L2 Security Analyst

🗓️ Posted 2026-08-26 2 Locations Full-time Hybrid ICT

Company shared salary

NA

Market rate

S$4,500–S$7,500/mo (S$54,000–S$90,000/yr)

Based on similar roles (title + domain + location).

About the Company

Ensign is hiring As a Level 2 Security Analyst in a Managed Security Service Provider (MSSP) environment, you will serve as an advanced escalation point for Tier 1 analysts, handling complex alerts and security incidents across multiple client environments. Your primary responsibility is to investigate threats in-depth, guide incident response efforts, enhance detection capabilities, and ensure clients are protected with timely and accurate responses. This role demands strong technical, analytical, and communication skills to succeed in a fast-paced, multi-tenant SOC. Key Responsibilities: Analyze and respond to escalated alerts from Tier 1 analysts across multiple clients. Conduct in-depth investigations using SIEM, EDR, NDR, firewall logs, and other security tools. Perform malware analysis, log correlation, and network traffic analysis to identify attack vectors. Execute containment, eradication, and recovery procedures using predefined runbooks and playbooks. Escalate and coordinate with Level 3 analysts or incident response teams for high-severity incidents. Provide technical guidance, support, and mentoring to Tier 1 analysts. Identify gaps in detection capabilities and recommend improvements in correlation rules, tuning, and alerts. Support proactive threat hunting initiatives based on IOCs, TTPs, and contextual threat intelligence. Monitor external threat intelligence feeds and correlate them with client telemetry to identify potential risk

Requirements

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field-or equivalent work experience.
  • -4 years of experience in a Security Operations Center or similar cybersecurity environment.
  • Strong experience with SIEM platforms (e.g., Splunk, Sentinel, QRadar).
  • Hands-on experience with EDR tools (e.g., CrowdStrike, SentinelOne, Microsoft Defender).
  • Familiarity with NDR and SOAR platforms is a plus (e.g., Darktrace, Corelight, Cortex XSOAR).
  • Strong understanding of networking protocols, log analysis, and system administration (Windows/Linux).
  • Knowledge of malware behaviors, phishing techniques, and MITRE ATT&CK framework.
  • Familiarity with case management tools (e.g., Jira, ServiceNow, TheHive). Certifications (preferred):
  • CompTIA Security+, CySA+, or equivalent.
  • GIAC certifications (e.g., GCIH, GCIA, GCFA).
  • CEH, or vendor-specific certifications (e.g., Microsoft SC-200, CrowdStrike CCFR). Key Competencies:
  • Strong analytical and problem-solving skills.
  • Excellent written and verbal communication-especially in client-facing documentation and briefings.
  • Ability to handle multiple investigations and prioritize effectively under pressure.
  • Customer-centric mindset with attention to SLA adherence and service quality.
  • Collaborative, team-oriented, and proactive with continuous learning attitude. Shift Expectations:
  • Participation in shift rotations (24/7 support model, if applicable), including weekends and public holidays.
  • On-call support may be required depending on client SLAs and incident severity.