SOC Analyst II
About the role:
The SOC Analyst L2 is responsible for investigating and responding to complex cybersecurity incidents escalated from Level 1 analysts. The role performs advanced analysis, validates security events, coordinates containment activities, and supports incident response while contributing to threat hunting and detection improvements.
Responsibilities:
Operations:
• Perform detailed investigation of escalated security alerts.
• Analyze endpoint, network, cloud, and identity-related security events.
• Validate indicators of compromise (IOCs) and determine incident severity.
• Coordinate containment and recovery activities with technology teams.
• Execute incident response procedures for malware, phishing, ransomware, credential compromise, insider threats, and cloud security incidents.
• Collect and preserve forensic evidence where required.
• Document investigations and maintain complete case records.
• Perform threat intelligence enrichment.
• Identify attacker tactics, techniques, and procedures (TTPs).
• Map incidents to the MITRE ATT&CK framework.
• Recommend new detection opportunities based on investigations.
• Identify false positives and recommend SIEM tuning.
• Support development and validation of detection use cases.
• Participate in threat hunting exercises and purple team activities.
• Escalate high-severity incidents to L3/Incident Response teams.
• Work closely with Detection Engineering, SIEM Engineering and IT Operations teams.
• Prepare detailed incident reports.
• Update knowledge articles and operational runbooks.
• Participate in post-incident reviews and lessons learned sessions.
Required Qualifications:
• Bachelor’s degree in computer science, Cybersecurity, Information Technology or a related field.
• 2+ years of experience in a Security Operations Center.
• Experience with enterprise SIEM, EDR/XDR, and incident response.
• Preferred Certifications - GCIH, GCIA, CompTIA Security+, Microsoft SC-200, Splunk Core Certified Power User or equivalent, CySA+.
• Technical Skills - SIEM platforms (Splunk), EDR/XDR technologies, Windows, Linux and Active Directory security, Cloud security (Azure, AWS, or Google Cloud), Network security fundamentals, Malware analysis basics, Threat intelligence, Log analysis, MITRE ATT&CK, Basic scripting (PowerShell or Python).