21 Aug
|
Incedo
|
Gurugram
Job Description – SOC Analyst (L2)
Role: Security Operations Center (SOC) – L2 Analyst
Experience
4–7 years of experience in Cyber Security Operations / SOC
3+ years of hands-on experience in security monitoring, incident investigation, and incident response
Key Responsibilities
Investigate and analyze security incidents escalated by the L1 SOC team
Perform alert triage, log analysis, event correlation, and root cause analysis
Validate security alerts and distinguish true positives from false positives
Investigate phishing, malware, unauthorized access, privilege escalation, and cloud security incidents
Monitor and analyze security events across endpoints, networks, cloud, and identity platforms
Coordinate with L3 engineers, infrastructure teams, and other stakeholders for incident remediation
Maintain incident documentation, investigation reports, and ticket updates
Ensure SLA adherence in a 24x7 SOC environment
Must-Have Skills
SIEM: Splunk, QRadar, Microsoft Sentinel, LogRhythm
EDR/XDR: CrowdStrike, Microsoft Defender,
SentinelOne, Cortex XDR
Security Monitoring: Firewall, IDS/IPS, WAF, VPN, Email Security, Endpoint Security
Log Analysis: Windows, Linux, Active Directory, Microsoft 365, CloudTrail
Threat Analysis: IOC validation, Threat Intelligence, MITRE ATT&CK;
Networking: TCP/IP, DNS, HTTP/HTTPS, SMTP
Positive-to-Have Skills
AWS or Azure security
PowerShell or Python
Knowledge of the NIST Incident Response Framework
Preferred Certifications
Security+
SC-200
CEH
CySA+
Splunk Certified User
IBM QRadar SIEM Foundation
Education
Bachelor's degree in Computer Science, Information Technology, Cyber Security, or a related field.
Work Location & Shift
24x7 rotational shift
Willingness to work on weekends and holidays as required
Keywords
SOC, SIEM, Splunk, QRadar, Microsoft Sentinel, EDR, CrowdStrike, Incident Response, Threat Hunting, Log Analysis
📌 Security Operations Center Analyst- (Gurugram)
🏢 Incedo
📍 Gurugram