About the role
Our security operations centre watches client environments around the clock. As a Tier 2 analyst you take the alerts that Tier 1 has triaged and decide what is really happening: whether it is a false positive, a policy problem, or an intrusion that needs to be contained in the next ten minutes.
You will have containment authority, agreed with each client in advance, which means you can isolate a host or block an indicator without waiting for a committee. That authority comes with the expectation that you can justify the decision afterwards in writing.
This is a shift role on a rotating roster covering 24/7, with hybrid working for part of the rotation. You will report to the Head of Cybersecurity.
What you will do
- Investigate escalated alerts across EDR, firewall, identity, email and network telemetry.
- Determine scope and impact, then contain according to the client's agreed playbook.
- Write incident records that a client's board can read and an auditor can follow.
- Hunt proactively for indicators the tooling did not catch, using hypotheses rather than waiting for alerts.
- Tune detections and suppress noise, so the next analyst on shift is not drowning in the same false positives.
- Support incident response engagements, including ransomware recovery, alongside the wider team.
- Contribute to the monthly client threat report and to the internal knowledge base.
- Mentor Tier 1 analysts and review their triage decisions.
What we are looking for
- Three or more years in a SOC, incident response or blue team role.
- Hands-on experience with at least one SIEM, and the ability to write your own queries rather than only running saved ones.
- Working knowledge of EDR/XDR platforms and what their telemetry can and cannot tell you.
- Solid grounding in Windows and Linux internals, Active Directory, and common attacker techniques against them.
- Understanding of network protocols good enough to read a packet capture and form an opinion.
- Familiarity with MITRE ATT&CK as a working tool, not a poster.
- Clear written English. Incident reports are a deliverable and clients read them.
- Arabic or Kurdish (Sorani) for client communication.
- Willingness to work a rotating shift pattern including nights and weekends.
Nice to have
- Certifications such as GCIH, GCIA, CySA+, Security+, CEH or equivalent practical evidence.
- Scripting in Python or PowerShell for enrichment and automation.
- Digital forensics experience: memory analysis, disk imaging, timeline reconstruction.
- Exposure to OT or industrial environments.
- Threat intelligence work, including dark web credential monitoring.
What we offer
- Sponsored certification including a covered second attempt if an exam does not go your way.
- Real incidents. We respond to genuine intrusions, so you will not spend your career on simulated ones.
- Shift allowance on top of base salary, and a roster published in advance so you can plan your life.
- A published competency framework for the security track.
- Health cover for you and your dependants, transport allowance and 22 days of leave.
- Time allocated for research and detection engineering, not only queue work.
What the lab exercise looks like. Two paid hours with a realistic scenario: some telemetry, an alert, and a question about what happened. We are interested in how you reason and what you check first, not whether you reach a predetermined answer.
How to apply
Send your CV to careers@oktagate.com with the subject line "Application: SOC Analyst Tier 2". Tell us about an incident you worked, what you got right and what you would check earlier next time. Home lab and CTF work counts.
OKTAGATE hires on ability. We welcome applications regardless of gender, background or religion, and we will make reasonable adjustments to our process on request.