Cybersecurity Analyst – Tier 2

Posted 9 Hours Ago
Be an Early Applicant
Vancouver, BC, CAN
In-Office
90K-115K Annually
Senior level
Logistics • Other • Software
The Role
Leads Tier 2 SOC investigations, incident response, threat hunting, forensic analysis, malware reverse engineering, and detection-rule development. Escalates complex incidents, mentors Tier 1 analysts, coordinates containment and remediation, manages access and patch-related security activities, and produces incident reporting. The role also improves SOC processes, validates detections, applies threat intelligence and MITRE ATT&CK techniques, and supports continuous improvement in a 24/7 operational environment.
Summary Generated by Built In
Job TitleCybersecurity Analyst – Tier 2

Job Description

The Security Operations Center – Tier 2 Analyst will lead complex investigations, coordinate incident response efforts, and drive continuous improvement in threat detection and response capabilities. You will serve as a technical expert and escalation point for Tier 1 analysts, customers or other departments.  This role supports incident detection, escalation, and response activities within customer environments, in line with agreed SOC service scope and service level agreements (SLAs). You will have had previous experience in handling escalation from Tier 1 and direct work in security monitoring, threat intelligence, or incident response 


Key Responsibilities 

  • Perform advanced analysis of escalated security incidents and support investigation efforts. 
  • Act as an escalation point for Tier 1 analysts and provide expert guidance during incident response activities. 
  • Develop and tune detection rules and use cases in SIEM and other platforms. 
  • Perform threat hunting based on intelligence and behavioral analysis. 
  • Conduct forensic analysis and reverse engineering of malware when needed. 
  • Collaborate with threat intelligence teams to enrich investigations. 
  • Provide strategic recommendations to improve SOC processes and technologies. 
  • Mentor junior analysts and contribute to training programs. 
  • Participate in detection validation and lessons‑learned activities to enhance SOC detection and response. 

Additional Responsibilities 

Monitoring & Detection 

  • Validate complex alerts  escalated by Tier 1 
  • Determine scope, impact, and severity of confirmed incidents. 
  • Perform deep log analysis, forensic investigations, and develop custom detection rules. 
  • Implement containment, mitigation and remediation actions.in accordance with playbooks and customer agreements 
  • Understanding TTPs (tactics, techniques, procedures) of threat actors 
  • Ability to develop custom detection rules and correlation logic  

Investigation & Analysis 

  • Analyze data patterns and outliers to identify threat actor behaviors and insider threats.  
  • Conduct deep investigations into logs, network telemetry, and endpoint activity.  
  • Document findings, actions taken, and recommended next steps. 

Incident Response Support 

  • Assist the SOC team during active security incidents by collecting evidence and containing low‑severity threats as per playbooks. 
  • Follow established runbooks to ensure consistent and compliant response actions. 
  • Respond to escalated security incidents requiring advanced analysis.  
  • Provide containment recommendations and support remediation. 

Access Management  

  • Processing user access requests (add, remove, modify) following established workflows. 
  • Enforcing least‑privilege principles and role‑based access standards. 
  • Conducting periodic access reviews (user accounts, permissions, group memberships). 
  • Investigating and escalating suspicious access activities or unauthorized access attempts. 
     

Patch Management  

  • Assist with tracking and verifying system patch status as part of vulnerability review activities. 
  • Monitor patch‑related alerts (failed deployments, outdated versions) within security tools and coordinate remediation with IT operations. 
  • Support the vulnerability management process by validating missing patches identified during scans and escalating high‑risk findings. 
    (This is aligned with Tier 1’s documented tasks involving vulnerability scans and reporting.) 

Reporting & Communication 

  • Generate clear, accurate incident reports and daily shift summaries. 
  • Communicate event details with internal teams in a professional and timely manner. 

Continuous Improvement 

  • Recommend improvements to detection rules, response processes, and SOC procedures. 
  • Stay current on cyber threat trends, attacker techniques (TTPs), and security best practices. 

Required Qualifications 

  • 5+ years of experience in cybersecurity, with at least 2 years in a SOC or IR role. 
  • Advanced expertise in SIEM, EDR, and forensic tools. 
  • Strong understanding of MITRE ATT&CK framework and threat actor TTPs. 
  • Experience with scripting and automation (e.g., Python, PowerShell). 
  • Ability to lead and manage incident response efforts under pressure. 
  • Relevant security certifications from ISC2 or ISACA  
  • Excellent communication and leadership skills. 

Preferred Qualifications 

  • Bachelor’s degree in IT, Cybersecurity, or CS  
  • Certifications such as:  
  • CompTIA Security+ 
  • Microsoft SC-200 
  • CEH, CySA+ 
  • GIAC certifications (GSEC, GCIH, GMON) 
  • Experience with:  
  •  EDR, IDS/IPS, and network security tools 
  • SIEM/SOAR workflows/playbooks 
  • Threat intelligence platforms 

Key Competencies 

  • Strong analytical and problem‑solving skills 
  • Attention to detail 
  • Ability to work under pressure during incidents 
  • Team‑first mindset and willingness to learn 
  • Ability to recognize patterns and anomalies 
  • Prior SOC or IR experience 
  • Strong analysis and investigation skills 
  • Familiarity with threat intelligence and adversary behavior 
  • Ability to perform forensic/log analysis 
  • More advanced certifications preferred 

Work Environment 

  • 24/7 SOC environment - day shift with weekend coverage
  • Fast‑paced operational setting with tight response timelines 
  • Collaboration with cross‑functional IT and security teams 

Salary range:

This is a full-time, exempt position, eligible to receive a base salary and to participate in an annual performance bonus program. The salary range listed represents the maximum and minimum starting base pay for this position as of the time of posting. Final salary offered will be determined based on factors including but not limited to the candidate's skills and experience. The annual performance bonus program is preset and not candidate dependent.

Salary range for this position is CAD$90,000 to CAD$115,000.

Skills Required

  • 5+ years of cybersecurity experience, including at least 2 years in a SOC or incident response role
  • Advanced expertise in SIEM, EDR, and forensic tools
  • Strong understanding of the MITRE ATT&CK framework and threat actor tactics, techniques, and procedures
  • Experience with scripting and automation, such as Python or PowerShell
  • Ability to lead and manage incident response efforts under pressure
  • Relevant security certifications from ISC2 or ISACA
  • Excellent communication and leadership skills
  • Bachelor’s degree in IT, Cybersecurity, or Computer Science
  • CompTIA Security+ certification
  • Microsoft SC-200 certification
  • CEH or CySA+ certification
  • GIAC certification, such as GSEC, GCIH, or GMON
  • Experience with EDR, IDS/IPS, and network security tools
  • Experience with SIEM/SOAR workflows and playbooks
  • Experience with threat intelligence platforms

Vanderlande Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Vanderlande and has not been reviewed or approved by Vanderlande.

  • Healthcare Strength — Health coverage is described as comprehensive, with day‑one eligibility in many U.S. roles and employer‑paid protections that reduce out‑of‑pocket exposure. Feedback suggests medical, dental, and vision are a clear strength.
  • Retirement Support — Retirement offerings include a 401(k) with company match and immediate vesting in the U.S. Feedback suggests this forms a solid pillar of the total rewards package.
  • Leave & Time Off Breadth — Paid time off, sick leave, and paid holidays are characterized as generous relative to peers. Compressed workweek options in some roles further support time away and recovery.

Vanderlande Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Veghel
7,500 Employees
Year Founded: 1949

What We Do

Vanderlande is the global market leader for future-proof logistic process automation at airports. The company is also a leading supplier of process automation solutions for warehouses and in the parcel market. Vanderlande’s baggage handling systems are capable of moving over 4 billion pieces of baggage around the world per year. Its systems are active in more than 600 airports including 12 of the world’s top 20. More than 52 million parcels are sorted by its systems every day, which have been installed for the world’s leading parcel companies. In addition, many of the largest global e-commerce players and retailers have confidence in Vanderlande’s efficient and reliable solutions. The company focuses on the optimisation of its customers’ business processes and competitive positions. Through close cooperation, it strives for the improvement of their operational activities and the expansion of their logistical achievements. Vanderlande’s extensive portfolio of integrated solutions – innovative systems, intelligent software and life-cycle services – results in the realisation of fast, reliable and efficient automation technology. Established in 1949, Vanderlande has more than 7,500 employees, all committed to moving its customers’ businesses forward at diverse locations on every continent. With a consistently increasing turnover of 1.8 billion euros, it has established a global reputation over the past seven decades as a highly reliable partner for future-proof logistic process automation. Vanderlande was acquired in 2017 by Toyota Industries Corporation, which will help it to continue its sustainable profitable growth. The two companies have a strong strategic match, and the synergies include cross-selling, product innovations, and research and development.

Similar Jobs

Samsara Logo Samsara

Senior Software Engineer

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
Canada
4000 Employees
143K-185K Annually

Samsara Logo Samsara

Customer Success Manager

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
Canada
4000 Employees
134K-174K Annually

Cash App Logo Cash App

Software Engineer

Blockchain • Fintech • Mobile • Payments • Software • Financial Services
Remote or Hybrid
8 Locations
3500 Employees
264K-395K Annually

Cash App Logo Cash App

Strategic Pricing & Monetization Lead

Blockchain • Fintech • Mobile • Payments • Software • Financial Services
Remote or Hybrid
8 Locations
3500 Employees
208K-312K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account