HirePortal

SOC Analyst - L2

Role Overview

The SOC Analyst L2 is responsible for advanced threat detection, incident investigation, threat hunting, malware analysis, security incident response, and continuous improvement of security monitoring capabilities. This role serves as the primary escalation point for L1 analysts and plays a key role in strengthening the organization's cyber defense posture.

Key Responsibilities

Incident Response & Investigation

  • Investigate escalated security incidents and validate true positives.
  • Perform root cause analysis and impact assessment.
  • Lead containment, eradication, and recovery activities.
  • Conduct detailed forensic investigations on endpoints and systems.
  • Coordinate with IT, Cloud, Network, and Security Engineering teams during major incidents.

Threat Hunting

  • Proactively identify emerging threats and hidden adversary activities.
  • Develop threat hunting hypotheses using MITRE ATT&CK Framework.
  • Identify attacker tactics, techniques, and procedures (TTPs).
  • Utilize threat intelligence feeds to improve detection capabilities.

SIEM & Detection Engineering

  • Tune and optimize SIEM correlation rules.
  • Develop new threat detection use cases.
  • Reduce false positives through continuous rule enhancement.
  • Improve detection coverage across cloud, endpoints, network, and identity platforms.

Cloud Security Operations

  • Monitor and investigate security events across Azure and AWS environments.
  • Analyze IAM anomalies, privilege escalations, and cloud misconfigurations.
  • Support cloud-native security tools and security posture management platforms.

Endpoint & Malware Analysis

  • Perform malware investigation and behavioral analysis.
  • Analyze EDR/XDR detections.
  • Conduct IOC and IOA investigations.
  • Support ransomware response activities.

Technical Skills

SIEM Platforms

  • Microsoft Sentinel
  • Splunk Enterprise Security
  • IBM QRadar
  • LogRhythm

Endpoint & XDR Security

  • Microsoft Defender XDR
  • CrowdStrike Falcon
  • SentinelOne
  • Cortex XDR

Threat Hunting & Incident Response

  • MITRE ATT&CK Framework
  • Cyber Kill Chain
  • Threat Intelligence Platforms
  • IOC/IOA Analysis
  • Digital Forensics

Cloud Security

  • Microsoft Azure Security
  • AWS Security Services
  • Cloud Security Posture Management (CSPM)
  • Identity Security Monitoring

Security Controls

  • WAF
  • CASB
  • DLP
  • Email Security
  • Zero Trust Security Architecture
  • Zscaler Security Monitoring (Preferred)

Shift & Scheduling

  • 24x7 Security Operations Coverage
  • On-call Support for Critical Incidents
  • Major Incident Management Participation
  • Support During Security Breach Investigations

Preferred Certifications

  • Microsoft SC-200 Security Operations Analyst
  • CompTIA CySA+
  • CEH (Certified Ethical Hacker)
  • Splunk Enterprise Security Administrator

Cloud & Security Certifications

  • Microsoft Azure Security Engineer (AZ-500)
  • AWS Security Specialty
  • Google Professional Cloud Security Engineer

Zscaler Certifications (Preferred)

  • Zscaler Certified Administrator (ZCCA-IA)
  • Zscaler Certified Security Administrator
  • Zscaler Certified Cloud Administrator
  • Zscaler Internet Access (ZIA) Administration Experience

Skills

  • SIEM
  • Incident Response
  • Threat hunting
  • Malware Analysis
  • MITRE ATT&CK
  • Cloud Security
  • Forensics

Related jobs

SRM TechnologiesApply for this job