Skip to content
Corpshore Türkiye

Urgent

Security Operations Centre Analyst, Tier 2

You work the second line of a 24 by 7 security operations centre in Ankara, serving clients in financial services, energy, telecommunications and government-adjacent sectors. Tier 1 triages. You investigate. When an alert is real, you determine scope, contain it and brief the client.

What you will do

  • Investigate escalated alerts across endpoint, network, identity and cloud telemetry
  • Determine true positives, establish scope and drive containment per the incident response plan
  • Perform threat hunting against current intelligence and tune rules to cut false positives
  • Write incident documentation a non-technical executive can act on
  • Support KVKK breach assessment where personal data is implicated

What you bring

  • At least three years in a SOC or incident response role, one at second line or above
  • Hands-on command of a SIEM such as Sentinel, Splunk or QRadar, and of EDR tooling
  • Understanding of attacker behaviour mapped to MITRE ATT&CK
  • Turkish at C1, English at C1 and willingness to work twelve hour rotating shifts

Nice to have

  • Certification such as GCIH, GCIA, CySA+ or OSCP
  • Cloud security depth and scripting for automation
  • Experience with OT or ICS environments in energy or utilities

What we offer

  • A four on four off pattern that gives real recovery time
  • Shift allowance on top of base and a funded certification pathway
  • Private health insurance, meal card and transport allowance
  • Progression into threat hunting, detection engineering and SOC management

Apply

The first step takes under two minutes. We respond to every application.

CV upload will be added when the candidate portal goes live. For now you can share your LinkedIn URL and a cover note.

Let us build your Türkiye team

Tell us your function, your scale and your language needs. We will come back to you within six hours.