The Role
Serves as the SOC escalation point for complex QRadar incidents. Conducts deep-dive investigations, threat hunting, log correlation, malware and phishing analysis, rule tuning, and incident response coordination. Develops AQL searches and detection use cases, integrates threat intelligence, leads root cause analysis, supports vulnerability and patch validation, mentors L1 analysts, and improves SOC processes and playbooks.
Summary Generated by Built In
The SOC Sr Analyst L2 serves as the escalation point for complex security incidents detected within IBM QRadar. The L2 analyst conducts deep-dive investigations, performs threat hunting, tunes correlation rules, and coordinates incident response activities. This role requires strong analytical and technical expertise in QRadar SIEM operations, along with proactive detection and threat mitigation skills.
Key Responsibilities• Analyze escalated incidents and offenses from L1 analysts for deeper investigation and containment.
• Perform in-depth log correlation and timeline reconstruction using IBM QRadar.
• Develop and fine-tune QRadar correlation rules, AQL searches, and custom use cases for improved detection.
• Perform proactive threat hunting across multiple data sources using QRadar and threat intelligence feeds.
• Coordinate response actions during security incidents, ensuring containment, eradication, and recovery.
• Lead the root cause analysis (RCA) and prepare incident summary reports with actionable recommendations.
• Integrate and validate external threat intelligence feeds (STIX/TAXII) within QRadar for advanced correlation.
• Collaborate with IT, network, and endpoint teams for incident validation and resolution.
• Support vulnerability management, patch validation, and policy enforcement activities.
• Provide mentorship and technical guidance to L1 analysts.
• Participate in continuous improvement initiatives for SOC processes and playbooks.
Required Technical Skills• Advanced proficiency with IBM QRadar SIEM – rule creation, offense management, AQL queries, dashboards.
• Strong understanding of network and endpoint telemetry, including firewall, proxy, and EDR logs.
• Experience with malware analysis, phishing investigation, and digital forensics concepts.
• Knowledge of scripting languages (Python, PowerShell, or Bash) for automation of analysis tasks.
• Understanding of threat intelligence platforms and integration mechanisms (STIX/TAXII).
• Experience in incident response processes aligned with NIST or SANS frameworks.
• Ability to work independently and collaboratively in high-pressure security incidents.
• Excellent report writing, communication, and documentation skills.
Qualifications & Certifications• Bachelor’s or master’s degree in computer science, Cybersecurity, or related discipline.
• 2–5 years of experience in SOC, Incident Response, or Threat Analysis roles.
• Preferred certifications: IBM Certified Analyst – QRadar SIEM, GCIH, GCIA, CEH, CySA+, or MITRE ATT&CK Defender (MAD).
Skills Required
- Advanced proficiency with IBM QRadar SIEM, including rule creation, offense management, AQL queries, and dashboards
- Strong understanding of network and endpoint telemetry, including firewall, proxy, and EDR logs
- Experience with malware analysis, phishing investigation, and digital forensics concepts
- Knowledge of Python, PowerShell, or Bash scripting for automation
- Understanding of threat intelligence platforms and STIX/TAXII integration mechanisms
- Experience with incident response processes aligned with NIST or SANS frameworks
- Excellent report writing, communication, and documentation skills
- Bachelor’s or master’s degree in computer science, cybersecurity, or a related discipline
- Two to five years of experience in SOC, incident response, or threat analysis roles
- IBM Certified Analyst QRadar SIEM, GCIH, GCIA, CEH, CySA+, or MITRE ATT&CK Defender certification
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Infosec is a cybersecurity education company that helps IT and security professionals advance their careers and helps employees become safer online at work and home. Its offerings include Infosec Skills, with more than 1,400 hands-on cybersecurity courses and instructor-led certification boot camps, and Infosec IQ, which provides security-awareness training. Its mission is to equip individuals and organizations to outsmart cybercrime.







