{"id":1185852,"url":"https://alion.io/job/vanderlande-cybersecurity-analyst-tier-2","title":"Cybersecurity Analyst – Tier 2","company":{"id":54548,"name":"Vanderlande","domain":"vanderlande.com","url":"https://alion.io/company/vanderlande","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":{"grade":"A","score":91,"open_postings":19,"ghost_share":0,"stale_share":0.368,"repost_share":0,"time_to_fill_p50_days":29,"computed_at":"2026-09-25T05:45:01Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Vancouver, Canada"],"countries":["CA"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":94000,"max_usd":200000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":68},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Least Privilege","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"SIEM","optional":false}],"status":"live","first_seen_at":"2026-09-24T14:45:07Z","employer_posted_date":"2026-09-24","last_verified_at":"2026-09-25T22:29:55Z","board_verified":true,"closed_at":null,"days_open":1,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":1},"description":"Job Title\nCybersecurity Analyst - Tier 2Job Description\nThe Security Operations Center - Tier 2 Analyst will lead complex investigations, coordinate incident response efforts, and drive continuous improvement in threat detection and response capabilities. You will serve as a technical expert and escalation point for Tier 1 analysts, customers or other departments. This role supports incident detection, escalation, and response activities within customer environments, in line with agreed SOC service scope and service level agreements (SLAs). You will have had previous experience in handling escalation from Tier 1 and direct work in security monitoring, threat intelligence, or incident response\nKey Responsibilities\nPerform advanced analysis of escalated security incidents and support investigation efforts. \nAct as an escalation point for Tier 1 analysts and provide expert guidance during incident response activities. \nDevelop and tune detection rules and use cases in SIEM and other platforms. \nPerform threat hunting based on intelligence and behavioral analysis. \nConduct forensic analysis and reverse engineering of malware when needed. \nCollaborate with threat intelligence teams to enrich investigations. \nProvide strategic recommendations to improve SOC processes and technologies. \nMentor junior analysts and contribute to training programs. \nParticipate in detection validation and lessons-learned activities to enhance SOC detection and response. \nAdditional Responsibilities\nMonitoring & Detection\nValidate complex alerts escalated by Tier 1 \nDetermine scope, impact, and severity of confirmed incidents. \nPerform deep log analysis, forensic investigations, and develop custom detection rules. \nImplement containment, mitigation and remediation actions.in accordance with playbooks and customer agreements \nUnderstanding TTPs (tactics, techniques, procedures) of threat actors \nAbility to develop custom detection rules and correlation logic \nInvestigation & Analysis\nAnalyze data patterns and outliers to identify threat actor behaviors and insider threats. \nConduct deep investigations into logs, network telemetry, and endpoint activity. \nDocument findings, actions taken, and recommended next steps. \nIncident Response Support\nAssist the SOC team during active security incidents by collecting evidence and containing low-severity threats as per playbooks. \nFollow established runbooks to ensure consistent and compliant response actions. \nRespond to escalated security incidents requiring advanced analysis. \nProvide containment recommendations and support remediation. \nAccess Management\nProcessing user access requests (add, remove, modify) following established workflows. \nEnforcing least-privilege principles and role-based access standards. \nConducting periodic access reviews (user accounts, permissions, group memberships). \nInvestigating and escalating suspicious access activities or unauthorized access attempts. \nPatch Management\nAssist with tracking and verifying system patch status as part of vulnerability review activities. \nMonitor patch-related alerts (failed deployments, outdated versions) within security tools and coordinate remediation with IT operations. \nSupport the vulnerability management process by validating missing patches identified during scans and escalating high-risk findings. (This is aligned with Tier 1’s documented tasks involving vulnerability scans and reporting.) \nReporting & Communication\nGenerate clear, accurate incident reports and daily shift summaries. \nCommunicate event details with internal teams in a professional and timely manner. \nContinuous Improvement\nRecommend improvements to detection rules, response processes, and SOC procedures. \nStay current on cyber threat trends, attacker techniques (TTPs), and security best practices. \nRequired Qualifications\n5+ years of experience in cybersecurity, with at least 2 years in a SOC or IR role. \nAdvanced expertise in SIEM, EDR, and forensic tools. \nStrong understanding of MITRE ATT&CK framework and threat actor TTPs. \nExperience with scripting and automation (e.g., Python, PowerShell). \nAbility to lead and manage incident response efforts under pressure. \nRelevant security certifications from ISC2 or ISACA \nExcellent communication and leadership skills. \nPreferred Qualifications\nBachelor’s degree in IT, Cybersecurity, or CS \nCertifications such as: \nCompTIA Security+ \nMicrosoft SC-200 \nCEH, CySA+ \nGIAC certifications (GSEC, GCIH, GMON) \nExperience with: \n EDR, IDS/IPS, and network security tools \nSIEM/SOAR workflows/playbooks \nThreat intelligence platforms \nKey Competencies\nStrong analytical and problem-solving skills \nAttention to detail \nAbility to work under pressure during incidents \nTeam-first mindset and willingness to learn \nAbility to recognize patterns and anomalies \nPrior SOC or IR experience \nStrong analysis and investigation skills \nFamiliarity with threat intelligence and adversary behavior \nAbility to perform forensic/log analysis \nMore advanced certifications preferred \nWork Environment\n24/7 SOC environment - day shift with weekend coverage\nFast-paced operational setting with tight response timelines \nCollaboration with cross-functional IT and security teams \nSalary range:\nThis is a full-time, exempt position, eligible to receive a base salary and to participate in an annual performance bonus program. The salary range listed represents the maximum and minimum starting base pay for this position as of the time of posting. Final salary offered will be determined based on factors including but not limited to the candidate's skills and experience. The annual performance bonus program is preset and not candidate dependent.\nSalary range for this position is CAD$90,000 to CAD$115,000.","description_format":"text","description_chars":5760,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Security","Warehousing","Incident Response"],"lifecycle":[{"event":"open","at":"2026-09-24T14:45:07Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":0,"expected_fill_days":29,"reasons":["conf:0","velocity","win:early","comp:brand"],"computed_at":"2026-09-25T05:45:01Z"},"pay":null,"html_url":"https://alion.io/job/vanderlande-cybersecurity-analyst-tier-2","json_url":"https://alion.io/job/vanderlande-cybersecurity-analyst-tier-2.json","meta":{"generated_at":"2026-09-26T03:13:45Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3429,"day_limit":5000,"remaining_today":1571,"minute_limit":60,"resets_at":"2026-09-27T00:00:00Z"}}}