Verified current Job

SOC Analyst (Tier 1, Tier 2 & Tier 3)

Build the Future with AspenView Technology Partners

Job Full source details
Aspenview Technology Partners Source published Oct 5, 2026 Verified 3 hours ago
✓ 100% verification score · Source: Aspenviewtech (greenhouse) · Always confirm final requirements on the original source.
Complete source information imported The available role or programme description, requirements, benefits and source facts were imported from the public official endpoint and formatted for reading.

Overview

Build the Future with AspenView Technology Partners

Full job description

Build the Future with AspenView Technology Partners At AspenView, we are passionate about transforming the way organizations approach technology. We specialize in creating high-performing, nearshore IT teams to help North American clients innovate faster and more efficiently. As we continue to grow, we’re looking for exceptional people to join our team and help drive impactful change across industries. About the Role AspenView is building a dedicated, 24/7 Security Operations Center team for a large U.S. consumer lender in the financial services sector, and we are hiring at three levels: Tier 1 Monitoring Analysts (junior), Tier 2 Analysts and Shift Leads (mid-level), and Tier 3 Senior SOC Analysts (senior). All roles are full-time, on site in Bogotá or Buenos Aires, and dedicated to a single client, working on U.S. Eastern Time with senior leads in the United States. Alerts arrive in ServiceNow already enriched. Tier 1 validates, classifies and escalates them following the runbook; Tier 2 decides which escalations are real and owns them through to client notification; Tier 3 takes every P1, major incident and Tier 2 request for support, scoping the impact, building the timeline, recommending containment and performing first-response forensics before the U.S.-based Incident Response Lead steps in. Incident declaration and containment execution sit with the client; the team escalates with evidence and a recommendation. The team is built for round-the-clock coverage. Six Tier 1 analysts cover three rotating 8-hour shifts (07:00–15:00, 15:00–23:00 and 23:00–07:00) seven days a week, including nights, weekends and public holidays. Three Tier 2 analysts rotate across the day and evening shifts and share the overnight on-call. Two Tier 3 analysts work business hours and share a 24/7 on-call rotation with the Incident Response Lead. All analysts report to the on-site SOC Manager. All analysts work from AspenView's access-controlled delivery suite, which operates under a clean-desk rule with VDI-only access to the client's environment and tooling. Access to the client environment requires identity, criminal-background, employment and education checks, repeated periodically. Tier 1 to Tier 3 is a defined career path, and detection engineering, threat hunting and incident response lead work all sit within the same team. What You Will Do Tier 1 – Monitoring Own the live alert queue: acknowledgement, validation, classification and prioritization against the agreed severity matrix. Check enrichment and pull additional context from Elastic, CrowdStrike, Microsoft Defender and Okta before making a call, and work runbooks for common alert types such as reported phishing, malware detections, risky or impossible-travel sign-ins and policy violations. Deliver clean escalations to the Tier 2 shift lead, keep audit-ready ServiceNow ticket records, and write shift handovers covering open cases. Serve as the only analyst on the console during night shifts, with Tier 2 and Tier 3 on call, and judge when to wake them. Tier 2 – Shift Lead Run the day or evening shift: who is working what, what is open, and a written handover the next shift acknowledges before you leave. Own every escalation raised on your shift, from investigation through to client notification, plus overnight escalations when on call. Investigate validated or ambiguous alerts, correlating Elastic, CrowdStrike, Microsoft Defender, Okta and AWS logs to reach a call you can defend, and document hypothesis, evidence, reasoning and disposition in ServiceNow. Escalate to Tier 3 with scope, evidence and a working hypothesis, coach Tier 1 analysts, and provide tuning feedback to Detection Engineering on noisy or missed rules. Tier 3 – Senior Analyst Own P1 cases, major incidents and Tier 2 requests for support: scoping what is affected, building the timeline, and giving the client the evidence it needs to decide whether to declare an incident. Write evidence-backed containment recommendations for the client's teams to execute. Perform first-response DFIR: endpoint triage in CrowdStrike and Microsoft Defender, memory and disk artifacts, Okta session analysis and AWS log review, with evidence preserved properly, working across Abstract Security, Elastic and ServiceNow. Hold escalation authority over Tier 2, review and coach their work, produce incident write-ups for the client's security leadership, and feed detection gaps back to Detection Engineering. What You Bring Education Bachelor's degree in Cybersecurity, Computer Science, Information Systems or a related field, or equivalent hands-on experience (all levels). Experience All levels: English strong enough to escalate, brief and write reports for a U.S. security team without an intermediary (B2 or above), and willingness to work the shift or on-call pattern for your level. Tier 1: Early-career professional with hands-on exposure to security monitoring through a SOC, a NOC with security duties, or a serious lab or CTF record. Tier 2: Several years of SOC or security investigation work beyond triage, having closed incidents rather than only escalated them, plus experience leading a shift or owning escalations end to end. Tier 3: Several years in security operations or incident response, with an incident you can walk through end to end, and the judgment to recommend containment that stops an attacker without breaking the systems the business runs on. Technical Expertise Tier 1: Log fundamentals (reading Windows events, authentication logs and proxy logs) and triage discipline: following a runbook exactly and noticing when an alert does not fit it. Tier 2: Querying logs directly in a SIEM (Elastic, Splunk, Microsoft Sentinel, QRadar or equivalent), joining evidence across endpoint, identity and cloud sources, and solid fundamentals in Windows event logs, SSO and MFA flows, and phishing and malware patterns mapped to MITRE ATT&CK. Tier 3: Investigation in a production SIEM or log platform, writing your own queries, and working knowledge of Windows, Linux and identity attack paths (credential theft, session and token abuse, lateral movement, privilege escalation) mapped to MITRE ATT&CK. Certifications Tier 1: Security+, CySA+, SC-200, BTL1, CCNA CyberOps or similar (preferred). Tier 2: CySA+, GCIA, GCIH, BTL1, SC-200 or Security+ (preferred). Tier 3: GCIH, GCFA, GCIA, CySA+, BTL2 or OSCP (preferred). Nice to Have Elastic query languages (EQL, ES|QL, KQL), Abstract Security, ServiceNow or ServiceNow SecOps. EDR consoles such as CrowdStrike Falcon, Microsoft Defender or SentinelOne. Identity and cloud investigation in Okta or Entra ID and AWS (CloudTrail, GuardDuty, VPC flow logs) or Azure equivalents. Email and network evidence from Proofpoint and Palo Alto, or equivalents. Basic scripting (Python, PowerShell), SOAR playbooks, or GenAI-assisted triage tools and knowing when not to trust them. Forensic tooling (Velociraptor, KAPE, Volatility, Autopsy) and malware triage or basic reverse engineering (Tier 3). Experience in banking, payments or another regulated sector, ideally with a feel for PCI DSS, GLBA or NYDFS evidence expectations. Visa Sponsorship AspenView does not sponsor employment visas for this role. Applicants must be permanently authorized to work in their country of residence and must not require visa sponsorship now or in the future. Equal Opportunity Employer AspenView is proud to be an equal opportunity employer. We believe in creating an environment where all employees feel welcome, valued, and empowered to succeed. We celebrate diversity and strive to build a culture of inclusion where all individuals, regardless of their race, color, gender, gender identity or expression, sexual orientation, disability, age, or any other characteristic, can thrive. We encourage applicants from all walks of life to join our team and make a lasting impact.

Tips for this job

Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.

  1. Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
  2. Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
  3. Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
  4. Apply through the original employer or official recruitment destination shown on this page.

Verification notes

laptop-ats-crawler v3

Original authoritative source

JobOpportunity is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.

Apply through JobOpportunity →

Browse current JobOpportunity listings from Aspenviewtech (greenhouse) →

More ways to save

Discover deals, coupons and free courses on our sister site.

Explore DealVorio
Save more with DealVorio: deals, coupons, free courses, apps and books