Skip to content

Open nowPosted 10 days ago

Tier 2 SOC Analyst / Engineer

MyCareersFuture94,028 open roles

Pay
SGD 4,000 – SGD 5,000 a month
Where
Central, Singapore
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowTier 2 SOC Analyst / EngineerMyCareersFuture · Central, Singapore
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on MyCareersFuture's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.7% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.3%3 days
  3. 7.7%7 days
  4. 14.0%14 days
  5. 33.7%30 days
This job: posted 10 days ago

The posting

We are looking for a Tier 2 SOC Analyst/Engineer to serve as the escalation point for our Tier 1 SOC team. This role owns in-depth investigation of escalated alerts, performs root cause analysis, leads incident response activities, and drives detection engineering and threat hunting initiatives to continuously mature our security monitoring program. You will be a technical anchor for the SOC — turning raw alerts into confirmed incidents, confirmed incidents into lessons learned, and lessons learned into better detections.

Department: Security Operations Center (SOC)

Reports to: SOC Manager

Works closely with: Tier 1 SOC Analysts (escalation point), Detection Engineering, IT Infrastructure, Application Development

## Key Responsibilities

**Escalation & Investigation**

- Serve as the primary technical escalation point for Tier 1 analysts on alerts requiring deeper analysis

- Conduct in-depth investigations across endpoint, network, cloud, identity, and application telemetry

- Correlate data across multiple tools/log sources (SIEM, EDR, NDR, cloud logs, identity providers) to determine scope and impact

- Distinguish true positives from false positives and refine triage logic accordingly

**Root Cause Analysis**

- Perform root cause analysis on confirmed incidents to determine initial vector, method, and any control gaps

- Document attack timelines/kill chains and produce clear technical findings for stakeholders

- Identify systemic issues (misconfigurations, missing patches, process gaps) surfaced during investigations

**Incident Response**

- Lead or co-lead containment, eradication, and recovery activities for security incidents

- Coordinate with IT, engineering, legal, and management during active incidents per the IR plan

- Author incident reports, timelines, and post-incident/lessons-learned reviews

- Support tabletop exercises and continuous improvement of IR playbooks and runbooks

**Detection Engineering**

- Design, build, test, and tune detection rules/use cases (SIEM correlation rules, EDR detections, Sigma rules, etc.)

- Translate threat intel, incident findings, and threat hunt results into new or improved detections

- Reduce alert fatigue by improving detection fidelity and eliminating noisy/low-value alerts

- Map detections to a framework such as MITRE ATT&CK to identify and close coverage gaps

**Threat Hunting**

- Conduct proactive, hypothesis-driven threat hunts using threat intelligence, ATT&CK TTPs, and anomaly analysis

- Identify indicators of compromise or adversary behavior not caught by existing detections

- Convert hunt findings into new detection logic and share findings with the broader team

**Mentorship & Process**

- Mentor and provide technical guidance to Tier 1 analysts, including escalation reviews and knowledge transfer

- Contribute to and maintain SOC playbooks, runbooks, and standard operating procedures

- Support onboarding of new log sources, tools, and data feeds into the SOC's monitoring scope

- Participate in an on-call/escalation rotation as needed

## Required Qualifications

- 3+ years of hands-on SOC experience, with demonstrated progression into Tier 2/senior analyst responsibilities

- Strong understanding of the attack lifecycle, common TTPs, and the MITRE ATT&CK framework

- Hands-on experience with SIEM platforms (e.g., Splunk, Sentinel, QRadar, Elastic) — writing/tuning correlation rules and queries

- Experience with EDR/XDR tools (e.g., CrowdStrike, Microsoft Defender, SentinelOne, TrendAI) for endpoint investigation

- Solid grasp of networking fundamentals (TCP/IP, DNS, HTTP/S, proxies) and ability to read packet captures

- Experience with incident response processes: containment, eradication, recovery, and post-incident reporting

- Familiarity with cloud security monitoring (AWS/Azure/GCP logs, IAM, CloudTrail or equivalent)

- Scripting/automation skills (Python, PowerShell, or similar) for detection logic, parsing, or workflow automation

- Excellent written and verbal communication skills — able to translate technical findings for non-technical stakeholders

- Ability to remain calm and methodical under pressure during active incidents

## Preferred Qualifications

- Certifications such as GCIH, GCIA, GCFA, CySA+, OSCP, or equivalent

- Experience writing Sigma, YARA, or Snort/Suricata rules

- Experience with SOAR platforms for playbook automation

- Familiarity with digital forensics tools and techniques (memory/disk forensics)

- Experience with threat intelligence platforms and integrating IOC feeds

- Prior experience mentoring or training junior analysts

## What Success Looks Like

- Reduced mean-time-to-detect (MTTD) and mean-time-to-respond (MTTR) for escalated incidents

- Measurable improvement in detection coverage against ATT&CK techniques relevant to the organization

- A steady cadence of proactive threat hunts with documented findings and resulting detections

- Well-documented incidents with clear root cause and remediation tracking

- Stronger, more capable Tier 1 team through consistent mentorship and escalation feedback

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against MyCareersFuture's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on MyCareersFuture's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    MyCareersFuture's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.