Cybersecurity SOC Analyst (L2)
Summary
SOC L2 Analyst responsible for advanced monitoring, investigation, and incident response using SIEM and EDR tools, with threat hunting and malware analysis duties.
The SOC L2 Analyst is responsible for advanced monitoring, investigation and response to cybersecurity incidents. This role serves as the escalation point for L1 analysts and performs in-depth analysis to ensure timely containment and remediation of threats.
Responsibilities:
Monitor and investigate security alerts escalated from L1 analysts
Perform detailed analysis using SIEM, EDR and related tools
Lead incident response activities, including containment and recovery
Conduct threat hunting based on intelligence and observed patterns
Analyze malware, phishing attempts, and suspicious behaviour
Correlate events across multiple sources to identify threats
Document incidents and response actions clearly
Provide guidance and mentoring to L1 analysts
Fine-tune detection rules to improve alert quality
Work closely with internal teams for incident resolution
Technical Skills & Requirements:
Experience with SIEM tools (e.g. Splunk, netwitness, Sentinel)
Familiarity with EDR platforms (e.g. Carbonblack)
Strong understanding of network protocols and log analysis
Knowledge of MITRE ATT&CK framework
Experience in incident response processes
Basic scripting (Python, PowerShell, or Bash) is preferred
Understanding of security controls such as firewalls, IDS/IPS, and VPNs etc.
Experience & Qualifications:
3–5 years of SOC or cybersecurity operations experience
Relevant qualification in Cybersecurity, IT, or equivalent
Certifications such as CEH, CySA+, GCIH, or Security+ are advantageous
Soft Skills:
Strong analytical and problem-solving skills
Ability to work in a fast-paced SOC environment
Good communication and documentation capability
Team player with mentoring ability