Vanderlande
Cybersecurity Analyst – Tier 2
Vancouver
Apply through hirly
Upload your resume and get a version tailored to this job, plus a cover letter, in about thirty seconds — before you create an account.
Apply with hirlyhirly's read of this role
- Seniority
- Mid level
- Stated salary
- $90,000 per year
- Country
- CA
- Work mode
- On-site / unstated
- First seen by hirly
- 24 Sept 2026
Derived automatically from the posting. Sign up to see how the role scores against your own resume.
the posting
Job Title
Cybersecurity Analyst – Tier 2
Job Description
The Security Operations Center – Tier 2 Analyst will lead complex investigations, coordinate incident response efforts, and drive continuous improvement in threat detection and response capabilities. You will serve as a technical expert and escalation point for Tier 1 analysts, customers or other departments. This role supports incident detection, escalation, and response activities within customer environments, in line with agreed SOC service scope and service level agreements (SLAs). You will have had previous experience in handling escalation from Tier 1 and direct work in security monitoring, threat intelligence, or incident response
Key Responsibilities
Perform advanced analysis of escalated security incidents and support investigation efforts.
Act as an escalation point for Tier 1 analysts and provide expert guidance during incident response activities.
Develop and tune detection rules and use cases in SIEM and other platforms.
Perform threat hunting based on intelligence and behavioral analysis.
Conduct forensic analysis and reverse engineering of malware when needed.
Collaborate with threat intelligence teams to enrich investigations.
Provide strategic recommendations to improve SOC processes and technologies.
Mentor junior analysts and contribute to training programs.
Participate in detection validation and lessons‑learned activities to enhance SOC detection and response.
Additional Responsibilities
Monitoring & Detection
Validate complex alerts escalated by Tier 1
Determine scope, impact, and severity of confirmed incidents.
Perform deep log analysis, forensic investigations, and develop custom detection rules.
Implement containment, mitigation and remediation actions.in accordance with playbooks and customer agreements
Understanding TTPs (tactics, techniques, procedures) of threat actors
Ability to develop custom detection rules and correlation logic
Investigation & Analysis
Analyze data patterns and outliers to identify threat actor behaviors and insider threats.
Conduct deep investigations into logs, network telemetry, and endpoint activity.
Document findings, actions taken, and recommended next steps.
Incident Response Support
Assist the SOC team during active security incidents by collecting evidence and containing low‑severity threats as per playbooks.
Follow established runbooks to ensure consistent and compliant response actions.
Respond to escalated security incidents requiring advanced analysis.
Provide containment recommendations and support remediation.
Access Management
Processing user access requests (add, remove, modify) following established workflows.
Enforcing least‑privilege principles and role‑based access standards.
Conducting periodic access reviews (user accounts, permissions, group memberships).
Investigating and escalating suspicious access activities or unauthorized access attempts.
Patch Management
Assist with tracking and verifying system patch status as part of vulnerability review activities.
Monitor patch‑related alerts (failed deployments, outdated versions) within security tools and coordinate remediation with IT operations.
- Support the vulnerability management process by validating missing patches identified during scans and escalating high‑risk findings.
- (This is aligned with Tier 1’s documented tasks involving vulnerability scans and reporting.)
Reporting & Communication
Generate clear, accurate incident reports and daily shift summaries.
Communicate event details with internal teams in a professional and timely manner.
Continuous Improvement
Recommend improvements to detection rules, response processes, and SOC procedures.
Stay current on cyber threat trends, attacker techniques (TTPs), and security best practices.
Required Qualifications
5+ years of experience in cybersecurity, with at least 2 years in a SOC or IR role.
Advanced expertise in SIEM, EDR, and forensic tools.
Strong understanding of MITRE ATT&CK framework and threat actor TTPs.
Experience with scripting and automation (e.g., Python, PowerShell).
Ability to lead and manage incident response efforts under pressure.
Relevant security certifications from ISC2 or ISACA
Excellent communication and leadership skills.
Preferred Qualifications
Bachelor’s degree in IT, Cybersecurity, or CS
Certifications such as:
CompTIA Security+
Microsoft SC-200
CEH, CySA+
GIAC certifications (GSEC, GCIH, GMON)
Experience with:
EDR, IDS/IPS, and network security tools
SIEM/SOAR workflows/playbooks
Threat intelligence platforms
Key Competencies
Strong analytical and problem‑solving skills
Attention to detail
Ability to work under pressure during incidents
Team‑first mindset and willingness to learn
Ability to recognize patterns and anomalies
Prior SOC or IR experience
Strong analysis and investigation skills
Familiarity with threat intelligence and adversary behavior
Ability to perform forensic/log analysis
More advanced certifications preferred
Work Environment
24/7 SOC environment - day shift with weekend coverage
Fast‑paced operational setting with tight response timelines
Collaboration with cross‑functional IT and security teams
Salary range:
This is a full-time, exempt position, eligible to receive a base salary and to participate in an annual performance bonus program. The salary range listed represents the maximum and minimum starting base pay for this position as of the time of posting. Final salary offered will be determined based on factors including but not limited to the candidate's skills and experience. The annual performance bonus program is preset and not candidate dependent.
Salary range for this position is CAD$90,000 to CAD$115,000.
Similar jobs
- Cybersecurity Analyst IITriumf · TRIUMF – Vancouver, BCFirst seen 4d ago
- Military Fellowship Program: Cybersecurity AnalystSnc · 2 LocationsFirst seen today
- Cybersecurity AnalystSkechers · Manhattan Beach, CAFirst seen today
- Cybersecurity Analyst | PCI (Remote)Homedepot · TEXAS - VIRTUAL - TX01First seen todayremote
- Cybersecurity Analyst II | Fraud (Remote)Homedepot · GEORGIA - VIRTUAL - GA01First seen todayremote
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job