The L2 SOC Analyst is responsible for advanced security monitoring, investigation, and incident response across enterprise environments. This role focuses on deep analysis of alerts, threat validation, escalation handling, and coordination with L3 teams, using tools such as Microsoft Defender, Microsoft Sentinel, Cofense, Proofpoint, and Splunk.
Key Responsibilities
Perform in depth analysis and triage of security alerts escalated from L1 analysts.
Investigate security incidents across endpoints, email, network, and cloud environments.
Use Microsoft Defender (Defender for Endpoint, Defender for Office 365, Defender for Cloud) to analyze endpoint and identity based threats.
Monitor, investigate, and respond to incidents using Microsoft Sentinel, including querying using KQL and tuning detection rules.
Analyze phishing and email based threats using Cofense and Proofpoint, including malware, spoofing, and BEC incidents.
Perform log analysis and correlation using Splunk to identify anomalous behavior and advanced threats.
Validate true positives, identify root cause,
and recommend remediation actions.
Handle incident escalation to L3 teams and coordinate with IT, IR, and infrastructure teams.
Support containment, eradication, and recovery activities during security incidents.
Create and update incident reports, playbooks, and SOPs.
Assist in use case tuning, false positive reduction, and dashboard improvements.
Participate in threat hunting activities and continuous improvement initiatives.
Required Skills & Experience
3–6 years of experience in SOC operations or cybersecurity monitoring roles.
Solid hands on experience with Microsoft Defender and Microsoft Sentinel.
Practical experience with Splunk for log analysis and investigations.
Experience handling phishing investigations using Cofense and Proofpoint.
Solid understanding of:
MITRE ATT&CK; framework
Incident response lifecycle
Malware, ransomware, phishing, and credential based attacks
Experience with KQL (Senti
📌 soc analsyt (Bengaluru)
🏢 CGI
📍 Bengaluru