SOC Analyst - L2
Role Overview
We are seeking a highly skilled SOC Analyst (L2) to provide hands-on security monitoring, investigation, and incident response support within a 24x7 Security Operations Center (SOC). The primary focus of this role is to ensure continuous security queue coverage, perform effective triage of medium and low-severity alerts, rapidly escalate high and critical security events, and maintain high-quality incident documentation and handoffs.
The ideal candidate will have strong investigative skills across endpoint, identity, cloud, and network security domains, with practical experience using EDR platforms, case management tools, SQL-based analysis, and structured incident response procedures.
Key Responsibilities
Security Monitoring & Alert Triage
Monitor and triage security alerts from multiple security platforms on a 24x7 basis.
Perform detailed analysis of medium and low-severity alerts and determine appropriate disposition.
Rapidly identify, validate, and escalate high and critical severity incidents according to defined SLAs.
Execute incident response runbooks and playbooks to ensure consistent handling of security events.
Maintain hygiene and ensure timely closure or escalation of alerts.
CrowdStrike Falcon is preferred. We have a large footprint in both prod and corp. Other EDR experience could be helpful but understanding Crowdstrike is top priority
AWS is our largest public cloud footprint. GCP and Azure are significantly smaller. General public cloud experience is a basic qualification; however AWS is a preferred qualification
Incident Investigation & Response
Conduct hands-on investigations involving endpoint, identity, cloud, email, and network-based security events.
Correlate data from multiple sources to determine attack scope, impact, and root cause.
Gather and document evidence to support incident disposition and remediation recommendations.
Participate in containment, eradication, and recovery activities during security incidents.
Support post-incident reviews and lessons learned activities.
Case Management & Documentation
Manage incidents through Tines or comparable case management and workflow platforms.
Maintain accurate incident records, investigation notes, and evidence artifacts.
Produce clear and actionable updates for stakeholders and escalation teams.
Ensure high-quality shift handovers with complete context, findings, and pending actions.
Security Analytics & Threat Investigation
Perform log and data analysis using Databricks, SQL, and security telemetry sources.
Investigate suspicious activity using endpoint, identity, cloud, and authentication data.
Support threat hunting activities and identify patterns indicative of malicious behavior.
Recommend improvements to alert logic, detection rules, and operational processes.
Collaboration & Continuous Improvement
Collaborate with SOC Leads, Incident Responders, Cloud Operations, and Infrastructure teams.
Assist in refining operational runbooks, playbooks, and investigation procedures.
Contribute to knowledge management and continuous service improvement initiatives.
Required Technical Skills
Endpoint Security
CrowdStrike Falcon
Skills Required
- Experience with SIEM platforms including Microsoft Sentinel, Splunk Enterprise Security, IBM QRadar, or LogRhythm
- Experience with endpoint and XDR security platforms including Microsoft Defender XDR, CrowdStrike Falcon, SentinelOne, or Cortex XDR
- Knowledge of the MITRE ATT&CK Framework and Cyber Kill Chain
- Threat hunting, threat intelligence, IOC and IOA analysis experience
- Digital forensics and malware investigation experience
- Experience with Microsoft Azure Security and AWS Security Services
- Knowledge of cloud security posture management and identity security monitoring
- Knowledge of WAF, CASB, DLP, email security, and Zero Trust security architecture
- Microsoft SC-200 Security Operations Analyst certification
- CompTIA CySA+ certification
- Certified Ethical Hacker certification
- Splunk Enterprise Security Administrator certification
- Microsoft Azure Security Engineer AZ-500 certification
- AWS Security Specialty certification
- Google Professional Cloud Security Engineer certification
- Zscaler certifications or Zscaler Internet Access administration experience
What We Do
SRM Technologies is a global IT services company specialising in automotive technologies, digital transformation and product engineering services. We provide technology consulting, platform development, data analytics, artificial intelligence, cloud enablement, digital infrastructure, quality assurance, embedded software and design to manufacturing product solutions to various industries and enterprises across the North America, Japan, Europe and India. At the heart of our organization are passionate employees who embody our core belief - 'ideas@work.' We firmly believe that ideas and innovation truly matter only when they create a meaningful impact on our customers' businesses and the lives of their end customers. Therefore, we prioritize the practical application of these ideas and their transformative impact through our talented and ever-growing workforce. ??? ???? ?? ? ????? ?????? ?? ??? ??? ?????, ? ????????????? ???????????? ???? ? ???? ??????? ???????? ???? ???? ???????. ??? ??? ????? ???????? ?? ??????? ???????, ????????? ?????????, ??????????, ??????????, ??? ?????








