Role Summary
The L2 SOC Analyst plays a critical role in Keyloop’s 24/7 Security Operations Center, responsible for in-depth investigation, analysis, and response to security alerts and incidents. This role acts as the primary escalation point from L1 analysts (internal or MSP) and is accountable for validating incidents, performing root cause analysis, and driving effective containment and remediation actions.
The L2 SOC Analyst is expected to demonstrate strong technical capability across multiple security technologies, contribute to continuous improvement of SOC processes and detections, and support compliance and assurance requirements. The role requires a proactive mindset, strong analytical skills, and the ability to communicate effectively with technical and non-technical stakeholders.
Key Responsibilities
Investigate and validate escalated security alerts and incidents from L1 SOC analysts.
Perform detailed analysis to determine scope, impact, root cause, and attacker activity.
Lead containment, eradication, and recovery actions in collaboration with IT, engineering, and other security teams.
Ensure incidents are handled in accordance with defined incident response policies, runbooks, and SLAs.
Document incidents thoroughly, including timelines, findings, actions taken, and recommendations.
Actively monitor SIEM dashboards, queues, and alerts as required.
Validate detection logic and identify false positives, gaps, and improvement opportunities.
Propose and assist with the development of new SIEM use cases, correlation rules, and alert tuning.
Support continuous improvement of detection coverage across cloud, on‑premise, and SaaS environments.
Execute and validate SOAR playbooks during incident response.
Identify opportunities for automation to improve response time, consistency, and quality.
Support the SOC Manager in testing, maintaining, and improving automated workflows.
Investigate alerts and events from a broad range of security technologies, including:
Web content filtering solutions
Email security gateways
Endpoint Detection & Response (EDR)
Managed Detection & Response (MDR)
Extended Detection & Response (XDR)
Correlate events across tools to build a complete incident narrative.
Consume and analyze threat intelligence relevant to Keyloop’s environment and industry.
Apply threat intelligence to investigations, detections, and response actions.
Support proactive threat hunting activities based on emerging threats and attacker techniques.
Act as the escalation point for complex or high-severity incidents.
Collaborate closely with the SOC Manager, L1 analysts, IT operations, engineering, and third-party providers.
Escalate incidents appropriately based on severity, impact, and business risk.
Support SOC-related controls for NIST, ISO/IEC 27001, and SOC 2.
Ensure investigations, evidence collection, and logging meet audit and regulatory requirements.
Assist with audit requests by providing incident records, metrics, and operational evidence.
Contribute to the creation and maintenance of incident response runbooks and playbooks.
Participate in post-incident reviews and lessons-learned activities.
Share knowledge and mentor L1 analysts where appropriate.
Stay current with evolving threats, attack techniques, and defensive strategies.
Incident Investigation & Response
Security Monitoring & Detection
SOAR & Automation Support
Security Technology Operations
Threat Intelligence
Escalation & Collaboration
Compliance & Assurance Support
Continuous Improvement & Knowledge Sharing
Required Experience & Qualifications
3–6 years of experience in a SOC, security operations, or incident response role.
Proven hands-on experience investigating and responding to security incidents.
Practical experience working with SIEM platforms and security alerting systems.
Exposure to SOAR tools and automated response workflows.
Experience with endpoint, email, network, and cloud security technologies.
Familiarity with threat intelligence sources and attacker methodologies.
Skills & Competencies
Incident analysis and response
Log analysis and event correlation
Endpoint, email, and network security investigation
Understanding of attacker tactics, techniques, and procedures (e.g., MITRE ATT&CK)
Strong analytical and problem-solving ability
Clear and concise written and verbal communication
Ability to work under pressure and manage multiple incidents
Collaborative mindset and willingness to support team objectives
Attention to detail and disciplined documentation
Technical Skills
Soft Skills
Education & Certifications (Preferred)
Bachelor’s degree in Computer Science, Information Technology, or a related field
Relevant certifications such as GCIA, GCIH, Security+, CEH, or equivalent
Working Pattern
24/7 SOC environment with shift-based working as required
Based in Hyderabad, India
Values & Business Alignment
Demonstrates alignment with Keyloop’s values and ethical standards.
Understands how SOC activities support Keyloop’s products, customers, and business objectives.
Operates with a strong sense of ownership, accountability, and continuous improvement.
Skills Required
- 3-6 years of experience in a SOC, security operations, or incident response role
- Hands-on experience investigating and responding to security incidents
- Practical experience with SIEM platforms and security alerting systems
- Exposure to SOAR tools and automated response workflows
- Experience with endpoint, email, network, and cloud security technologies
- Familiarity with threat intelligence sources and attacker methodologies
- Bachelor's degree in Computer Science, Information Technology, or a related field
- Relevant certification such as GCIA, GCIH, Security+, CEH, or equivalent
What We Do
As the largest global automotive technology company, Keyloop delivers cutting-edge solutions, tailored to the modern needs of auto retailers and OEMs alike. With 40 years of automotive DNA, and a deep understanding of what it takes to drive success, Keyloop solutions are delivered in over 90 countries, and trusted by more 20,000 retailers and 80 OEMs worldwide. From the showroom to the workshop, and everything in between, its technology facilitates distinctive customer experiences between key systems, tools and departments. With modern consumers demanding increasingly high levels of service and responsiveness, Keyloop and their partners connect retailers and OEMs to consumers through every step of their journey. Keyloop delivers a proven technology ecosystem that redesigns the automotive retail experience to cultivate lasting loyalty and optimise margins through increased efficiency, elevated experiences, and unrivalled connected data. For more information, please visit www.keyloop.com







