15 Sep
|
JCPenney
|
Bengaluru
15 Sep
JCPenney
Bengaluru
Job Summary
Overview SOC Analyst in Cybersecurity Team (Analyst 2).
Role Overview
A SOC (Security Operations Center) L2 Analyst, also known as Tier 2 or Analyst 2, is the intermediate tier in the common three-tier SOC model for Catalyst Brands Cybersecurity Team. Their primary goal is to handle escalated alerts and confirmed or complex incidents that Tier 1 cannot fully resolve.
Responsibilities
- Real-Time Monitoring: Continuously watch security dashboards (SIEM) for potential threats across networks, endpoints, and other security consoles.
- Investigate escalated security incidents from Tier 1.
- Perform in-depth analysis and event correlation across multiple sources (endpoint/EDR/XDR, network, identity, cloud, email, SIEM logs, etc.).
- Support or lead containment, eradication, and recovery actions (e.g., isolate hosts, disable accounts, block IPs/domains).
- Perform basic malware analysis, network forensics, or endpoint forensics as needed.
- Build incident timelines, determine scope/impact/blast radius, and identify affected systems, accounts, and data.
- Recommend or implement detection improvements (SIEM rule tuning, playbook updates) and reduce false positives.
- Mentor/support Tier 1 analysts and escalate highly complex or high-impact cases to Tier 3.
- Sometimes contributes to limited proactive hunting.
- Documentation: Maintain accurate logs of all findings, Investigations, actions taken, and evidence gathered in Case management tool.
- Shift Handover: Communicate ongoing investigations and suspicious patterns to the next shift to ensure continuity 24/7.
- Constant Vigilance: Real-time surveillance of network traffic and security alerts is essential to minimize downtime and prevent data breaches.
Soft Skills
- Ability to remain calm and focused during high-pressure security events.
- Excellent written communication for documenting technical findings clearly.
- Analytical mindset with solid attention to detail.
Work Schedule
- Willingness and ability to work nights, weekends, holidays, and rotating shifts is frequently required (especially for 24/7 SOCs).
- Flexibility for additional coverage or surge support during major incidents.
- Reliability: Punctuality and commitment to the assigned shift schedule are critical for maintaining security coverage.
Required Skills
- Technical Proficiency: Understanding of networking protocols (TCP/IP, DNS, HTTP), operating systems (Windows, Linux), and common attack patterns (MITRE ATTCK).
- Security Tools: Familiarity with SIEM (Cribl Lake, Logscale etc), EDR (CrowdStrike, Microsoft Defender), SOAR (Phantom, BlinkOps) platforms and NDR (Vectra, Plixer, ExtraHop).
- Analytical Thinking: Ability to correlate data from multiple sources to identify anomalies and form a response hypothesis.
- Familiarity with MITRE ATTCK, incident response frameworks, and basic scripting (Python/PowerShell).
- Ability to correlate data, exercise judgment under time pressure, and communicate clearly with other teams.
Qualifications
- Education: Bachelor s degree in computer science, IT, or Cybersecurity.
- Experience: 4-6 years in SOC.
- Key Certifications: CompTIA Security+, CEH, CCNA Security, or CISSP etc.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Analyst 2 (Bengaluru)
🏢 JCPenney
📍 Bengaluru