The Role
Investigates and qualifies escalated SOC alerts involving phishing, account compromise, malware, and lateral movement. Correlates events across security platforms, enriches investigations with logs, indicators of compromise, and threat intelligence, determines severity and impact, and recommends or initiates mitigation and escalation actions. Documents findings, analyzes endpoint and network artifacts, coaches Level 1 analysts, improves detection rules and playbooks, and uses approved automation and AI tools.
Summary Generated by Built In
Overview:
- The client is looking for an IT security analyst for its
SOC, positioned at level 2: alerts reach this person already escalated by level
1, and the person in turn acts as the technical escalation point for those
analysts.
- The work centres on investigation: qualifying phishing,
account compromise, malware or lateral movement cases, correlating events
across several platforms, then enriching them with logs, indicators of
compromise and threat intelligence.
- The person determines verdict, severity and impact, then
recommends or initiates first measures according to established processes, with
incident response remaining initial and carried out with other teams.
- The form title specifies no level, while the full set of
responsibilities describes a level 2 role.
- The Talents and qualifications section is empty: no degree,
certification, language or named tool is required, so assessment rests entirely
on the activity profile.
- Target candidate: a QA professional with at least 10 years
in IT, including 5 years in testing, who has coordinated testing within agile
teams and uses JIRA, XRAY, Cypress and Playwright in recent mandates.
- Group insurance exposure or an integration project will set
apart otherwise equal candidates.
Requirements
Required:
- Analysis and qualification of escalated alerts (phishing,
account compromise, malware, lateral movement)
- Event correlation (SIEM, XDR, EDR, identity, email, network,
cloud)
- Alert enrichment (logs, indicators of compromise, threat
intelligence)
- Determination of verdict, severity, potential impact and
required actions
- Initial mitigation, containment or escalation measures,
recommended or initiated per processes
- Documentation of investigations, findings, decisions and
actions
- First-level technical analysis of endpoint and network logs
and artefacts
- Support and coaching of level 1 SOC analysts on complex
cases
- Improvement of detection rules, investigation queries,
runbooks and playbooks
- Use of approved AI and automation tools (triage, enrichment,
documentation)
Skills Required
- At least 10 years of IT experience
- At least 5 years of testing experience
- Experience coordinating testing within agile teams
- Recent experience using JIRA, XRAY, Cypress, and Playwright
- Analysis and qualification of escalated SOC alerts
- Event correlation across SIEM, XDR, EDR, identity, email, network, and cloud platforms
- Alert enrichment using logs, indicators of compromise, and threat intelligence
- Determining verdict, severity, potential impact, and required actions
- Performing or recommending initial mitigation, containment, and escalation measures
- Documenting investigations, findings, decisions, and actions
- First-level technical analysis of endpoint and network logs and artifacts
- Supporting and coaching Level 1 SOC analysts on complex cases
- Improving detection rules, investigation queries, runbooks, and playbooks
- Using approved AI and automation tools for triage, enrichment, and documentation
- Group insurance exposure
- Experience with an integration project
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Maarut Inc. is a Canadian company specializing in IT services, technology staffing, and software development, dedicated to assisting businesses with digital transformation and solving business challenges through technology.








