More jobs:
Soc Analyst - L2
Job Description & How to Apply Below
Department: Cyber Security / Security Operations Center (SOC)
Reporting to: SOC Manager / Team Lead
Role OverviewThe SOC L2 Analyst is responsible for advanced security monitoring, deep-dive incident investigation, and complex threat analysis. Acting as the critical escalation point for Level 1 Analysts, you will lead the response to sophisticated threats and ensure the continuous improvement of our detection capabilities. You will play a hands-on role in incident containment, eradication, and recovery, while proactively hunting for emerging threats within our environment.
Key Responsibilities 1. Advanced Investigation & Incident Response- Deep-Dive Analysis: Perform advanced threat analysis and investigate complex security incidents escalated from Tier 1.
- Incident Leadership: Lead incident response activities, including the containment of active threats, eradication of malicious actors, and recovery of systems.
- Root Cause Analysis (RCA): Conduct comprehensive RCAs to identify how breaches occurred and recommend preventative controls.
- Threat Hunting: Proactively hunt for threats using IOCs (Indicators of Compromise) and TTPs (Tactics, Techniques, and Procedures) to uncover hidden malicious activity.
- Tool Mastery: Analyze logs and correlate security events using complex queries within Splunk and IBM QRadar
. - Rule Optimization: Develop and optimize SIEM use cases, correlation rules, and alerts to reduce false positives and improve detection accuracy.
- Playbook Development: Create and refine incident response playbooks and automated detection logic to standardize response efforts.
- Threat Intel Integration: Monitor and integrate threat intelligence feeds into the SIEM to ensure the environment is protected against the latest known threats.
- Mentorship: Serve as a technical mentor for L1 analysts, providing guidance on investigation techniques and professional development.
- SIEM Platforms: High proficiency in Splunk (Search Processing Language - SPL, dashboards, alerting) and IBM QRadar (Offense management, rules engine, AQL queries).
- Frameworks: Strong operational knowledge of the MITRE ATT&CK framework and the full Incident Response lifecycle.
- Security Tooling: Experience with EDR/XDR solutions, Firewall logs, and IDS/IPS systems.
- Threat Analysis: Expert knowledge of IOC analysis, malware behavior, and threat intelligence platforms.
- Scripting: Basic automation skills using Python, Power Shell, or Bash to streamline repetitive tasks.
- Experience: 4–6 years of dedicated experience in a SOC environment or Cyber Security operations.
- Education: Bachelor’s degree in Computer Science, Cyber Security, or a related technical field.
Certifications:
- Core: CompTIA CySA+ or Certified Ethical Hacker (CEH).
- Platform Specific: Splunk Certified User/Admin or IBM QRadar Certification.
- Advanced: GCIH, GCIA, or similar technical IR certifications.
- Strong analytical thinking and problem-solving skills under pressure.
- Excellent communication skills for documenting technical findings in clear business terms.
- A proactive "hunter" mindset focused on continuous security improvement.
Required Skills
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×