SOC Analyst - L2
Role Overview
The SOC Analyst L2 is responsible for
advanced threat detection, incident investigation, threat hunting, malware
analysis, security incident response, and continuous improvement of security
monitoring capabilities. This role serves as the primary escalation point for
L1 analysts and plays a key role in strengthening the organization's cyber
defense posture.
Key Responsibilities
Incident Response & Investigation
- Investigate escalated security incidents and validate true
positives.
- Perform root cause analysis and impact assessment.
- Lead containment, eradication, and recovery activities.
- Conduct detailed forensic investigations on endpoints and
systems.
- Coordinate with IT, Cloud, Network, and Security Engineering
teams during major incidents.
Threat Hunting
- Proactively identify emerging threats and hidden adversary
activities.
- Develop threat hunting hypotheses using MITRE ATT&CK
Framework.
- Identify attacker tactics, techniques, and procedures (TTPs).
- Utilize threat intelligence feeds to improve detection
capabilities.
SIEM & Detection Engineering
- Tune and optimize SIEM correlation rules.
- Develop new threat detection use cases.
- Reduce false positives through continuous rule enhancement.
- Improve detection coverage across cloud, endpoints, network,
and identity platforms.
Cloud Security Operations
- Monitor and investigate security events across Azure and AWS
environments.
- Analyze IAM anomalies, privilege escalations, and cloud
misconfigurations.
- Support cloud-native security tools and security posture
management platforms.
Endpoint & Malware Analysis
- Perform malware investigation and behavioral analysis.
- Analyze EDR/XDR detections.
- Conduct IOC and IOA investigations.
- Support ransomware response activities.
Technical Skills
SIEM Platforms
- Microsoft Sentinel
- Splunk Enterprise Security
- IBM QRadar
- LogRhythm
Endpoint & XDR Security
- Microsoft Defender XDR
- CrowdStrike Falcon
- SentinelOne
- Cortex XDR
Threat Hunting & Incident Response
- MITRE ATT&CK Framework
- Cyber Kill Chain
- Threat Intelligence Platforms
- IOC/IOA Analysis
- Digital Forensics
Cloud Security
- Microsoft Azure Security
- AWS Security Services
- Cloud Security Posture Management (CSPM)
- Identity Security Monitoring
Security Controls
- WAF
- CASB
- DLP
- Email Security
- Zero Trust Security Architecture
- Zscaler Security Monitoring (Preferred)
Shift & Scheduling
- 24x7 Security Operations Coverage
- On-call Support for Critical Incidents
- Major Incident Management Participation
- Support During Security Breach Investigations
Preferred Certifications
- Microsoft SC-200 Security Operations Analyst
- CompTIA CySA+
- CEH (Certified Ethical Hacker)
- Splunk Enterprise Security Administrator
Cloud & Security Certifications
- Microsoft Azure Security Engineer (AZ-500)
- AWS Security Specialty
- Google Professional Cloud Security Engineer
Zscaler Certifications (Preferred)
- Zscaler Certified Administrator (ZCCA-IA)
- Zscaler Certified Security Administrator
- Zscaler Certified Cloud Administrator
- Zscaler Internet Access (ZIA) Administration Experience
Skills Required
- Experience with SIEM platforms including Microsoft Sentinel, Splunk Enterprise Security, IBM QRadar, or LogRhythm
- Experience with endpoint and XDR security platforms including Microsoft Defender XDR, CrowdStrike Falcon, SentinelOne, or Cortex XDR
- Knowledge of the MITRE ATT&CK Framework and Cyber Kill Chain
- Threat hunting, threat intelligence, IOC and IOA analysis experience
- Digital forensics and malware investigation experience
- Experience with Microsoft Azure Security and AWS Security Services
- Knowledge of cloud security posture management and identity security monitoring
- Knowledge of WAF, CASB, DLP, email security, and Zero Trust security architecture
- Microsoft SC-200 Security Operations Analyst certification
- CompTIA CySA+ certification
- Certified Ethical Hacker certification
- Splunk Enterprise Security Administrator certification
- Microsoft Azure Security Engineer AZ-500 certification
- AWS Security Specialty certification
- Google Professional Cloud Security Engineer certification
- Zscaler certifications or Zscaler Internet Access administration experience
What We Do
SRM Technologies is a global IT services company specialising in automotive technologies, digital transformation and product engineering services. We provide technology consulting, platform development, data analytics, artificial intelligence, cloud enablement, digital infrastructure, quality assurance, embedded software and design to manufacturing product solutions to various industries and enterprises across the North America, Japan, Europe and India. At the heart of our organization are passionate employees who embody our core belief - 'ideas@work.' We firmly believe that ideas and innovation truly matter only when they create a meaningful impact on our customers' businesses and the lives of their end customers. Therefore, we prioritize the practical application of these ideas and their transformative impact through our talented and ever-growing workforce. 𝘚𝘙𝘔 𝘛𝘦𝘤𝘩 𝘪𝘴 𝘢 𝘱𝘳𝘰𝘶𝘥 𝘮𝘦𝘮𝘣𝘦𝘳 𝘰𝘧 𝘵𝘩𝘦 𝘚𝘙𝘔 𝘎𝘳𝘰𝘶𝘱, 𝘢 𝘮𝘶𝘭𝘵𝘪𝘯𝘢𝘵𝘪𝘰𝘯𝘢𝘭 𝘤𝘰𝘯𝘨𝘭𝘰𝘮𝘦𝘳𝘢𝘵𝘦 𝘸𝘪𝘵𝘩 𝘢 𝘳𝘪𝘤𝘩 𝘩𝘪𝘴𝘵𝘰𝘳𝘺 𝘴𝘱𝘢𝘯𝘯𝘪𝘯𝘨 𝘰𝘷𝘦𝘳 𝘧𝘰𝘶𝘳 𝘥𝘦𝘤𝘢𝘥𝘦𝘴. 𝘛𝘩𝘦 𝘚𝘙𝘔 𝘎𝘳𝘰𝘶𝘱 𝘰𝘱𝘦𝘳𝘢𝘵𝘦𝘴 𝘪𝘯 𝘥𝘪𝘷𝘦𝘳𝘴𝘦 𝘴𝘦𝘤𝘵𝘰𝘳𝘴, 𝘪𝘯𝘤𝘭𝘶𝘥𝘪𝘯𝘨 𝘌𝘥𝘶𝘤𝘢𝘵𝘪𝘰𝘯, 𝘛𝘦𝘤𝘩𝘯𝘰𝘭𝘰𝘨𝘺, 𝘏𝘦𝘢𝘭𝘵𝘩𝘤𝘢𝘳𝘦, 𝘢𝘯𝘥 𝘔𝘦𝘥𝘪𝘢







