Posted August 15, 2026
Security Analyst II (SOC)
Robert Half
Los Angeles, CA, US
Full Time
52.25USD - 60.5USD per hour
Job Description
Job Description
We are looking for a Security Analyst II (SOC) to join a security operations team in Los Angeles, California as part of a Long-term Contract engagement. This role focuses on monitoring security activity, investigating alerts, and helping drive incident response efforts in a fast-paced environment. The ideal candidate brings hands-on experience in security operations, sound investigative judgment, and the ability to work closely with technical teams to strengthen detection and response capabilities.
Responsibilities:
• Evaluate a high daily volume of security alerts and determine whether events represent genuine threats, routine activity, or inaccurate detections.
• Triage security events, prioritize risk, and escalate advanced or high-impact issues to Security Engineers when deeper analysis is required.
• Contribute to incident response activities from initial identification through containment, documentation, and follow-up review.
• Refine and enhance detection logic to improve visibility, strengthen coverage, and reduce unnecessary alert noise.
• Investigate suspicious behavior related to data loss, insider risk, and other security concerns surfaced through monitoring tools.
• Apply threat intelligence by reviewing indicators of compromise and conducting targeted searches across available telemetry sources.
• Collaborate with IT, platform, and engineering partners to remediate vulnerabilities and address gaps identified during investigations.
• Support hybrid team operations with onsite participation Tuesday through Thursday as needed.• 2–4+ years of experience in security analysis, security operations, or detection and response functions.
• Background working in a Level 1 or Level 2 SOC environment with hands-on alert triage and investigation responsibilities.
• Understanding of networking concepts, security event logs, SIEM workflows, and incident response practices.
• Ability to analyze activity patterns and distinguish legitimate business behavior from potentially malicious actions.
• Strong analytical mindset, investigative problem-solving skills, and a proactive approach to technical learning.
• Experience with cybersecurity tools and concepts such as DLP, Okta, SIEM platforms, application security, and cyber security policies.
• Familiarity with tools or platforms such as SentinelOne, CrowdStrike, AWS Security Hub, or similar security technologies is preferred.
• Relevant security knowledge supported by certifications such as CompTIA Security+ or equivalent practical experience is a plus.
Responsibilities:
• Evaluate a high daily volume of security alerts and determine whether events represent genuine threats, routine activity, or inaccurate detections.
• Triage security events, prioritize risk, and escalate advanced or high-impact issues to Security Engineers when deeper analysis is required.
• Contribute to incident response activities from initial identification through containment, documentation, and follow-up review.
• Refine and enhance detection logic to improve visibility, strengthen coverage, and reduce unnecessary alert noise.
• Investigate suspicious behavior related to data loss, insider risk, and other security concerns surfaced through monitoring tools.
• Apply threat intelligence by reviewing indicators of compromise and conducting targeted searches across available telemetry sources.
• Collaborate with IT, platform, and engineering partners to remediate vulnerabilities and address gaps identified during investigations.
• Support hybrid team operations with onsite participation Tuesday through Thursday as needed.• 2–4+ years of experience in security analysis, security operations, or detection and response functions.
• Background working in a Level 1 or Level 2 SOC environment with hands-on alert triage and investigation responsibilities.
• Understanding of networking concepts, security event logs, SIEM workflows, and incident response practices.
• Ability to analyze activity patterns and distinguish legitimate business behavior from potentially malicious actions.
• Strong analytical mindset, investigative problem-solving skills, and a proactive approach to technical learning.
• Experience with cybersecurity tools and concepts such as DLP, Okta, SIEM platforms, application security, and cyber security policies.
• Familiarity with tools or platforms such as SentinelOne, CrowdStrike, AWS Security Hub, or similar security technologies is preferred.
• Relevant security knowledge supported by certifications such as CompTIA Security+ or equivalent practical experience is a plus.
