Point your AI agent at freehire and let it find you a job.

Get the CLI →

SRM Technologies

New

SOC Analyst - L2

Posted Updated 4 views
Discussion

Summary

Level-2 SOC analyst in Chennai who investigates escalated security incidents, performs threat hunting, malware and forensic analysis, and tunes SIEM/EDR detections. Core tooling spans Microsoft Sentinel, Splunk, QRadar, Defender XDR, CrowdStrike, with cloud security monitoring across Azure and AWS; role includes 24x7 shift and on-call coverage.


SOC Analyst - L2

Role Overview

We are seeking a highly skilled SOC Analyst (L2) to provide hands-on security monitoring, investigation, and incident response support within a 24x7 Security Operations Center (SOC). The primary focus of this role is to ensure continuous security queue coverage, perform effective triage of medium and low-severity alerts, rapidly escalate high and critical security events, and maintain high-quality incident documentation and handoffs.

The ideal candidate will have strong investigative skills across endpoint, identity, cloud, and network security domains, with practical experience using EDR platforms, case management tools, SQL-based analysis, and structured incident response procedures.

Key Responsibilities

Security Monitoring & Alert Triage

  • Monitor and triage security alerts from multiple security platforms on a 24x7 basis.

  • Perform detailed analysis of medium and low-severity alerts and determine appropriate disposition.

  • Rapidly identify, validate, and escalate high and critical severity incidents according to defined SLAs.

  • Execute incident response runbooks and playbooks to ensure consistent handling of security events.

  • Maintain hygiene and ensure timely closure or escalation of alerts.

  • CrowdStrike Falcon is preferred. We have a large footprint in both prod and corp. Other EDR experience could be helpful but understanding Crowdstrike is top priority

  • AWS is our largest public cloud footprint. GCP and Azure are significantly smaller. General public cloud experience is a basic qualification; however AWS is a preferred qualification

Incident Investigation & Response

  • Conduct hands-on investigations involving endpoint, identity, cloud, email, and network-based security events.

  • Correlate data from multiple sources to determine attack scope, impact, and root cause.

  • Gather and document evidence to support incident disposition and remediation recommendations.

  • Participate in containment, eradication, and recovery activities during security incidents.

  • Support post-incident reviews and lessons learned activities.

Case Management & Documentation

  • Manage incidents through Tines or comparable case management and workflow platforms.

  • Maintain accurate incident records, investigation notes, and evidence artifacts.

  • Produce clear and actionable updates for stakeholders and escalation teams.

  • Ensure high-quality shift handovers with complete context, findings, and pending actions.

Security Analytics & Threat Investigation

  • Perform log and data analysis using Databricks, SQL, and security telemetry sources.

  • Investigate suspicious activity using endpoint, identity, cloud, and authentication data.

  • Support threat hunting activities and identify patterns indicative of malicious behavior.

  • Recommend improvements to alert logic, detection rules, and operational processes.

Collaboration & Continuous Improvement

  • Collaborate with SOC Leads, Incident Responders, Cloud Operations, and Infrastructure teams.

  • Assist in refining operational runbooks, playbooks, and investigation procedures.

  • Contribute to knowledge management and continuous service improvement initiatives.


Required Technical Skills

Endpoint Security

  • CrowdStrike Falcon

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available