PitchMeAI
PitchMeAI
Home›Jobs›SOC Security Analyst L2
BlueVoyant

SOC Security Analyst L2

BlueVoyant · NAMER

  • Hybrid
  • Full-time
  • $100,000 / year
  • NAMER

Job highlights

  • Analyze security events and alerts globally.
  • Investigate and remediate cyber threats.
  • Serve as technical escalation point.
  • Mentor junior analysts and support clients.
  • Improve security processes and technology.

About the role

SOC Security Analyst L2

BlueVoyant is seeking a Security Operations Center (SOC) Security Analyst L2 to help global customers manage and improve their cybersecurity posture. You will work in a fast-paced environment focused on minimizing the impact of security incidents and ensuring critical business operations remain uninterrupted.

As a senior analyst, you serve as the technical expert and escalation point for junior analysts. Your deep understanding of modern attacks, intrusion data analysis, and remediation techniques ensures that threats are identified, escalated, and remediated with urgency and precision. You will mentor junior team members, support customers directly, and contribute to ongoing process and technology improvements.

Key Responsibilities:

  • Ensure the safety and security of customer environments through expert analysis, escalation handling, and effective communication.
  • Monitor and analyze security events and alerts from SIEM platforms, endpoint logs, network telemetry, and EDR tools.
  • Research indicators of compromise (IOCs) and malicious activity to determine reputation and risk.
  • Conduct malware analysis, attacker infrastructure investigation, and forensic analysis.
  • Execute complex investigations and declare incidents when appropriate.
  • Perform live response and remote forensics on compromised endpoints.
  • Conduct threat hunting activities based on behavioral anomalies and curated intelligence.
  • Participate in and support incident response, investigation, and documentation.
  • Collaborate closely with BlueVoyant Incident Response teams during active intrusions.
  • Ensure events are accurately identified, analyzed, escalated, and documented.
  • Identify and tune false positives and benign detections.
  • Perform peer reviews and QA checks on junior analysts’ investigations.
  • Mentor lower-level analysts and act as the technical escalation point.
  • Communicate regularly with clients regarding incidents, findings, and remediation steps.
  • Support Customer Success teams during client engagements as required.
  • Assist in improving security policies, procedures, tooling, and automation.

Basic Qualifications:

People Skills
  • Ability to remain calm and effective in high-pressure security incident situations.
  • Ability to work directly with customers to gather requirements and provide feedback on security services.
  • Strong written and verbal communication skills with the ability to translate complex technical concepts into clear, understandable language.
  • Strong teamwork and interpersonal skills; comfortable working with a globally distributed team.
  • Willingness and ability to work a 24/7/365 rotating shift schedule.
Technical Skills
  • Experience using SIEM solutions, Cloud App Security tools, and EDR platforms.
  • Advanced understanding of network protocols and network telemetry.
  • Knowledge of Windows and Unix forensic artifacts and analysis methods.
  • Expertise in endpoint, web, and authentication log analysis.
  • Experience creating SIEM/EDR detections.
  • Experience responding to modern authentication attacks (AD, Entra, OATH, etc.).
  • Deep knowledge of common attack paths, including LOLBins, adversary tools, BEC attacks, AiTM, and lateral movement techniques.
  • Strong knowledge of: SIEM workflows (preferably Microsoft Sentinel or Splunk), Modern authentication systems and attacks (SSO, OATH, Entra), Malware detection and analysis (dynamic and light static), Network and firewall logs, IDS/WAF, web traffic logs, Email security and BEC attack methodologies, Windows and Unix forensic artifacts (registry, wtmp/btmp, etc.), Windows PE and malicious document analysis, Legitimate and malicious remote access methods, O365 attack paths and common adversary techniques, Network metadata and commonly abused protocols, Credential harvesting tools and methodologies.
  • Experience countering ransomware threat actors (preferred).

Preferred Qualifications:

  • Experience in intrusion analysis, incident response, digital forensics, penetration testing, or similar fields.
  • 3+ years of hands-on SOC/TOC/NOC experience.
  • GIAC certification(s) strongly preferred.
  • Additional certifications such as CISSP, Security+, Network+, CEH, RHCA, RHCE, MCSA, MCP, MCSE.
  • Familiarity with tools such as Microsoft Sentinel, Splunk, Microsoft Defender suite, CrowdStrike Falcon, SentinelOne.
  • Familiarity with GPO, LANDesk, or other IT infrastructure tools.
  • Experience with one or more programming languages (JavaScript, Python, Lua, Ruby, Go, Rust).

Education:

Bachelor’s degree in Information Security, Computer Science, or related IT field, or equivalent experience.

About BlueVoyant:

BlueVoyant is an AI-driven cybersecurity company dedicated to standing between our customers and cyber threats. By combining human, artificial, and proprietary intelligence, we deliver a unified solution that protects every organization’s network, identities, vendors, and digital footprints as a single attack surface. The company’s award-winning Microsoft Security expertise helps organizations maximize their security investments while reducing risk and ensuring compliance.

Led by CEO, John Hernandez, BlueVoyant’s highly skilled team includes former government cyber officials with extensive frontline experience in responding to advanced cyber threats on behalf of the National Security Agency, Federal Bureau of Investigation, Unit 8200, and GCHQ, together with private sector experts. BlueVoyant services utilize large real-time datasets with industry leading analytics and technologies.

Founded in 2017 by Fortune 500 executives, including Chairman of the Board, Jim Rosenthal, Vice Chairman, Tom Glocer, and former Government cyber officials, BlueVoyant is headquartered in New York City and has offices in Maryland, Tel Aviv, San Francisco, London, Budapest, and Latin America and is committed to building a workplace where talented people are empowered to do their best work in the fight against global cyber threats.

Important Information for Applicants:

BlueVoyant uses AI-assisted tools within our applicant tracking system to help identify candidates whose experience and skills best match the requirements of a role. This technology provides hiring teams with added insights to support fair and efficient hiring decisions. All applications are reviewed by a member of our hiring team, and final hiring decisions are made by humans, not AI. By submitting your application, you acknowledge that AI tools may assist in the evaluation of your resume as part of the recruitment process.

While we embrace the use of AI within our business and recruitment process, we do not permit its use during interviews. Any suspected use of AI during an interview will be challenged, and this may include the use of detection tools.

For more information on how we process your personal data, please review our Candidate Privacy Notice available at https://www.bluevoyant.com/candidate-privacy-notice.

All employees must be authorized to work in the United States of America. BlueVoyant provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, or genetics. In addition to federal law requirements, BlueVoyant complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities.

Disclaimer: Please note that pursuant to contractual requirements and applicable law, in order for employees to perform work on some of the company’s federal contracts, U.S. citizenship is required. Accordingly, an employee’s ability to perform work on such contracts is contingent upon the company’s verification of the employee’s citizenship status.

Key skills/competency:

  • SOC Security Analyst
  • SIEM
  • EDR
  • Incident Response
  • Threat Hunting
  • Malware Analysis
  • Forensic Analysis
  • Network Protocols
  • Cybersecurity
  • Cyber Threat Intelligence

Skills & topics

  • SOC Security Analyst
  • Cybersecurity
  • SIEM
  • EDR
  • Incident Response
  • Threat Hunting
  • Malware Analysis
  • Forensic Analysis
  • Network Security
  • Information Security
  • Security Operations Center
  • Remote Work
  • US Citizenship
  • BlueVoyant
  • Analyst

How to get hired

  • Tailor your resume: Highlight your SOC, SIEM, EDR, incident response, and threat hunting experience. Quantify achievements where possible.
  • Showcase technical expertise: Emphasize your knowledge of network protocols, malware analysis, and modern attack techniques in your application.
  • Demonstrate people skills: Prepare examples of how you handle high-pressure situations and communicate technical information clearly.
  • Research BlueVoyant: Understand their AI-driven approach and commitment to cybersecurity for global clients.
  • Prepare for interviews: Be ready to discuss technical scenarios and your approach to incident investigation and escalation.

Technical preparation

Master SIEM/EDR platforms like Sentinel/Splunk.,Practice forensic analysis on Windows/Unix.,Study common attack vectors and IOCs.,Prepare for malware analysis scenarios.

Behavioral questions

How do you handle high-pressure incidents?,Describe translating technical findings clearly.,How do you collaborate with a distributed team?,How do you mentor junior colleagues?

Frequently asked questions

What is the work arrangement for the SOC Security Analyst L2 role at BlueVoyant?
This SOC Security Analyst L2 position at BlueVoyant is a remote role within the United States. It requires a specific shift schedule from Wednesday to Saturday, with available night shift options.
What are the primary responsibilities of a SOC Security Analyst L2 at BlueVoyant?
The primary responsibilities include monitoring and analyzing security events, researching indicators of compromise, conducting malware and forensic analysis, performing live response, threat hunting, and acting as a technical escalation point for junior analysts.
What technical skills are essential for the SOC Security Analyst L2 position?
Essential technical skills include experience with SIEM solutions, EDR platforms, advanced understanding of network protocols, forensic analysis of Windows and Unix systems, log analysis, and knowledge of modern attack paths and authentication systems.
Does BlueVoyant use AI in their hiring process for the SOC Security Analyst L2 role?
Yes, BlueVoyant uses AI-assisted tools in their applicant tracking system to help identify candidates whose experience and skills match the role requirements. However, all applications are reviewed by a human hiring team, and final decisions are made by humans.
What are the work authorization requirements for the SOC Security Analyst L2 position?
U.S. Citizenship is required for this SOC Security Analyst L2 position due to potential contractual requirements with federal clients. All employees must be authorized to work in the United States.
What kind of certifications are preferred for the SOC Security Analyst L2 role?
GIAC certifications are strongly preferred. Additional certifications like CISSP, Security+, Network+, CEH, RHCA, RHCE, MCSA, MCP, or MCSE are also beneficial.
What is the expected educational background for a SOC Security Analyst L2 at BlueVoyant?
A Bachelor’s degree in Information Security, Computer Science, or a related IT field is preferred, or equivalent work experience will be considered.
What are the 'people skills' emphasized for this SOC Security Analyst L2 role?
Key people skills include the ability to remain calm under pressure, strong communication to translate technical concepts, teamwork in a distributed environment, and the ability to gather customer requirements and provide feedback.