Skip to content
L&M Cybersecurity

Managed Detection & Response

SOC Analyst (Tier 2)

Investigate escalated detections, run containment under our client mandates, and turn every incident into a better detection.

Hybrid — Amman Full-time 3+ years

Our SOC runs a follow-the-sun rotation with real handover discipline. As a Tier 2 analyst you take escalations from triage, establish what actually happened, and act — isolating hosts, revoking sessions, and calling the client when it is serious.

We expect analysts to write detections, not just consume them. Time is protected each sprint for detection engineering.

What we are looking for

  • Three or more years in a SOC or CSIRT environment
  • Strong grasp of Windows, Linux and cloud telemetry
  • Experience writing detection logic in a SIEM query language
  • Calm judgement under incident pressure
  • Comfortable with a shift rotation including nights

What we offer

Fully remote within EMEA, with quarterly team weeks
Certification budget and paid study leave
10% of your time for research and tooling
Private healthcare and generous leave policy