Do

Tier 1 – Monitoring

  • Own the live alert queue: acknowledgement, validation, classification and prioritization against the agreed severity matrix.
  • Check enrichment and pull additional context from Elastic, CrowdStrike, Microsoft Defender and Okta before making a call, and work runbooks for common alert types such as reported phishing, malware detections, risky or impossible-travel sign-ins and policy violations.
  • Deliver clean escalations to the Tier 2 shift lead, keep audit-ready ServiceNow ticket records, and write shift handovers covering open cases.
  • Serve as the only analyst on the console during night shifts, with Tier 2 and Tier 3 on call, and judge when to wake them.

Tier 2 – Shift Lead

  • Run the day or evening shift: who is working what, what is open, and a written handover the next shift acknowledges before you leave.
  • Own every escalation raised on your shift, from investigation through to client notification, plus overnight escalations when on call.
  • Investigate validated or ambiguous alerts, correlating Elastic, CrowdStrike, Microsoft Defender, Okta and AWS logs to reach a call you can defend, and document hypothesis, evidence, reasoning and disposition in ServiceNow.
  • Escalate to Tier 3 with scope, evidence and a working hypothesis, coach Tier 1 analysts, and provide tuning feedback to Detection Engineering on noisy or missed rules.

Tier 3 – Senior Analyst

  • Own P1 cases, major incidents and Tier 2 requests for support: scoping what is affected, building the timeline, and giving the client the evidence it needs to decide whether to declare an incident.
  • Write evidence-backed containment recommendations for the client's teams to execute.
  • Perform first-response DFIR: endpoint triage in CrowdStrike and Microsoft Defender, memory and disk artifacts, Okta session analysis and AWS log review, with evidence preserved properly, working across Abstract Security, Elastic and ServiceNow.
  • Hold escalation authority over Tier 2, review and coach their work, produce incident write-ups for the client's security leadership, and feed detection gaps back to Detection Engineering.

What You Bring

Education

  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems or a related field, or equivalent hands-on experience (all levels).

Experience

  • All levels: English strong enough to escalate, brief and write reports for a U.S. security team without an intermediary (B2 or above), and willingness to work the shift or on-call pattern for your level.
  • Tier 1: Early-career professional with hands-on exposure to security monitoring through a SOC, a NOC with security duties, or a serious lab or CTF record.
  • Tier 2: Several years of SOC or security investigation work beyond triage, having closed incidents rather than only escalated them, plus experience leading a shift or owning escalations end to end.
  • Tier 3: Several years in security operations or incident response, with an incident you can walk through end to end, and the judgment to recommend containment that stops an attacker without breaking the systems the business runs on.

Technical Expertise

  • Tier 1: Log fundamentals (reading Windows events, authentication logs and proxy logs) and triage discipline: following a runbook exactly and noticing when an alert does not fit it.
  • Tier 2: Querying logs directly in a SIEM (Elastic, Splunk, Microsoft Sentinel, QRadar or equivalent), joining evidence across endpoint, identity and cloud sources, and solid fundamentals in Windows event logs, SSO and MFA flows, and phishing and malware patterns mapped to MITRE ATT&CK.
  • Tier 3: Investigation in a production SIEM or log platform, writing your own queries, and working knowledge of Windows, Linux and identity attack paths (credential theft, session and token abuse, lateral movement, privilege escalation) mapped to MITRE ATT&CK.

Certifications

  • Tier 1: Security+, CySA+, SC-200, BTL1, CCNA CyberOps or similar (preferred).
  • Tier 2: CySA+, GCIA, GCIH, BTL1, SC-200 or Security+ (preferred).
  • Tier 3: GCIH, GCFA, GCIA, CySA+, BTL2 or OSCP (preferred).

Nice to Have

  • Elastic query languages (EQL, ES|QL, KQL), Abstract Security, ServiceNow or ServiceNow SecOps.
  • EDR consoles such as CrowdStrike Falcon, Microsoft Defender or SentinelOne.
  • Identity and cloud investigation in Okta or Entra ID and AWS (CloudTrail, GuardDuty, VPC flow logs) or Azure equivalents.
  • Email and network evidence from Proofpoint and Palo Alto, or equivalents.
  • Basic scripting (Python, PowerShell), SOAR playbooks, or GenAI-assisted triage tools and knowing when not to trust them.
  • Forensic tooling (Velociraptor, KAPE, Volatility, Autopsy) and malware triage or basic reverse engineering (Tier 3).
  • Experience in banking, payments or another regulated sector, ideally with a feel for PCI DSS, GLBA or NYDFS evidence expectations.

Visa Sponsorship

AspenView does not sponsor employment visas for this role. Applicants must be permanently authorized to work in their country of residence and must not require visa sponsorship now or in the future.

Equal Opportunity Employer

AspenView is proud to be an equal opportunity employer. We believe in creating an environment where all employees feel welcome, valued, and empowered to succeed. We celebrate diversity and strive to build a culture of inclusion where all individuals, regardless of their race, color, gender, gender identity or expression, sexual orientation, disability, age, or any other characteristic, can thrive. We encourage applicants from all walks of life to join our team and make a lasting impact.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Aspenview Technology Partners's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Aspenview Technology Partners's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Aspenview Technology Partners's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.