Talent Radar · Supply Chain Analytics: supply chain data scientists grew 33% in a year, and experienced analysts are very hard to hire.

Get the report

SOC Analyst II

Bangalore, Karnataka, India Full-time Retail & E-commerce Associate

About the role

The SOC Analyst L2 is responsible for investigating and responding to complex cybersecurity incidents escalated from Level 1 analysts. The role performs advanced analysis, validates security events, coordinates containment activities, and supports incident response while contributing to threat hunting and detection improvements.

Responsibilities

Operations

  • Perform detailed investigation of escalated security alerts.
  • Analyze endpoint, network, cloud, and identity-related security events.
  • Validate indicators of compromise (IOCs) and determine incident severity.
  • Coordinate containment and recovery activities with technology teams.
  • Execute incident response procedures for malware, phishing, ransomware, credential compromise, insider threats, and cloud security incidents.
  • Collect and preserve forensic evidence where required.
  • Document investigations and maintain complete case records.
  • Perform threat intelligence enrichment.
  • Identify attacker tactics, techniques, and procedures (TTPs).
  • Map incidents to the MITRE ATT&CK framework.
  • Recommend new detection opportunities based on investigations.
  • Identify false positives and recommend SIEM tuning.
  • Support development and validation of detection use cases.
  • Participate in threat hunting exercises and purple team activities.
  • Escalate high-severity incidents to L3/Incident Response teams.
  • Work closely with Detection Engineering, SIEM Engineering and IT Operations teams.
  • Prepare detailed incident reports.
  • Update knowledge articles and operational runbooks.
  • Participate in post-incident reviews and lessons learned sessions.

Required Qualifications

  • Bachelor’s degree in computer science, Cybersecurity, Information Technology or a related field.
  • 2+ years of experience in a Security Operations Center.
  • Experience with enterprise SIEM, EDR/XDR, and incident response.
  • Preferred Certifications - GCIH, GCIA, CompTIA Security+, Microsoft SC-200, Splunk Core Certified Power User or equivalent, CySA+.
  • Technical Skills - SIEM platforms (Splunk), EDR/XDR technologies, Windows, Linux and Active Directory security, Cloud security (Azure, AWS, or Google Cloud), Network security fundamentals, Malware analysis basics, Threat intelligence, Log analysis, MITRE ATT&CK, Basic scripting (PowerShell or Python).
Share
More open mandates

Related mandates

Full-time

Specialist - Credit.

Bangalore, Karnataka, India
View mandate
Full-time

Lead Data Engineer- Governance

Bangalore, Karnataka, India
View mandate
Full-time

Associate Engineer II-Node.Js

Bangalore, Karnataka, India
View mandate
Apply

Apply for this mandate

It takes about four minutes. You can complete your application without leaving this page.

Have your CV ready. It goes directly to the consultant leading this search.

Your application is handled with discretion.

Your full annual package (your CTC, in India), for example 1800000 or 18 LPA. If you are between roles, give your last one. Picked Other? Write the currency in with the amount.
On the same basis, for a move. A cross-border move often changes the currency, so set each one.
Attach your CV PDF, Word, RTF or text · up to 5 MB

Application received

Thank you for applying for this role.

As we receive many applications, we’re not able to reply to each one personally. If you’re shortlisted, the consultant running this search will be in touch. We do not share your details with any client before we speak to you.

Not ready to apply? Submit your profile for future and confidential mandates.

Let's build what's next.