Home › Companies › Iaim › SOC Analyst - Level 2
SOC Analyst - Level 2
Iaim · Remote · Active · BambooHR
Job facts
| Field | Value |
|---|---|
| Company | Iaim |
| Title | SOC Analyst - Level 2 |
| Normalized title | - |
| Department / team | SOC |
| Location | Any, Any, Pakistan |
| Work model | Remote / Remote |
| Employment type | Full Time |
| Salary | - |
| Status | active |
| ATS provider | BambooHR |
| Posted / first seen | 2026-04-27 / 2026-05-30 |
| Changed / last seen | 2026-05-30 / 2026-06-06 |
Related slices
| Page | What it contains | Open |
|---|---|---|
| Company jobs | Active postings from Iaim. | Open |
| Company breakdowns | Role, location, ATS, and work model facets for this company. | Open |
| ATS provider jobs | Active postings observed through BambooHR. | Open |
| Provider filtered search | The same provider as a filtered job collection. | Open |
| City jobs | Active postings in Any. | Open |
| Department jobs | Active postings in SOC. | Open |
| Work model jobs | Active Remote postings. | Open |
| Lifecycle events | Open, update, close, and reopen events for this posting. | Open |
| Original posting | Canonical source or apply URL captured from the ATS. | Open |
Linked records
| Company | Iaim |
| Source | 8a538a5c-f612-4aa9-986e-df08987bc86e |
| ATS provider | BambooHR |
Description
Job Title: SOC Analyst – Level 2
Location: Pakistan (Remote)
Employment Type: Full-time
Work Model: Remote (24/7 Shift Rotation)
About Us:
Arancia is a Canadian Cybersecurity Consulting, Advisory and Technology firm based in Mississauga, Ontario. Our team consists of geographically diverse professionals dedicated to solving complex cybersecurity challenges.
Offering a robust set of services across the IT and Cybersecurity landscape, supported by our proprietary security platform DarkSense, Arancia delivers high-quality security solutions across industries such as Healthcare, Financial Services, and Critical Infrastructure to a global client base.
Operating a modern 24/7 Security Operations Center, we combine advanced tooling with an evolving Agentic SOC platform to reduce noise, improve detection quality, and enable analysts to focus on meaningful investigations.
If you are interested in working in a fast-paced, growing cybersecurity environment with a strong focus on innovation, investigation quality, and operational excellence, this role is for you.
Job Summary:
We are seeking a skilled and highly motivated SOC Analyst – Level 2 to join our Security Operations team. This role is ideal for someone with hands-on experience in SOC operations, threat investigation, and incident response.
As an L2 SOC Analyst, you will take ownership of advanced triage and investigation of alerts escalated from L1, execute containment actions across customer environments, and drive detection quality through structured tuning and feedback loops.
You will work closely with L1 analysts, Detection Engineering, Incident Response, and Threat Intelligence teams, as well as our Agentic SOC platform, to reduce dwell time and false positives. During evening shifts, you will also transition into proactive threat hunting, using dedicated time blocks to identify detection gaps and improve coverage.
This role serves as a direct progression pathway into L3, Threat Hunting, Detection Engineering, or Incident Response.
Key Responsibilities:
Alert Triage & Investigation:
Perform advanced triage of alerts escalated from L1, determining true vs false positives. Investigate security events across endpoint, identity, network, and cloud telemetry. Correlate events and map adversary behavior to MITRE ATT&CK while enriching findings with relevant threat intelligence context.
Incident Response Execution:
Execute or coordinate containment actions including host isolation (EDR), account disablement (Entra ID / IAM), and blocking indicators such as IPs, domains, or hashes. Partner with Incident Response teams on high-severity or multi-system incidents and document actions, timelines, and evidence with a clear chain of reasoning.
Threat Hunting:
Conduct hypothesis-driven threat hunting across endpoint, identity, and cloud datasets, particularly during evening shifts and on rotation. Convert hunt findings into new detections or tuning recommendations and maintain proper documentation of hunts and derived detections.
Detection Quality & Tuning:
Provide structured feedback to Detection Engineering on false positives, detection gaps, and tuning opportunities. Validate new detection rules (Sigma, KQL, SPL, or equivalent) before production rollout and contribute to playbook authoring and continuous improvement.
Case Management & Reporting:
Produce clear, complete incident reports suitable for both technical and non-technical stakeholders. Track and support SLA metrics including MTTD, MTTR, and MTTC. Participate in structured shift handovers and post-incident reviews.
Collaboration & Cross-Functional Teamwork:
Collaborate closely with internal teams including Detection Engineering, Incident Response, and Threat Intelligence. Mentor L1 analysts on triage quality and investigation techniques, and contribute to internal knowledge bases and lessons-learned sessions.
Qualifications:
Experience:
2–5 years of experience in a SOC, Incident Response, or equivalent hands-on blue team role. Demonstrable experience handling real security incidents end-to-end with a strong understanding of SOC workflows, escalation paths, and on-shift discipline.
Industry Knowledge:
Strong understanding of cybersecurity concepts including endpoint, network, identity, and cloud security. Solid grounding in MITRE ATT&CK and its operational application in investigations.
Technical Skills:
Hands-on experience with at least one modern SIEM (Microsoft Sentinel, Elastic SIEM, OpenSearch, or similar) and at least one EDR solution (Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, or similar). Working knowledge of identity and cloud telemetry (Entra ID, Office 365, AWS/Azure logs). Proficiency in KQL is required; additional query languages such as SPL or OpenSearch DQL are a plus. Basic scripting in Python or PowerShell for automation and enrichment.
Analytical & Soft Skills:
Strong investigative mindset with the ability to pivot across data sources and build timelines. Clear written communication suitable for customer-facing reports. Ability to remain calm under pressure during live incidents and shift transitions. Team-oriented with a willingness to mentor and continuously learn.
Education:
Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent practical experience).
Certifications:
Certifications such as BTL1, CySA+, GCIH, Microsoft SC-200, or CompTIA Security+ are considered a plus.
Nice to Have:
Exposure to SOAR platforms (Cortex XSOAR, Shuffle, Tines), threat intelligence platforms (MISP, OpenCTI), malware analysis or sandboxing tools (Any.Run, Joe Sandbox, Cuckoo), network detection tools (Zeek, Suricata), and cloud security experience across Azure, AWS, or GCP.
Shift Details:
This role operates on a 24/7 rotating schedule including day, evening, and night shifts. Evening shifts follow a hybrid structure combining live queue work with scheduled threat hunting blocks. Structured handovers are conducted at every shift change to ensure continuity on active incidents. Shift allowances apply for evenings, nights, weekends, and public holidays.
Onboarding (First 30 Days):
Days 1–15 — Shadowing:
Pair with senior analysts across shifts to observe live investigations, understand playbooks, tooling, customer environments, and escalation thresholds. No production alert ownership during this phase.
Days 16–30 — Supervised Queue:
Take ownership of alerts under direct supervision. All cases are reviewed with structured feedback on triage decisions, incident response actions, and reporting quality.
Day 30+ — Full Ownership:
Independently manage the queue, continue shadowing complex incidents, and rotate into threat hunting responsibilities.
What a Typical Shift Looks Like:
Start by reviewing handover notes, open incidents, and any ongoing hunts. Work through the escalation queue by triaging, investigating, containing, and documenting incidents. During evening shifts, execute scheduled hunts or deep-dive into complex investigations. End the shift by updating case notes, preparing a clear handover, and flagging detection tuning opportunities.
Why Join Us:
Modern SOC stack and tooling
Agentic SOC platform enabling AI-assisted triage and investigations
Clear career progression into L3, Threat Hunting, Detection Engineering, or IR
Structured onboarding and continuous learning support
Investigation-led culture focused on quality over ticket volume
Hours:
40 hours per week (shift-based schedule)
Compensation:
Market competitive salary based on experience & qualifications.
Full job record
| Job ID | dc7f6d62248c90ba06ccd14af373a1367fc4efb9 |
| Org ID | 6f376d12-8968-4f68-a2af-d41e63fa97ef |
| Source ID | 8a538a5c-f612-4aa9-986e-df08987bc86e |
| Board ID | 8a538a5c-f612-4aa9-986e-df08987bc86e |
| Provider | bamboohr |
| Provider Job Key | 169 |
| Title | SOC Analyst - Level 2 |
| Normalized Title | — |
| Status | active |
| Active | yes |
| Location Text | — |
| Department | SOC |
| Team | — |
| Employment Type | full_time |
| Workplace Type | remote |
| Remote Policy | remote |
| Country | Pakistan |
| Region | Any |
| City | Any |
| Salary Raw | — |
| Salary Min | — |
| Salary Max | — |
| Salary Currency | — |
| Salary Period | — |
| Source URL | https://iaim.bamboohr.com/careers/169 |
| Apply URL | https://iaim.bamboohr.com/careers/169 |
| First Seen At | 2026-05-30 05:58:26Z |
| Last Seen At | 2026-06-06 10:31:32Z |
| Last Checked At | 2026-06-06 10:31:32Z |
| Last Changed At | 2026-05-30 05:58:26Z |
| Inactive At | — |
| Source Posted At | 2026-04-27 00:00:00Z |
| Source Updated At | — |
| Raw Payload Uri | s3://job-postings-prod-raw-590183727216/raw/provider=bamboohr/board=iaim/date=2026-06-06/2026-06-06T10-31-31-453Z-a9e90a4fd87ca5696a6a7ce39b3f16552159869fb4acb977e855893cae5c7049.json |
Event Fields
{
"content_hash": "13142793fa915b75d29312f1335d77c25c12c8d5e7ee2b1978aca209f395e530",
"source_hash": "660106aff89b05a1969d4bf8fefbcff3cb943624c28da918f54e6c3d47f475d4",
"last_changed_at": "2026-05-30T05:58:26.232Z",
"active_status": "active"
}Parsed Structured
{
"language": "en",
"location": {
"raw": "Any, Any, Pakistan",
"city": "Any",
"region": "Any",
"country": "Pakistan",
"is_remote": true,
"confidence": 0.8
},
"salary_max": null,
"salary_min": null,
"inferred_at": "2026-06-06T10:31:32.766Z",
"launch_scope": {
"reason": "bamboohr_production_catalog",
"included": true,
"location": {
"raw": "Any, Any, Pakistan",
"city": "Any",
"region": "Any",
"country": "Pakistan",
"is_remote": true,
"confidence": 0.8
},
"countries": [
"Pakistan"
]
},
"remote_policy": "remote",
"salary_period": null,
"workplace_type": "remote",
"salary_currency": null
}Extensions
{}Native Structured
{
"list_job": {
"id": "169",
"isRemote": null,
"location": {
"city": null,
"state": null
},
"atsLocation": {
"city": "Any",
"state": null,
"country": "Pakistan",
"province": "Any"
},
"departmentId": "18784",
"locationType": "1",
"jobOpeningName": "SOC Analyst - Level 2",
"departmentLabel": "SOC",
"employmentStatusLabel": "Full-Time"
},
"detail_errors": [],
"detail_job_opening": {
"location": {
"city": null,
"state": null,
"postalCode": null,
"addressCountry": null
},
"datePosted": "2026-04-27",
"atsLocation": {
"city": "Any",
"state": "Any",
"country": "Pakistan",
"countryId": "163"
},
"description": "<p><span style=\"font-weight: bold\">Job Title: </span>SOC Analyst – Level 2 </p>\n<p><span style=\"font-weight: bold\">Location:</span> Pakistan (Remote)</p>\n<p><span style=\"font-weight: bold\">Employment Type: </span>Full-time</p>\n<p><span style=\"font-weight: bold\">Work Model:</span> Remote (24/7 Shift Rotation)</p>\n<p><br></p>\n<p><span style=\"font-weight: bold\">About Us:</span></p>\n<p>Arancia is a Canadian Cybersecurity Consulting, Advisory and Technology firm based in Mississauga, Ontario. Our team consists of geographically diverse professionals dedicated to solving complex cybersecurity challenges.</p>\n<p>Offering a robust set of services across the IT and Cybersecurity landscape, supported by our proprietary security platform DarkSense, Arancia delivers high-quality security solutions across industries such as Healthcare, Financial Services, and Critical Infrastructure to a global client base.</p>\n<p>Operating a modern 24/7 Security Operations Center, we combine advanced tooling with an evolving Agentic SOC platform to reduce noise, improve detection quality, and enable analysts to focus on meaningful investigations.</p>\n<p>If you are interested in working in a fast-paced, growing cybersecurity environment with a strong focus on innovation, investigation quality, and operational excellence, this role is for you.</p>\n<p><br></p>\n<p><span style=\"font-weight: bold\">Job Summary:</span></p>\n<p>We are seeking a skilled and highly motivated SOC Analyst – Level 2 to join our Security Operations team. This role is ideal for someone with hands-on experience in SOC operations, threat investigation, and incident response.</p>\n<p>As an L2 SOC Analyst, you will take ownership of advanced triage and investigation of alerts escalated from L1, execute containment actions across customer environments, and drive detection quality through structured tuning and feedback loops.</p>\n<p>You will work closely with L1 analysts, Detection Engineering, Incident Response, and Threat Intelligence teams, as well as our Agentic SOC platform, to reduce dwell time and false positives. During evening shifts, you will also transition into proactive threat hunting, using dedicated time blocks to identify detection gaps and improve coverage.</p>\n<p>This role serves as a direct progression pathway into L3, Threat Hunting, Detection Engineering, or Incident Response.</p>\n<p><br></p>\n<p><span style=\"font-weight: bold\">Key Responsibilities:</span></p>\n<ul>\n<li><span style=\"font-weight: bold\">Alert Triage & Investigation:</span></li>\n</ul>\n<p>Perform advanced triage of alerts escalated from L1, determining true vs false positives. Investigate security events across endpoint, identity, network, and cloud telemetry. Correlate events and map adversary behavior to MITRE ATT&CK while enriching findings with relevant threat intelligence context.</p>\n<ul>\n<li><span style=\"font-weight: bold\">Incident Response Execution:</span></li>\n</ul>\n<p>Execute or coordinate containment actions including host isolation (EDR), account disablement (Entra ID / IAM), and blocking indicators such as IPs, domains, or hashes. Partner with Incident Response teams on high-severity or multi-system incidents and document actions, timelines, and evidence with a clear chain of reasoning.</p>\n<ul>\n<li><span style=\"font-weight: bold\">Threat Hunting:</span></li>\n</ul>\n<p>Conduct hypothesis-driven threat hunting across endpoint, identity, and cloud datasets, particularly during evening shifts and on rotation. Convert hunt findings into new detections or tuning recommendations and maintain proper documentation of hunts and derived detections.</p>\n<ul>\n<li><span style=\"font-weight: bold\">Detection Quality & Tuning:</span></li>\n</ul>\n<p>Provide structured feedback to Detection Engineering on false positives, detection gaps, and tuning opportunities. Validate new detection rules (Sigma, KQL, SPL, or equivalent) before production rollout and contribute to playbook authoring and continuous improvement.</p>\n<ul>\n<li><span style=\"font-weight: bold\">Case Management & Reporting:</span></li>\n</ul>\n<p>Produce clear, complete incident reports suitable for both technical and non-technical stakeholders. Track and support SLA metrics including MTTD, MTTR, and MTTC. Participate in structured shift handovers and post-incident reviews.</p>\n<ul>\n<li><span style=\"font-weight: bold\">Collaboration & Cross-Functional Teamwork:</span></li>\n</ul>\n<p>Collaborate closely with internal teams including Detection Engineering, Incident Response, and Threat Intelligence. Mentor L1 analysts on triage quality and investigation techniques, and contribute to internal knowledge bases and lessons-learned sessions.</p>\n<p><br></p>\n<p><span style=\"font-weight: bold\">Qualifications:</span></p>\n<ul>\n<li><span style=\"font-weight: bold\">Experience:</span></li>\n</ul>\n<p>2–5 years of experience in a SOC, Incident Response, or equivalent hands-on blue team role. Demonstrable experience handling real security incidents end-to-end with a strong understanding of SOC workflows, escalation paths, and on-shift discipline.</p>\n<ul>\n<li><span style=\"font-weight: bold\">Industry Knowledge:</span></li>\n</ul>\n<p>Strong understanding of cybersecurity concepts including endpoint, network, identity, and cloud security. Solid grounding in MITRE ATT&CK and its operational application in investigations.</p>\n<ul>\n<li><span style=\"font-weight: bold\">Technical Skills:</span></li>\n</ul>\n<p>Hands-on experience with at least one modern SIEM (Microsoft Sentinel, Elastic SIEM, OpenSearch, or similar) and at least one EDR solution (Microsoft Defender for Endpoint, CrowdStrike, SentinelOne, or similar). Working knowledge of identity and cloud telemetry (Entra ID, Office 365, AWS/Azure logs). Proficiency in KQL is required; additional query languages such as SPL or OpenSearch DQL are a plus. Basic scripting in Python or PowerShell for automation and enrichment.</p>\n<ul>\n<li><span style=\"font-weight: bold\">Analytical & Soft Skills:</span></li>\n</ul>\n<p>Strong investigative mindset with the ability to pivot across data sources and build timelines. Clear written communication suitable for customer-facing reports. Ability to remain calm under pressure during live incidents and shift transitions. Team-oriented with a willingness to mentor and continuously learn.</p>\n<ul>\n<li><span style=\"font-weight: bold\">Education:</span></li>\n</ul>\n<p>Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent practical experience).</p>\n<ul>\n<li><span style=\"font-weight: bold\">Certifications:</span></li>\n</ul>\n<p>Certifications such as BTL1, CySA+, GCIH, Microsoft SC-200, or CompTIA Security+ are considered a plus.</p>\n<p><br></p>\n<p><span style=\"font-weight: bold\">Nice to Have:</span></p>\n<p>Exposure to SOAR platforms (Cortex XSOAR, Shuffle, Tines), threat intelligence platforms (MISP, OpenCTI), malware analysis or sandboxing tools (Any.Run, Joe Sandbox, Cuckoo), network detection tools (Zeek, Suricata), and cloud security experience across Azure, AWS, or GCP.</p>\n<p><br></p>\n<p><span style=\"font-weight: bold\">Shift Details:</span></p>\n<p>This role operates on a 24/7 rotating schedule including day, evening, and night shifts. Evening shifts follow a hybrid structure combining live queue work with scheduled threat hunting blocks. Structured handovers are conducted at every shift change to ensure continuity on active incidents. Shift allowances apply for evenings, nights, weekends, and public holidays.</p>\n<p><br></p>\n<p><span style=\"font-weight: bold\">Onboarding (First 30 Days):</span></p>\n<ul>\n<li><span style=\"font-weight: bold\">Days 1–15 — Shadowing:</span><br>Pair with senior analysts across shifts to observe live investigations, understand playbooks, tooling, customer environments, and escalation thresholds. No production alert ownership during this phase.</li>\n<li><span style=\"font-weight: bold\">Days 16–30 — Supervised Queue:</span><br>Take ownership of alerts under direct supervision. All cases are reviewed with structured feedback on triage decisions, incident response actions, and reporting quality.</li>\n<li><span style=\"font-weight: bold\">Day 30+ — Full Ownership:</span><br>Independently manage the queue, continue shadowing complex incidents, and rotate into threat hunting responsibilities.</li>\n</ul>\n<p><br></p>\n<p><span style=\"font-weight: bold\">What a Typical Shift Looks Like:</span></p>\n<p>Start by reviewing handover notes, open incidents, and any ongoing hunts. Work through the escalation queue by triaging, investigating, containing, and documenting incidents. During evening shifts, execute scheduled hunts or deep-dive into complex investigations. End the shift by updating case notes, preparing a clear handover, and flagging detection tuning opportunities.</p>\n<p><br></p>\n<p><span style=\"font-weight: bold\">Why Join Us:</span></p>\n<ul>\n<li>Modern SOC stack and tooling</li>\n<li>Agentic SOC platform enabling AI-assisted triage and investigations</li>\n<li>Clear career progression into L3, Threat Hunting, Detection Engineering, or IR</li>\n<li>Structured onboarding and continuous learning support</li>\n<li>Investigation-led culture focused on quality over ticket volume</li>\n</ul>\n<p><br></p>\n<p><span style=\"font-weight: bold\">Hours:</span></p>\n<p>40 hours per week (shift-based schedule)</p>\n<p><br></p>\n<p><span style=\"font-weight: bold\">Compensation:</span></p>\n<p>Market competitive salary based on experience & qualifications.</p>",
"compensation": "DOE",
"departmentId": "18784",
"locationType": "1",
"seekPromoted": false,
"jobCategoryId": null,
"jobOpeningName": "SOC Analyst - Level 2",
"departmentLabel": "SOC",
"jobOpeningStatus": "Open",
"minimumExperience": "Mid-level",
"jobOpeningShareUrl": "https://iaim.bamboohr.com/careers/169",
"employmentStatusLabel": "Full-Time"
}
}Get this page with API
Rendered from the bluedoor Job Postings API. Reproduce it:
GET https://api.bluedoor.sh/job-postings/v1/jobs/dc7f6d62248c90ba06ccd14af373a1367fc4efb9?include=descriptionJSONGET https://api.bluedoor.sh/job-postings/v1/orgs/6f376d12-8968-4f68-a2af-d41e63fa97efJSONGET https://api.bluedoor.sh/job-postings/v1/sources/8a538a5c-f612-4aa9-986e-df08987bc86eJSONGET https://api.bluedoor.sh/job-postings/v1/jobs/dc7f6d62248c90ba06ccd14af373a1367fc4efb9/eventsJSON