SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Operations Analyst II

AlphaSense - Remote - Remote - posted 2026-08-20

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

AlphaSense is hiring a Security Operations Analyst II to join its Security Operations team in a fully remote capacity from Canada. This is a Tier 1–2 role for someone past the learning phase who is ready to own alert triage, perform structured investigations, and contribute to detection quality improvements. You will monitor and triage alerts across endpoint, network, cloud, runtime, and identity data sources with accuracy and appropriate urgency. You'll perform structured investigations on escalated or ambiguous alerts by pivoting across log sources, correlating events, and building coherent timelines. You will classify alerts correctly—true positive, false positive, or benign—with documented rationale, identify scope and blast radius on confirmed incidents, and escalate to senior analysts with a complete investigation package including context, evidence, timeline, and hypothesis. In incident response, you'll participate in active response under senior analyst or manager direction, executing containment actions such as endpoint isolation, account suspension, and token revocation as directed. You'll maintain accurate case documentation throughout the incident lifecycle and contribute to post-incident timelines and root cause documentation. Cloud and identity security monitoring is a key focus. You'll monitor cloud audit logs and native threat detection findings for suspicious IAM activity, unusual API calls, and access anomalies. You'll investigate identity provider events including suspicious logins, MFA bypass attempts, session anomalies, and unauthorized app assignments. You'll recognize common cloud-native attack patterns and correlate cloud-side events with endpoint and network telemetry. You'll contribute to detection and quality improvement by flagging false positives and noisy detections with context for tuning, identifying coverage gaps, applying MITRE ATT&CK knowledge to label techniques, and flagging outdated runbook steps. You'll write clear case notes that colleagues can pick up mid-investigation, produce shift handoff summaries, and communicate incident updates effectively. The role expects analytical thinking, thorough documentation, and growing independence, supported by experienced colleagues and mature tooling.

Similar roles