SOC Analyst - L2

SRM TechnologiesChennai, Tamil NaduOn-siteFull-timeMid level, 2–5 yearsListed 1 week ago

Apply now

About this role

SOC Analyst - L2

Role Overview

The SOC Analyst L2 is responsible for
advanced threat detection, incident investigation, threat hunting, malware
analysis, security incident response, and continuous improvement of security
monitoring capabilities. This role serves as the primary escalation point for
L1 analysts and plays a key role in strengthening the organization's cyber
defense posture.

Key Responsibilities

Incident Response & Investigation

- Investigate escalated security incidents and validate true
positives.
- Perform root cause analysis and impact assessment.
- Lead containment, eradication, and recovery activities.
- Conduct detailed forensic investigations on endpoints and
systems.
- Coordinate with IT, Cloud, Network, and Security Engineering
teams during major incidents.

Threat Hunting

- Proactively identify emerging threats and hidden adversary
activities.
- Develop threat hunting hypotheses using MITRE ATT&CK
Framework.
- Identify attacker tactics, techniques, and procedures (TTPs).
- Utilize threat intelligence feeds to improve detection
capabilities.

SIEM & Detection Engineering

- Tune and optimize SIEM correlation rules.
- Develop new threat detection use cases.
- Reduce false positives through continuous rule enhancement.
- Improve detection coverage across cloud, endpoints, network,
and identity platforms.

Cloud Security Operations

- Monitor and investigate security events across Azure and AWS
environments.
- Analyze IAM anomalies, privilege escalations, and cloud
misconfigurations.
- Support cloud-native security tools and security posture
management platforms.

Endpoint & Malware Analysis

- Perform malware investigation and behavioral analysis.
- Analyze EDR/XDR detections.
- Conduct IOC and IOA investigations.
- Support ransomware response activities.

Technical Skills

SIEM Platforms

- Microsoft Sentinel
- Splunk Enterprise Security
- IBM QRadar
- LogRhythm

Endpoint & XDR Security

- Microsoft Defender XDR
- CrowdStrike Falcon
- SentinelOne
- Cortex XDR

Threat Hunting & Incident Response

- MITRE ATT&CK Framework
- Cyber Kill Chain
- Threat Intelligence Platforms
- IOC/IOA Analysis
- Digital Forensics

Cloud Security

- Microsoft Azure Security
- AWS Security Services
- Cloud Security Posture Management (CSPM)
- Identity Security Monitoring

Security Controls

- WAF
- CASB
- DLP
- Email Security
- Zero Trust Security Architecture
- Zscaler Security Monitoring (Preferred)

Shift & Scheduling

- 24x7 Security Operations Coverage
- On-call Support for Critical Incidents
- Major Incident Management Participation
- Support During Security Breach Investigations

Preferred Certifications

- Microsoft SC-200 Security Operations Analyst
- CompTIA CySA+
- CEH (Certified Ethical Hacker)
- Splunk Enterprise Security Administrator

Cloud & Security Certifications

- Microsoft Azure Security Engineer (AZ-500)
- AWS Security Specialty
- Google Professional Cloud Security Engineer

Zscaler Certifications (Preferred)

- Zscaler Certified Administrator (ZCCA-IA)
- Zscaler Certified Security Administrator
- Zscaler Certified Cloud Administrator
- Zscaler Internet Access (ZIA) Administration Experience