Managed Detection & Response
SOC Analyst (Tier 2)
Investigate escalated detections, run containment under our client mandates, and turn every incident into a better detection.
Hybrid — Amman
Full-time
3+ years
Our SOC runs a follow-the-sun rotation with real handover discipline. As a Tier 2 analyst you take escalations from triage, establish what actually happened, and act — isolating hosts, revoking sessions, and calling the client when it is serious.
We expect analysts to write detections, not just consume them. Time is protected each sprint for detection engineering.
What we are looking for
- Three or more years in a SOC or CSIRT environment
- Strong grasp of Windows, Linux and cloud telemetry
- Experience writing detection logic in a SIEM query language
- Calm judgement under incident pressure
- Comfortable with a shift rotation including nights
What we offer
Fully remote within EMEA, with quarterly team weeks
Certification budget and paid study leave
10% of your time for research and tooling
Private healthcare and generous leave policy