Security Operations Analyst II
VF CorporationAbout the role
Security Operations Center (SOC) Analyst II
Now that you’ve found the job description, what’s next?
At VF, we strive to foster a culture of belonging based on respect, connection, openness, and authenticity. As a purpose-led, performance-driven company, we are committed to inclusion, diversity, equity, and action. So, before we get to the job details, take a minute to learn a little more about us – our values and our culture - visit VF Careers or www.vfc.com.
What will you do?
A day in the life of a Security Operations Center (SOC) Analyst II at VF looks a little like this.
As technology continues to advance so does the threat landscape. Attackers are now using more sophisticated tactics to evade security controls. As a result, VF must also continue to advance its capabilities in threat detection and monitoring systems.
The SOC Tier II Analyst is responsible for monitoring, analysis, response, and escalation of security incidents and events. The Security Operations Center is the first line of detection and defense which actively monitors the SIEM (Security Information & Event Management), reviews log and event data, and works tickets associated with said data. Providing research using internal and open-source tools, resolving and escalating incidents using established policies and procedures.
Let’s break down that day-in-the-life a bit more.
Monitoring and Analysis:
- Monitor and analyze logs, alerts, and external data sources to determine any security and/or operational impact on the organization.
- Monitor the SIEM environment for the global organization, providing resolution to events and incidents triggered within the SIEM tool as part of day-to-day operations.
- Address security events, analyze data, and provide recommended actions or escalate to incident analysts for further review.
Research and Threat Intelligence:
- Conduct research on security events and threat intelligence using internal and open-source tools.
- Perform proactive threat research and validation of security event data.
- Engage in threat hunting activities to proactively identify potential threats and vulnerabilities within the network.
Incident Response:
- Serve as an escalation point for Tier I SOC Analysts; resolve or escalate cybersecurity incidents according to established policies and procedures.
- Collaborate with technical teams to identify, investigate, resolve, and mitigate security events as part of the Incident Response Plan.
- Participate in incident post-mortem analysis to identify root causes and recommend improvements to prevent future incidents.
Threat Detection:
- Ensure critical infrastructure reports into the SIEM and work with appropriate teams to remediate identified deficiencies.
- Create reference sets within the SIEM tool to support Tier 1 SOC Analysts in threat research.
- Evaluate unwarranted changes within the environment as part of monitoring rules within the SIEM tool.
- Enhance detections, alerts, and other cyber event correlation rules within the SIEM to reduce false positives.
Documentation and Reporting:
- Perform documentation of event analysis and record this data within our Incident Tracking tool, ensuring all relevant data is captured within each incident.
- Approve various security requests originated by the Tier I SOC Analysts.
Training and Development:
- Train new SOC Tier I Analysts on security tools and SOC procedures.
- Represent the Security Operations team in various SOC, Incident Response, and Cyber Security projects.
- Work on optimizing and fine-tuning security tools and systems to improve detection and response capabilities.
What do you need to succeed?
We all have unique skills that we bring to work and celebrate every day. For this role, there are foundation skills you’ll need to succeed and excel. Additionally, while formal education in a related field is great to have, we are most interested in your 3+ years of experience and professional achievements.
The foundation skills you will need in this position are:
- Experience executing security incident handling and investigation processes and procedures.
- Familiarity with modern EDR/XDR tools. Experience with Crowdstrike Falcon considered a plus.
- Proficiency in digital forensics and incident response (DFIR) methodologies and execution across common enter
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s