29 Aug
|
Recruise
|
India
About the role:
The SOC Analyst L2 is responsible for investigating and responding to complex cybersecurity incidents escalated from Level 1 analysts. The role performs advanced analysis, validates security events, coordinates containment activities, and supports incident response while contributing to threat hunting and detection improvements.
Responsibilities:
Operations:
- Perform detailed investigation of escalated security alerts.
- Analyze endpoint, network, cloud, and identity-related security events.
- Validate indicators of compromise (IOCs) and determine incident severity.
- Coordinate containment and recovery activities with technology teams.
- Execute incident response procedures for malware, phishing, ransomware, credential compromise, insider threats, and cloud security incidents.
- Collect and preserve forensic evidence where required.
- Document investigations and maintain complete case records.
- Perform threat intelligence enrichment.
- Identify attacker tactics, techniques, and procedures (TTPs).
- Map incidents to the MITRE ATT&CK; framework.
- Recommend recent detection opportunities based on investigations.
- Identify false positives and recommend SIEM tuning.
- Support development and validation of detection use cases.
- Participate in threat hunting exercises and purple team activities.
- Escalate high-severity incidents to L3/Incident Response teams.
- Work closely with Detection Engineering, SIEM Engineering and IT Operations teams.
- Prepare detailed incident reports.
- Update knowledge articles and operational runbooks.
- Participate in post-incident reviews and lessons learned sessions.
Required Qualifications:
- Bachelor’s degree in computer science, Cybersecurity, Information Technology or a related field.
- 2 years of experience in a Security Operations Center.
- Experience with enterprise SIEM, EDR/XDR, and incident response.
- Preferred Certifications - GCIH, GCIA, CompTIA Security , Microsoft SC-200, Splunk Core Certified Power User or equivalent, CySA .
- Technical Skills - SIEM platforms (Splunk), EDR/XDR technologies, Windows, Linux and Active Directory security, Cloud security (Azure, AWS, or Google Cloud), Network security fundamentals, Malware analysis basics, Threat intelligence, Log analysis, MITRE ATT&CK;, Basic scripting (PowerShell or Python).
📌 SOC Analyst II (India)
🏢 Recruise
📍 India