Skip to main content
AlphaSense

Security Operations Analyst II

RemoteCanada, United States only
Published
Role
Security
Experience
Mid
Employment
Full-time
Salary not disclosed
Check eligibility

Open to CA, US only. Set where you work from to check your eligibility.

No BS summary

Security Operations Analyst II for AlphaSense, fully remote in Canada, must be able to work in Pacific time zone. Requires 2-4+ years SOC experience, solid MITRE ATT&CK knowledge, EDR and SIEM familiarity, and strong written communication. You'll own triage, investigations, and incident response support.

Core skills

EDRSIEM

Required skills

MITRE ATT&CKTCP/IPDNSHTTP/STLSAWS/GCPOkta/Entra ID

Optional skills

CrowdStrike FalconSentinelOneGoogle SecOpsChronicleMicrosoft SentinelWizPrisma CloudCloudTrail

What you'll do

  • Monitor and triage alerts across endpoint, network, cloud, runtime and identity data sources with accuracy and appropriate urgency
  • Perform structured investigations on escalated or ambiguous alerts: pivot across log sources, correlate events, and build a coherent timeline
  • Classify alerts correctly — true positive, false positive, or benign — with documented rationale, not just a verdict
  • Identify scope and blast radius on confirmed incidents: affected users, systems, and data before escalating or containing
  • Escalate to senior analysts with a complete investigation package — context, evidence, timeline, and a hypothesis
  • Participate in active incident response under senior analyst or manager direction: evidence collection, log pulls, timeline reconstruction
  • Execute containment actions — endpoint isolation, account suspension, token revocation — as directed with documented rationale
  • Maintain accurate and timely case documentation throughout the incident lifecycle
  • Contribute to post-incident timelines and assist with root cause documentation
  • Monitor cloud audit logs and native threat detection findings for suspicious IAM activity, unusual API calls, and access anomalies
  • Investigate identity provider events: suspicious logins, MFA bypass attempts, session anomalies, and unauthorized app assignments
  • Recognize common cloud-native attack patterns: credential abuse via metadata service, privilege escalation via IAM role assumption, and storage misconfiguration access
  • Correlate cloud-side events with endpoint and network telemetry to build a fuller picture of attacker activity
  • Flag false positives and noisy detections with enough context for a senior analyst or detection engineer to tune them
  • Identify gaps in existing detection coverage based on alert patterns you observe during triage
  • Apply knowledge of MITRE ATT&CK to label attacker techniques and communicate findings consistently
  • Contribute to runbook accuracy by flagging outdated steps or missing guidance encountered during investigations
  • Participate with Detections Engineers to build detections and contribute to automating activity with an Engineering mindset
  • Write clear, concise case notes that a colleague could pick up mid-investigation without needing to re-investigate from scratch
  • Produce shift handoff summaries that accurately represent open cases, pending actions, and investigation status
  • Communicate incident updates to the Security Operations Manager with sufficient clarity to brief upward without re-investigation

What they require

  • 2–4+ years of hands-on experience in a SOC, or security operations role with direct alert triage responsibility
  • Solid understanding of the MITRE ATT&CK framework — you use it to label and communicate attacker behavior, not just reference it
  • Working knowledge of EDR tooling: process tree analysis, behavioral detection review, and basic endpoint artifact interpretation
  • Familiarity with SIEM-based investigation: querying logs, correlating events across sources, and building timelines from normalized data
  • Understanding of foundational network protocols (TCP/IP, DNS, HTTP/S, TLS) and how attackers abuse them
  • Exposure to cloud security monitoring ex. AWS or GCP — including audit log review and IAM-related alert investigation
  • Experience investigating identity-based alerts in an enterprise identity provider (e.g., Okta, Entra ID, or equivalent)
  • Strong written communication: your case notes are accurate, structured, and useful to someone who wasn’t there

Benefits

  • Remote within Canada
  • Able to work in the Pacific time zone

AlphaSense delivers AI-driven market intelligence and search built on public and private content including equity research, company filings, event transcripts, expert calls, news, trade journals, and clients’ own research content.

🇺🇸 United StatesTechnologyEnterprisealphasense.net/
Salary not disclosed