RAJ
Verified from Aspenview Technology Partners's careers page · Greenhouse

SOC Analyst (Tier 1, Tier 2 & Tier 3)

Aspenview Technology PartnersLATAMNot SpecifiedPosted Oct 5, 2026

Apply faster

Fill most application fields automatically from your RealAnalystJobs profile. You review, you submit.

Included with the unlock (from $2 for 30 days)

About this role

Build the Future with AspenView Technology Partners At AspenView, we are passionate about transforming the way organizations approach technology. We specialize in creating high-performing, nearshore IT teams to help North American clients innovate faster and more efficiently. As we continue to grow, we’re looking for exceptional people to join our team and help drive impactful change across industries. About the Role AspenView is building a dedicated, 24/7 Security Operations Center team for a large U.S. consumer lender in the financial services sector, and we are hiring at three levels: Tier 1 Monitoring Analysts (junior), Tier 2 Analysts and Shift Leads (mid-level), and Tier 3 Senior SOC Analysts (senior). All roles are full-time, on site in Bogotá or Buenos Aires, and dedicated to a single client, working on U.S. Eastern Time with senior leads in the United States. Alerts arrive in ServiceNow already enriched. Tier 1 validates, classifies and escalates them following the runbook; Tier 2 decides which escalations are real and owns them through to client notification; Tier 3 takes every P1, major incident and Tier 2 request for support, scoping the impact, building the timeline, recommending containment and performing first-response forensics before the U.S.-based Incident Response Lead steps in. Incident declaration and containment execution sit with the client; the team escalates with evidence and a recommendation. The team is built for round-the-clock coverage. Six Tier 1 analysts cover three rotating 8-hour shifts (07:00–15:00, 15:00–23:00 and 23:00–07:00) seven days a week, including nights, weekends and public holidays. Three Tier 2 analysts rotate across the day and evening shifts and share the overnight on-call. Two Tier 3 analysts work business hours and share a 24/7 on-call rotation with the Incident Response Lead. All analysts report to the on-site SOC Manager. All analysts work from AspenView's access-controlled delivery suite, which operates under a clean-desk rule with VDI-only access to the client's environment and tooling. Access to the client environment requires identity, criminal-background, employment and education checks, repeated periodically. Tier 1 to Tier 3 is a defined career path, and detection engineering, threat hunting and incident response lead work all sit within the same team. What You Will Do Tier 1 – Monitoring • Own the live alert queue: acknowledgement, validation, classification and prioritization against the agreed severity matrix. • Check enrichment and pull additional context from Elastic, CrowdStrike, Microsoft Defender and Okta before making a call, and work runbooks for common alert types such as reported phishing, malware detections, risky or impossible-travel sign-ins and policy violations. • Deliver clean escalations to the Tier 2 shift lead, keep audit-ready ServiceNow ticket records, and write shift handovers covering open cases. • Serve as the only analyst on the console during night shifts, with Tier 2 and Tier 3 on call, and judge when to wake them. Tier 2 – Shift Lead • Run the day or evening shift: who is working what, what is open, and a written handover the next shift acknowledges before you leave. • Own every escalation raised on your shift, from investigation through to client notification, plus overnight escalations when on call. • Investigate validated or ambiguous alerts, correlating Elastic, CrowdStrike, Microsoft Defender, Okta and AWS logs to reach a call you can defend, and document hypothesis, evidence, reasoning and disposition in ServiceNow. • Escalate to Tier 3 with scope, evidence and a working hypothesis, coach Tier 1 analysts, and provide tuning feedback to Detection Engineering on noisy or missed rules. Tier 3 – Senior Analyst • Own P1 cases, major incidents and Tier 2 requests for support: scoping what is affected, building the timeline, and giving the client the evidence it needs to decide whether to declare an incident. • Write evidence-backed containment recommendations for the client's teams to execute. • Perform first-response DFIR: endpoint triage in CrowdStrike and Microsoft Defender, memory and disk artifacts, Okta session analysis and AWS log review, with evidence preserved properly, working across Abstract Security, Elastic and ServiceNow. • Hold escalation authority over Tier 2, review and coach their work, produce incident write-ups for the client's security leadership, and feed detection gaps back to Detection Engineering. What You Bring Education • Bachelor's degree in Cybersecurity, Computer Science, Information Systems or a related field, or equivalent hands-on experience (all levels). Experience • All levels: English strong enough to escalate, brief and write reports for a U.S. security team without an intermediary (B2 or above), and willingness to work the shift or on-call pattern for your level. • Tier 1: Early-career professional with hands-on exposure to security monitoring through a SOC, a NOC with security duties, or a serious lab or CTF record. • Tier 2: Several years of SOC or security investigation work beyond triage, having closed incidents rather than only escalated them, plus experience leading a shift or owning escalations end to end. • Tier 3: Several years in security operations or incident response, with an incident you can walk through end to end, and the judgment to recommend containment that stops an attacker without breaking the systems the business runs on. Technical Expertise • Tier 1: Log fundamentals (reading Windows events, authentication logs and proxy logs) and triage discipline: following a runbook exactly and noticing when an alert does not fit it. • Tier 2: Querying logs directly in a SIEM (Elastic, Splunk, Microsoft Sentinel, QRadar or equivalent), joining evidence across endpoint, identity and cloud sources, and solid fundamentals in Windows event logs, SSO and MFA flows, and phishing and malware patterns mapped to MITRE ATT&CK. •

Description from Aspenview Technology Partners's public careers feed, reproduced so you can read the role here. Apply on the company's own site; RealAnalystJobs never submits anything for you.

Raj