Vanderlande Logo

Vanderlande

Cybersecurity Analyst – Tier 2

Posted 3 Days Ago
Be an Early Applicant
In-Office
Vancouver, BC, CAN
Senior level
In-Office
Vancouver, BC, CAN
Senior level
Leads Tier 2 SOC investigations, incident response, threat hunting, forensic analysis, malware reverse engineering, and detection-rule development. Escalates complex incidents, mentors Tier 1 analysts, coordinates containment and remediation, manages access and patch-related security activities, and produces incident reporting. The role also improves SOC processes, validates detections, applies threat intelligence and MITRE ATT&CK techniques, and supports continuous improvement in a 24/7 operational environment.
The summary above was generated by AI
Job TitleCybersecurity Analyst – Tier 2

Job Description

The Security Operations Center – Tier 2 Analyst will lead complex investigations, coordinate incident response efforts, and drive continuous improvement in threat detection and response capabilities. You will serve as a technical expert and escalation point for Tier 1 analysts, customers or other departments.  This role supports incident detection, escalation, and response activities within customer environments, in line with agreed SOC service scope and service level agreements (SLAs). You will have had previous experience in handling escalation from Tier 1 and direct work in security monitoring, threat intelligence, or incident response 


Key Responsibilities 

  • Perform advanced analysis of escalated security incidents and support investigation efforts. 
  • Act as an escalation point for Tier 1 analysts and provide expert guidance during incident response activities. 
  • Develop and tune detection rules and use cases in SIEM and other platforms. 
  • Perform threat hunting based on intelligence and behavioral analysis. 
  • Conduct forensic analysis and reverse engineering of malware when needed. 
  • Collaborate with threat intelligence teams to enrich investigations. 
  • Provide strategic recommendations to improve SOC processes and technologies. 
  • Mentor junior analysts and contribute to training programs. 
  • Participate in detection validation and lessons‑learned activities to enhance SOC detection and response. 

Additional Responsibilities 

Monitoring & Detection 

  • Validate complex alerts  escalated by Tier 1 
  • Determine scope, impact, and severity of confirmed incidents. 
  • Perform deep log analysis, forensic investigations, and develop custom detection rules. 
  • Implement containment, mitigation and remediation actions.in accordance with playbooks and customer agreements 
  • Understanding TTPs (tactics, techniques, procedures) of threat actors 
  • Ability to develop custom detection rules and correlation logic  

Investigation & Analysis 

  • Analyze data patterns and outliers to identify threat actor behaviors and insider threats.  
  • Conduct deep investigations into logs, network telemetry, and endpoint activity.  
  • Document findings, actions taken, and recommended next steps. 

Incident Response Support 

  • Assist the SOC team during active security incidents by collecting evidence and containing low‑severity threats as per playbooks. 
  • Follow established runbooks to ensure consistent and compliant response actions. 
  • Respond to escalated security incidents requiring advanced analysis.  
  • Provide containment recommendations and support remediation. 

Access Management  

  • Processing user access requests (add, remove, modify) following established workflows. 
  • Enforcing least‑privilege principles and role‑based access standards. 
  • Conducting periodic access reviews (user accounts, permissions, group memberships). 
  • Investigating and escalating suspicious access activities or unauthorized access attempts. 
     

Patch Management  

  • Assist with tracking and verifying system patch status as part of vulnerability review activities. 
  • Monitor patch‑related alerts (failed deployments, outdated versions) within security tools and coordinate remediation with IT operations. 
  • Support the vulnerability management process by validating missing patches identified during scans and escalating high‑risk findings. 
    (This is aligned with Tier 1’s documented tasks involving vulnerability scans and reporting.) 

Reporting & Communication 

  • Generate clear, accurate incident reports and daily shift summaries. 
  • Communicate event details with internal teams in a professional and timely manner. 

Continuous Improvement 

  • Recommend improvements to detection rules, response processes, and SOC procedures. 
  • Stay current on cyber threat trends, attacker techniques (TTPs), and security best practices. 

Required Qualifications 

  • 5+ years of experience in cybersecurity, with at least 2 years in a SOC or IR role. 
  • Advanced expertise in SIEM, EDR, and forensic tools. 
  • Strong understanding of MITRE ATT&CK framework and threat actor TTPs. 
  • Experience with scripting and automation (e.g., Python, PowerShell). 
  • Ability to lead and manage incident response efforts under pressure. 
  • Relevant security certifications from ISC2 or ISACA  
  • Excellent communication and leadership skills. 

Preferred Qualifications 

  • Bachelor’s degree in IT, Cybersecurity, or CS  
  • Certifications such as:  
  • CompTIA Security+ 
  • Microsoft SC-200 
  • CEH, CySA+ 
  • GIAC certifications (GSEC, GCIH, GMON) 
  • Experience with:  
  •  EDR, IDS/IPS, and network security tools 
  • SIEM/SOAR workflows/playbooks 
  • Threat intelligence platforms 

Key Competencies 

  • Strong analytical and problem‑solving skills 
  • Attention to detail 
  • Ability to work under pressure during incidents 
  • Team‑first mindset and willingness to learn 
  • Ability to recognize patterns and anomalies 
  • Prior SOC or IR experience 
  • Strong analysis and investigation skills 
  • Familiarity with threat intelligence and adversary behavior 
  • Ability to perform forensic/log analysis 
  • More advanced certifications preferred 

Work Environment 

  • 24/7 SOC environment - day shift with weekend coverage
  • Fast‑paced operational setting with tight response timelines 
  • Collaboration with cross‑functional IT and security teams 

Salary range:

This is a full-time, exempt position, eligible to receive a base salary and to participate in an annual performance bonus program. The salary range listed represents the maximum and minimum starting base pay for this position as of the time of posting. Final salary offered will be determined based on factors including but not limited to the candidate's skills and experience. The annual performance bonus program is preset and not candidate dependent.

Salary range for this position is CAD$90,000 to CAD$115,000.

Similar Jobs

2 Hours Ago
Hybrid
Richmond, BC, CAN
Senior level
Senior level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Leads design, deployment, operation, and support of secure, highly available cloud and on-premises platforms. Builds CI/CD automation, manages Azure infrastructure through IaC, operates Kubernetes and containerized workloads, and implements observability, security, compliance, and reliability practices. Provides incident response, troubleshooting, documentation, technical leadership, mentorship, architectural coordination, cloud migration planning, and cost optimization while collaborating with developers, architects, security teams, product groups, and executives.
Top Skills: AngularArgo CdAzure FunctionsAzure Kubernetes Service (Aks)Azure PolicyCoverityDockerEclipseGitGitlab Ci/CdHTMLJavaJavaScriptJIRAKubernetesLinuxAzureNode.jsOpenshiftOraclePythonReactRole-Based Access Control (Rbac)Service MeshTerraformTypescriptVersionone
4 Hours Ago
Hybrid
Metrotown, Burnaby, BC, CAN
Junior
Junior
eCommerce • Fashion • Retail • Sales • Wearables • Design
Supports store sales and operations by assisting customers, operating POS systems, handling cash, receiving and organizing shipments, replenishing merchandise, maintaining stockroom and sales-floor standards, supporting visual merchandising, and following loss-prevention policies. The role requires flexible scheduling, strong customer service, attention to detail, retail experience, and the ability to lift up to 50 pounds occasionally.
Top Skills: InternetIpadLaptopMobile PosPos SystemsWalkie-Talkie
Yesterday
In-Office or Remote
Canada
Senior level
Senior level
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Leads health technology assessment, value, and evidence strategy for Pfizer’s genitourinary oncology portfolio. Manages HEOR, real-world evidence, economic models, global value dossiers, registries, and evidence dissemination to support reimbursement and patient access. Partners with global, regional, country, and cross-functional oncology teams, oversees vendors and project teams, and communicates findings through publications and conferences.

What you need to know about the Vancouver Tech Scene

Raincouver, Vancity, The Big Smoke — Vancouver is known by many names, and in recent years, it has gained a reputation as a growing hub for both tech and sustainability. Renowned for its natural beauty, the city has become a magnet for professionals eager to create environmental solutions, and with an emphasis on clean technology, renewable energy and environmental innovation, it's attracted companies across various industries, all working toward a shared goal: advancing clean technology.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account