SonicJobs Logo
Left arrow iconBack to search

SOC Analyst - L2

SRM Technologies
Posted 8 days ago, valid for 12 days
Location

Chennai, TN

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The SOC Analyst - L2 is responsible for advanced threat detection, incident investigation, threat hunting, and malware analysis, serving as the primary escalation point for L1 analysts.
  • Key responsibilities include investigating security incidents, conducting root cause analysis, leading containment and recovery activities, and coordinating with various teams during major incidents.
  • Candidates should have experience with SIEM platforms, endpoint security, threat hunting frameworks, and cloud security operations, particularly in Azure and AWS environments.
  • The role requires a minimum of 3-5 years of relevant experience in cybersecurity, with preferred certifications including Microsoft SC-200, CompTIA CySA+, and various cloud security certifications.
  • The salary for this position ranges from $90,000 to $120,000 per year, commensurate with experience and qualifications.

SOC Analyst - L2

Role Overview

The SOC Analyst L2 is responsible foradvanced threat detection, incident investigation, threat hunting, malwareanalysis, security incident response, and continuous improvement of securitymonitoring capabilities. This role serves as the primary escalation point forL1 analysts and plays a key role in strengthening the organization's cyberdefense posture.

Key Responsibilities

Incident Response & Investigation

  • Investigate escalated security incidents and validate true positives.
  • Perform root cause analysis and impact assessment.
  • Lead containment, eradication, and recovery activities.
  • Conduct detailed forensic investigations on endpoints and systems.
  • Coordinate with IT, Cloud, Network, and Security Engineering teams during major incidents.

Threat Hunting

  • Proactively identify emerging threats and hidden adversary activities.
  • Develop threat hunting hypotheses using MITRE ATT&CK Framework.
  • Identify attacker tactics, techniques, and procedures (TTPs).
  • Utilize threat intelligence feeds to improve detection capabilities.

SIEM & Detection Engineering

  • Tune and optimize SIEM correlation rules.
  • Develop new threat detection use cases.
  • Reduce false positives through continuous rule enhancement.
  • Improve detection coverage across cloud, endpoints, network, and identity platforms.

Cloud Security Operations

  • Monitor and investigate security events across Azure and AWS environments.
  • Analyze IAM anomalies, privilege escalations, and cloud misconfigurations.
  • Support cloud-native security tools and security posture management platforms.

Endpoint & Malware Analysis

  • Perform malware investigation and behavioral analysis.
  • Analyze EDR/XDR detections.
  • Conduct IOC and IOA investigations.
  • Support ransomware response activities.

Technical Skills

SIEM Platforms

  • Microsoft Sentinel
  • Splunk Enterprise Security
  • IBM QRadar
  • LogRhythm

Endpoint & XDR Security

  • Microsoft Defender XDR
  • CrowdStrike Falcon
  • SentinelOne
  • Cortex XDR

Threat Hunting & Incident Response

  • MITRE ATT&CK Framework
  • Cyber Kill Chain
  • Threat Intelligence Platforms
  • IOC/IOA Analysis
  • Digital Forensics

Cloud Security

  • Microsoft Azure Security
  • AWS Security Services
  • Cloud Security Posture Management (CSPM)
  • Identity Security Monitoring

Security Controls

  • WAF
  • CASB
  • DLP
  • Email Security
  • Zero Trust Security Architecture
  • Zscaler Security Monitoring (Preferred)

Shift & Scheduling

  • 24x7 Security Operations Coverage
  • On-call Support for Critical Incidents
  • Major Incident Management Participation
  • Support During Security Breach Investigations

Preferred Certifications

  • Microsoft SC-200 Security Operations Analyst
  • CompTIA CySA+
  • CEH (Certified Ethical Hacker)
  • Splunk Enterprise Security Administrator

Cloud & Security Certifications

  • Microsoft Azure Security Engineer (AZ-500)
  • AWS Security Specialty
  • Google Professional Cloud Security Engineer

Zscaler Certifications (Preferred)

  • Zscaler Certified Administrator (ZCCA-IA)
  • Zscaler Certified Security Administrator
  • Zscaler Certified Cloud Administrator
  • Zscaler Internet Access (ZIA) Administration Experience

 






Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.