Job Description
Roles & responsibilities
We are seeking a highly skilled and proactive SOC L2 Analyst to join our Cyber Security Operations team. The candidate will be responsible for advanced monitoring, investigation, analysis, and response to cybersecurity incidents using Splunk SIEM, CrowdStrike Falcon, and Microsoft Defender for Endpoint (MDE). The role requires strong analytical capabilities, incident response expertise, threat hunting experience, and the ability to mentor L1 analysts while contributing to the continuous improvement of security operations.
Note : Candidate must be willing to do 24x7 rotational shift (Mandatory requirement for this role)
Educational Qualifications:
•Bachelor's degree in Computer Science, Information Security, Cybersecurity, Information Technology, Engineering, or a related field.
•Master's degree in Cybersecurity, Information Security, or related discipline is preferred.
•Minimum 6 years of experience in Security Operations Center (SOC), Incident Response, or Cyber Defense operations.
•Experience working in a 24x7 SOC environment supporting enterprise-scale security monitoring and incident management.
Experience Requirements:
6-8 years of hands-on experience in SOC Operations, Incident Response, Threat Hunting, or Cyber Defense, with demonstrated expertise in Splunk SIEM, CrowdStrike Falcon, and Microsoft Defender for Endpoint (MDE) in enterprise environments.
The Ideal Candidate Will
•Investigate and respond to security alerts and incidents escalated by L1 analysts.
•Perform advanced threat analysis, triage, containment, eradication, and recovery activities.
•Be able to perform live response via Defender or Crowdstrike to perform cleanup of the detected malware etc.
•Conduct threat hunting activities using telemetry from Splunk, CrowdStrike, and Microsoft Defender for Endpoint.
•Correlate events from multiple security platforms to identify sophisticated attack patterns and anomalies.
•Lead incident investigations and provide detailed root cause analysis (RCA).
•Develop and improve use cases, correlation rules, dashboards, and detection content within Splunk.
•Analyze endpoint security incidents including malware, ransomware, phishing, credential compromise, insider threats, and advanced persistent threats (APTs).
•Collaborate with IT, Network, Cloud, Endpoint, and Infrastructure teams during incident response activities.
•Contribute to incident response playbooks, standard operating procedures (SOPs), and knowledge repositories.
•Perform threat intelligence analysis and incorporate indicators of compromise (IOCs) into monitoring processes.
•Provide mentorship and guidance to L1 analysts and assist in skill development initiatives.
•Participate in post-incident reviews and recommend security control improvements.
•Support compliance, audit, and reporting requirements related to security operations.
Roles & responsibilities
We are seeking a highly skilled and proactive SOC L2 Analyst to join our Cyber Security Operations team. The candidate will be responsible for advanced monitoring, investigation, analysis, and response to cybersecurity incidents using Splunk SIEM, CrowdStrike Falcon, and Microsoft Defender for Endpoint (MDE). The role requires strong analytical capabilities, incident response expertise, threat hunting experience, and the ability to mentor L1 analysts while contributing to the continuous improvement of security operations.
Note : Candidate must be willing to do 24x7 rotational shift (Mandatory requirement for this role)
Educational Qualifications:
•Bachelor's degree in Computer Science, Information Security, Cybersecurity, Information Technology, Engineering, or a related field.
•Master's degree in Cybersecurity, Information Security, or related discipline is preferred.
•Minimum 6 years of experience in Security Operations Center (SOC), Incident Response, or Cyber Defense operations.
•Experience working in a 24x7 SOC environment supporting enterprise-scale security monitoring and incident management.
Experience Requirements:
6-8 years of hands-on experience in SOC Operations, Incident Response, Threat Hunting, or Cyber Defense, with demonstrated expertise in Splunk SIEM, CrowdStrike Falcon, and Microsoft Defender for Endpoint (MDE) in enterprise environments.
The Ideal Candidate Will
•Investigate and respond to security alerts and incidents escalated by L1 analysts.
•Perform advanced threat analysis, triage, containment, eradication, and recovery activities.
•Be able to perform live response via Defender or Crowdstrike to perform cleanup of the detected malware etc.
•Conduct threat hunting activities using telemetry from Splunk, CrowdStrike, and Microsoft Defender for Endpoint.
•Correlate events from multiple security platforms to identify sophisticated attack patterns and anomalies.
•Lead incident investigations and provide detailed root cause analysis (RCA).
•Develop and improve use cases, correlation rules, dashboards, and detection content within Splunk.
•Analyze endpoint security incidents including malware, ransomware, phishing, credential compromise, insider threats, and advanced persistent threats (APTs).
•Collaborate with IT, Network, Cloud, Endpoint, and Infrastructure teams during incident response activities.
•Contribute to incident response playbooks, standard operating procedures (SOPs), and knowledge repositories.
•Perform threat intelligence analysis and incorporate indicators of compromise (IOCs) into monitoring processes.
•Provide mentorship and guidance to L1 analysts and assist in skill development initiatives.
•Participate in post-incident reviews and recommend security control improvements.
•Support compliance, audit, and reporting requirements related to security operations.
Roles & responsibilities
We are seeking a highly skilled and proactive SOC L2 Analyst to join our Cyber Security Operations team. The candidate will be responsible for advanced monitoring, investigation, analysis, and response to cybersecurity incidents using Splunk SIEM, CrowdStrike Falcon, and Microsoft Defender for Endpoint (MDE). The role requires strong analytical capabilities, incident response expertise, threat hunting experience, and the ability to mentor L1 analysts while contributing to the continuous improvement of security operations.
Note : Candidate must be willing to do 24x7 rotational shift (Mandatory requirement for this role)
Educational Qualifications:
•Bachelor's degree in Computer Science, Information Security, Cybersecurity, Information Technology, Engineering, or a related field.
•Master's degree in Cybersecurity, Information Security, or related discipline is preferred.
•Minimum 6 years of experience in Security Operations Center (SOC), Incident Response, or Cyber Defense operations.
•Experience working in a 24x7 SOC environment supporting enterprise-scale security monitoring and incident management.
Experience Requirements:
6-8 years of hands-on experience in SOC Operations, Incident Response, Threat Hunting, or Cyber Defense, with demonstrated expertise in Splunk SIEM, CrowdStrike Falcon, and Microsoft Defender for Endpoint (MDE) in enterprise environments.
The Ideal Candidate Will
•Investigate and respond to security alerts and incidents escalated by L1 analysts.
•Perform advanced threat analysis, triage, containment, eradication, and recovery activities.
•Be able to perform live response via Defender or Crowdstrike to perform cleanup of the detected malware etc.
•Conduct threat hunting activities using telemetry from Splunk, CrowdStrike, and Microsoft Defender for Endpoint.
•Correlate events from multiple security platforms to identify sophisticated attack patterns and anomalies.
•Lead incident investigations and provide detailed root cause analysis (RCA).
•Develop and improve use cases, correlation rules, dashboards, and detection content within Splunk.
•Analyze endpoint security incidents including malware, ransomware, phishing, credential compromise, insider threats, and advanced persistent threats (APTs).
•Collaborate with IT, Network, Cloud, Endpoint, and Infrastructure teams during incident response activities.
•Contribute to incident response playbooks, standard operating procedures (SOPs), and knowledge repositories.
•Perform threat intelligence analysis and incorporate indicators of compromise (IOCs) into monitoring processes.
•Provide mentorship and guidance to L1 analysts and assist in skill development initiatives.
•Participate in post-incident reviews and recommend security control improvements.
•Support compliance, audit, and reporting requirements related to security operations.