AlphaSense Oy logo
Posted August 24, 2026 · 4 days agoLast seen August 29, 2026Est. expiry September 28, 2026

Security Operations Analyst

Security Operations Analyst II
About the role

Security Operations Analyst II to join our Security Operations team in a fully remote capacity from Canada. This role sits at Tier 1–2 in our operating model — you are past the stage of learning what alerts look like and ready to own triage, perform structured investigations, and contribute to detection quality. You will handle the day-to-day alert queue, investigate escalated or ambiguous cases, handle incidents and work closely with senior analysts and the Security Operations Manager to close coverage gaps. You will be supported by experienced colleagues and a mature toolset, but you are expected to bring real investigative instinct and a curiosity to grow to the role from day one. WHAT YOU WILL DO: Alert Triage & Investigation Monitor and triage alerts across endpoint, network, cloud, runtime and identity data sources with accuracy and appropriate urgency Perform structured investigations on escalated or ambiguous alerts: pivot across log sources, correlate events, and build a coherent timeline Classify alerts correctly — true positive, false positive, or benign — with documented rationale, not just a verdict Identify scope and blast radius on confirmed incidents: affected users, systems, and data before escalating or containing Escalate to senior analysts with a complete investigation package — context, evidence, timeline, and a hypothesis Incident Response Support Participate in active incident response under senior analyst or manager direction: evidence collection, log pulls, timeline reconstruction Execute containment actions — endpoint isolation, account suspension, token revocation — as directed with documented rationale Maintain accurate and timely case documentation throughout the incident lifecycle Contribute to post-incident timelines and assist with root cause documentation Cloud & Identity Security Monitoring Monitor cloud audit logs and native threat detection findings for suspicious IAM activity, unusual API calls, and access anomalies Investigate identity provider events: suspicious logins, MFA bypass attempts, session anomalies, and unauthorized app assignments Recognize common cloud-native attack patterns: credential abuse via metadata service, privilege escalation via IAM role assumption, and storage misconfiguration access Correlate cloud-side events with endpoint and network telemetry to build a fuller picture of attacker activity Detection & Quality Improvement Flag false positives and noisy detections with enough context for a senior analyst or detection engineer to tune them Identify gaps in existing detection coverage based on alert patterns you observe during triage Apply knowledge of MITRE ATT&CK to label attacker techniques and communicate findings consistently Contribute to runbook accuracy by flagging outdated steps or missing guidance encountered during investigations Participate with Detections Engineers to build detections and contribute to automating activity with an Engineering mindset Documentation & Communication Write clear, concise case notes that a colleague could pick up mid-investigation without needing to re-investigate from scratch Produce shift handoff summaries that accurately represent open cases, pending actions, and investigation status Communicate incident updates to the Security Operations Manager with sufficient clarity to brief upward without re-investigation WHAT WE ARE LOOKING FOR: Required 2–4+ years of hands-on experience in a SOC, or security operations role with direct alert triage responsibility Solid understanding of the MITRE ATT&CK framework — you use it to label and communicate attacker behavior, not just reference it Working knowledge of EDR tooling: process tree analysis, behavioral detection review, and basic endpoint artifact interpretation Familiarity with SIEM-based investigation: querying logs, correlating events across sources, and building timelines from normalized data Understanding of foundational network protocols (TCP/IP, DNS, HTTP/S, TLS) and how attackers abuse them Exposure to cloud security monitoring ex. AWS or GCP — including audit log review and IAM-related alert investigation Experience investigating identity-based alerts in an enterprise identity provider (e.g., Okta, Entra ID, or equivalent) Strong written communication: your case notes are accurate, structured, and useful to someone who wasn’t there Preferred Experience with next-gen EDR platforms (e.g., CrowdStrike Falcon, SentinelOne, or equivalent) beyond basic alert review — RTR, process trees, custom detections Hands-on SIEM experience with a cloud-native platform (e.g., Google SecOps/Chronicle, Microsoft Sentinel, or equivalent) Exposure to CSPM or cloud security tooling (e.g., Wiz, Prisma Cloud, or equivalent) as an investigation data source Familiarity with AWS IR fundamentals: CloudTrail, GuardDuty, VPC Flow Logs, IAM chain analysis Understanding of encoding vs. encryption vs. hashing and their relevance to attacker obfuscation techniques Experience working alongside or receiving escalations from a managed detection and response (MDR) partner Relevant certifications: CompTIA CySA+, Security+, BTL1, GCIH, or equivalent practical security credential AlphaSense is an equal-opportunity employer. We are committed to a work environment that supports, inspires, and respects all individuals. All employees share in the responsibility for fulfilling AlphaSense’s commitment to equal employment opportunity. AlphaSense does not discriminate against any employee or applicant on the basis of race, color, sex (including pregnancy), national origin, age, religion, marital status, sexual orientation, gender identity, gender expression, military or veteran status, disability, or any other non-merit factor. This policy applies to every aspect of employment at AlphaSense, including recruitment, hiring, training, advancement, and termination.

Job Details

Skills & Technologies

MITRE ATT&CKEDR toolingSIEMCloud security monitoringIdentities & IAMNetwork protocolsIncident responseLog analysisTimeline reconstructionCase documentation
Seen 83 minutes agoPartial Schema
Financial overview
€28.2M
Revenue
€14.9M
Profit
53.0%
Profit margin
AlphaSense Oy logo
AlphaSenseOy · 216 open roles
Top locations: Remote - Global · 176 · Helsinki, Finland · 27 · Singapore · 2+9 other locations
View company
Current open roles at AlphaSense Oy on JobCrawls
LocationActive listings
Remote - Global176
Helsinki, Finland27
Singapore2
London, UK2
New York, USA2
New York City, United States1
Remote - Finland1
London, United Kingdom1
Remote1
New York, United States1
Remote - Europe1
Bangalore, India1
Current role mix at AlphaSense Oy on JobCrawls
Role typeActive listings
Software Engineer28
Account Manager9
Product Manager6
Customer Success Manager6
Channel and Customer Research Associate5
Compliance Analyst5
Account Executive4
Content Analyst4
Sales Development Representative4
Product Designer4
Principal Software Engineer3
Human Resources Specialist3
Network Engineer3
Analyst3
AI Platform Engineer3
Analyst Development Representative3
Android Engineer3
Customer Support Specialist2
Operations Manager2
People Business Partner2
Head of Developer Experience2
Data Scientist2
Enterprise Account Executive2
IT Support Analyst2
Pre-Sales Manager2
Sector Lead2
Program Manager2
Technical Program Manager2
Site Reliability Engineer2
Customer & Product Support Analyst2
iOS Engineer2
Design Engineer2
Sales Development Manager2
Senior Manager2
Associate Account Executive2
Manager2
Principal Design Engineer2
Cloud Platform Engineer2
Customer Education Manager1
Staff Engineer1
Equity Research1
Channel and Customer Research Sector Lead1
Revenue Accounting1
Senior Technical Program Manager1
Revenue Tools Specialist1
Payroll Director1
Product Security1
Account Director1
Tax Associate1
Head of Strategic Alliances1
Team Leader1
Director of Executive Recruiting1
Customer Support Analyst1
Strategic Account Leader1
Deal Desk Contracting Manager1
Business Applications Security Engineer1
Key Account Director1
Sales Operations Analyst1
Marketing AI & Transformation Strategy Lead1
Product Analyst1
Head of Broker Relations1
Senior Software Engineer1
Content Support Analyst1
Analytics Engineer1
Executive Assistant1
Financial Data Application Specialist1
Solutions Marketing Manager1
Implementation Consultant1
Human Resources1
Director of Global Real Estate and Workplace Experience1
Marketing Manager1
Program Management1
Senior Staff Software Engineer1
Legal Content and Data Director1
Product Platforms Engineer1
Embedded Client Platform Engineer1
Pre-Sales Consultant1
Motion Designer1
Deal Desk Analyst1
Analyst Development1
Business Applications Security1
Equity Research Associate1
Security Operations Analyst1
Compliance Surveillance Analyst1
Strategic Account Executive1
Audio Visual Engineer1
Strategic Sales Manager1
Strategic Finance Manager1
Senior Engineer1
Senior Commercial Counsel1
Researcher1
Account Management1
People Operations Coordinator1
Solutions Consultant1
Director of AI Governance and Security1
Data Analyst1
Core Developer Experience Engineer1
Revenue Operations Manager1
Marketing Analyst1
Sales Enablement1
Current role-level mix at AlphaSense Oy on JobCrawls
Role levelActive listings
Mid-Level162
Senior12
Manager3
Executive1

Help us improve JobCrawls — sign in to sync saved jobs across devices, or send feedback anytime.