SOC 2 Analyst
This is the employer's own posting, not a copy on a job board.
What we know
Is it still open?
Confirmed still open
Last checked 12h ago — checked against the employer's own applicant tracking system, which is the company answering directly.
We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.
How old is it?
Posted 246d ago
The date the source published, not the day we noticed it (2026-01-31). Last seen at its source 3h ago.
Is it remote?
Marked remote on the employer's board
Their board carries a remote setting on this posting — a field they filled in, not wording we read. The location field names somewhere specific, which is usually where the team or the entity sits.
Who may apply?
Australia
The description states no restriction of its own. This is the source's own tag.
Pay not stated
Similar roles pay A$1,650–2,438/mo
Middle 50% of 18 listings that do state pay — Operations · all levels · APAC · AUD/month. This employer has published no salary; this is what comparable listings we hold disclose, never converted between currencies or periods. How this is calculated.
Skills named in the ad
Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.
Carried by 1 source
-
bamboohr employer's own board first seen 12h ago · last seen 3h ago
The listing
SOC 2 Contract
Through 2026
Supporting APAC Time zones
Responsible for investigating security incidents and determining their root causes. They review incidents that have been escalated by Tier 1 analysts, who are responsible for collecting data and reviewing alerts. Tier 2/3 analysts use threat intelligence, such as indicators of compromise , TTPs, and company host system/network data sets to assess the alerts, threats and potential incidents in more depth.
They have deep experience with SIEM tools specifically Crowdstrike SIEM, network data, host data, Identity and Access log data, developing SIEM use cases, reducing/tuning false alerts and leading investigations until issues have been resolved. They will also monitor systems and events across different operating systems, such as Windows, macOS, and Linux.
Must be proactive, problem solver and curious.
Must have 5+ years recent experience as Tier 2 or 3 analyst at a large organization; government and Critical Infrastructure company preferred.
Must have strong, demonstrated SIEM and data correlation experience
Must have demonstrated experience designing new SOC use cases and working with vendor on implementing new use cases.
Must have experience designing and implementing runbooks and use cases to mitigate security incidents
Experience designing Incident Response plan, including alert definition, runbooks, escalation, etc..
Must have extensive experience reviewing and managing alerts in Microsoft Defender, Splunk and or Crowdstrike
Must have experience conducting hunts across disparate data sets, to include host data, vulnerability data, threat data, network data, active directory data, among others to identify threats
Experience leading timely security operations response efforts in collaboration with stakeholders
Experience documenting incident response communications for technical and management audiences
Must have experience setting up alert rules and effective alert management
Demonstrated ability to create runbooks and conducting investigations with key application, IT Infra and other stakeholders
Experience designing custom SOC SIEM use cases in Defender, Splunk and CRWD
Experience conducting forensic work investigations
Most be a problem solver
Must be curious
Must be analytical, qualitative and quantitative abilities
Must be adaptive to dynamic environment
Strong security operations documentation abilities