Talent Radar · Cybersecurity: 73% of Indian firms still can't find the security talent they need.

Get the report

SOC Analyst II

Bangalore, Karnataka, India Full-time Retail & E-commerce Associate

About the role:

The SOC Analyst L2 is responsible for investigating and responding to complex cybersecurity incidents escalated from Level 1 analysts. The role performs advanced analysis, validates security events, coordinates containment activities, and supports incident response while contributing to threat hunting and detection improvements.

 

Responsibilities:

Operations:

                     Perform detailed investigation of escalated security alerts.

                     Analyze endpoint, network, cloud, and identity-related security events.

                     Validate indicators of compromise (IOCs) and determine incident severity.

                     Coordinate containment and recovery activities with technology teams.

                     Execute incident response procedures for malware, phishing, ransomware, credential compromise, insider threats, and cloud security incidents.

                     Collect and preserve forensic evidence where required.

                     Document investigations and maintain complete case records.

                     Perform threat intelligence enrichment.

                     Identify attacker tactics, techniques, and procedures (TTPs).

                     Map incidents to the MITRE ATT&CK framework.

                     Recommend new detection opportunities based on investigations.

                     Identify false positives and recommend SIEM tuning.

                     Support development and validation of detection use cases.

 

                     Participate in threat hunting exercises and purple team activities.

                     Escalate high-severity incidents to L3/Incident Response teams.

                     Work closely with Detection Engineering, SIEM Engineering and IT Operations teams.

                     Prepare detailed incident reports.

                     Update knowledge articles and operational runbooks.

                     Participate in post-incident reviews and lessons learned sessions.

 

Required Qualifications:

                     Bachelor’s degree in computer science, Cybersecurity, Information Technology or a related field.

                     2+ years of experience in a Security Operations Center.

                     Experience with enterprise SIEM, EDR/XDR, and incident response.

                     Preferred Certifications - GCIH, GCIA, CompTIA Security+, Microsoft SC-200, Splunk Core Certified Power User or equivalent, CySA+.

                     Technical Skills - SIEM platforms (Splunk), EDR/XDR technologies, Windows, Linux and Active Directory security, Cloud security (Azure, AWS, or Google Cloud), Network security fundamentals, Malware analysis basics, Threat intelligence, Log analysis, MITRE ATT&CK, Basic scripting (PowerShell or Python).

 

Share
More open mandates

Related mandates

Full-time

Software Engineer II - Java

Bangalore, Karnataka, India
View mandate
Full-time

Software Engineer I - Node.Js

Bangalore, Karnataka, India
View mandate
Full-time

AI Engineer

Bangalore, Karnataka, India
View mandate
Apply

Apply for this mandate

Opens in a new tab — you’ll complete a short application in our secure recruiting system, about two minutes, résumé included. We read every one and reach out if there’s a fit. Handled with discretion.

Not ready to apply? Submit your profile instead — we’ll reach out when a matching mandate opens.

Let's build what's next.