Job Description
Job Title
SOC L2 Analyst (SIEM / SOAR / UEBA)
Job Summary
The L2 SOC Analyst supports the organizations cybersecurity operations by reviewing and
investigating security alerts, responding to incidents, and improving security monitoring
systems. The role works closely with SOC teams and IT to help protect company systems and
data from cyber threats.
Key Responsibilities
Perform Level 2 analysis of security alerts generated by SIEM, SOAR, and UEBA tools.
Validate incidents escalated from L1 SOC analysts and determine true positives vs false
positives.
Conduct in-depth investigation of security events such as Suspicious user behavior,
Privilege misuse, Malware and ransomware activity, Lateral movement and insider
threats
Lead or support incident response activities, including containment, eradication, and
recovery.
Analyze logs from multiple sources including endpoints, servers, network devices, cloud
platforms, and applications.
Fine-tune SIEM correlation rules, alerts, and dashboards to reduce noise and improve
detection eiciency.
Develop new use cases based on threat intelligence and emerging attack patterns.
Execute and support SOAR playbooks for automated response actions (account
disablement, IP blocking, ticketing, etc.).
Assist in designing and improving playbooks to optimize response time and analyst
productivity.
Perform manual response steps when automation is insuicient or requires human
validation.
Investigate anomalous behaviour detected by UEBA, including compromised accounts
and insider threat indicators.
Create detailed incident reports including root cause analysis, impact assessment, and
remediation steps.
Maintain investigation playbooks, runbooks, and SOPs.
Provide metrics and insights to SOC leadership (MTTD, MTTR, alert quality).
Work closely with L1 analysts, L3 analysts, IR teams, IT Ops, Cloud, and IAM teams.
Escalate high-risk or conrmed incidents to senior stakeholders as per dened
escalation matrix.
Provide mentoring and guidance to L1 analysts.
Required Skills:
Hands-on experience with SIEM / SOAR platforms like Splunk, QRadar, Gurucul, Google
SecOps, Cortex XSOAR, Sentinel SOAR etc.
Strong understanding of UEBA concepts and tools.
Knowledge of Windows and Linux operating systems, Networking concepts (TCP/IP,
DNS, HTTP, VPN), Cloud security fundamentals (AWS, Azure, GCP logs & IAM) etc.
Familiarity with EDR/XDR solutions.
Understanding of MITRE ATT&CK, kill chain, and TTP mapping.
Strong analytical and problem-solving abilities
Clear written and verbal communication
Ability to work in 24x7 SOC shifts
Experience & Education
5+ years of experience in SOC, Blue Team, or Security Operations roles
Bachelors degree in computer science, IT, Cybersecurity, or equivalent experience
Preferred Certications
CEH, GCIA, GCIH
Splunk / Sentinel / QRadar certications
SOC Analyst (CSA, BTL1)
Cloud security certications (AZ-500, AWS Security)
Reporting Line
SOC Manager / SOC Lead
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
