JobRaahGet matched free

Jobs

SOC Analyst, Tier 2

Aspenview Technology Partners · LATAM

Posted Sep 17, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

Build the Future with AspenView Technology Partners At AspenView, we are passionate about transforming the way organizations approach technology. We specialize in creating high-performing, nearshore IT teams to help North American clients innovate faster and more efficiently. As we continue to grow, we’re looking for exceptional people to join our team and help drive impactful change across industries. Why Join AspenView? At AspenView, we’re more than a nearshore IT partner—we’re a people-first, purpose-driven company that believes great culture drives great outcomes. We’re passionate about connecting talent and technology to deliver measurable value for clients—and meaningful career paths for our people. Here’s what you can expect: Competitive base Flexible work model: hybrid, remote, or in-office Real growth opportunities and leadership visibility Inclusive, respectful culture that blends U.S. innovation with Colombian heart A company that listens, invests in you, and celebrates wins together The Tier 2 SOC Analyst is a senior escalation point and operational leader within the security operations team, serving a US higher-education client . You take what Tier 1 escalates, scope the incident, execute containment within your authority, and make the critical call on when to wake a client's dedicated security engineer . Moving beyond simply processing a queue, you will actively tune detection rules to eliminate noise, ensuring the queue is trusted and accurate . This role offers protected time to improve detection content and serves as a natural progression path toward a dedicated client-facing engineering role . What you will do: Incident Escalation & Containment Own escalations from Tier 1, taking responsibility for scoping, enrichment, and deciding if an event constitutes a true incident . Execute containment actions (host isolation, account disablement, edge blocking) following client rules of engagement, balancing swift action with the judgment to not break production environments . Manage the handover process and make the decision to wake the client's dedicated engineer when necessary . Produce incident write-ups that are clear and accessible enough for a client CIO to read without a translator . Detection Engineering & Mentorship Improve detection content by tuning rules, cutting false positives, and proposing new analytics to close visibility gaps . Coach and mentor Tier 1 analysts, treating their escalation quality as a direct reflection of your output . Tools & Technologies: SIEM: Microsoft Sentinel in depth, including writing and tuning analytics rules in KQL . Cloud Security: Entra ID and identity attack paths (OAuth consent abuse, token theft, privilege escalation) . Automation (Bonus): SOAR playbooks, Logic Apps, Python . What you bring: Experience: Four or more years in security operations, with genuine escalation ownership rather than just accumulating queue time…