← Available openings

TECHNICAL OPPORTUNITY · Sep 13, 2026

Security Operations Analyst II

Boston, MA Hybrid — 3 days per week on-site; rotating shift coverage Full-time, exempt $95,000 – $120,000 base per year

THE ROLE

Help protect corporate, cloud, and product environments through security operations. Join a nine-person internal SOC. Work within a follow-the-sun model alongside a partner MSSP.

WHAT YOU'LL DO

  • Triage, investigate, and respond to alerts from SIEM, EDR, cloud security posture tools, and the email security platform.
  • Lead escalated incident response, including containment, evidence collection, root-cause analysis, and post-incident reporting.
  • Develop and tune Microsoft Sentinel detection rules using KQL and CrowdStrike detections to reduce false positives and improve mean time to detect.
  • Perform threat hunting using threat-intelligence feeds and MITRE ATT&CK-mapped hypotheses.
  • Coordinate MSSP hand-offs, escalations, and quality reviews of overnight coverage.
  • Maintain and improve incident-response playbooks and SOAR automations.
  • Support vulnerability management by validating exposure, prioritizing remediation, and tracking closure with system owners.

WHAT YOU'LL BRING

Required

  • 3–5 years in security operations, incident response, or a related role.
  • Hands-on experience with a SIEM and an EDR platform such as CrowdStrike, Defender for Endpoint, or SentinelOne. Microsoft Sentinel or Splunk is preferred for SIEM experience.
  • Working knowledge of Windows and Linux internals, network protocols, and common attacker techniques mapped to MITRE ATT&CK.
  • Experience investigating incidents in Azure or AWS cloud environments.
  • Clear, well-organized written communication for incident reports and stakeholder updates.
  • Ability to work on-site in Boston three days per week and participate in the rotating shift schedule.

Nice to have

  • GIAC certifications such as GCIH, GCIA, or GCFA, or CySA+.
  • Python or PowerShell scripting for automation and log analysis.
  • Experience with SOAR platforms such as Sentinel automation rules / Logic Apps, Tines, or Splunk SOAR.
  • Exposure to OT/IoT or product security in a hardware company.

COMPENSATION & BENEFITS

Base range: $95,000 – $120,000 base per year

Actual pay is determined by experience, skills, and location.

Bonus / commission: 8% bonus target.

  • Medical, dental, and vision coverage with HSA contribution.
  • 401(k) with 5% match.
  • 20 days of PTO, 12 paid holidays, and shift-differential pay for evening and weekend coverage.
  • Annual $3,500 training budget with SANS course sponsorship for high performers.
  • Commuter benefits and on-site parking.

HOW WE WORK

  • Report to the SOC Manager.
  • Rotating shifts cover 6am–10pm Eastern on weekdays and one weekend per month.

Make your next introduction.

Apply with your TalentBroker profile and resume.

Apply