More jobs:
SOC Analyst L2
Job in
Greater London, London, Greater London, W1B, England, UK
Listed on 2026-02-25
Listing for:
CYBERPROOF SG PTE. LIMITED
Full Time
position Listed on 2026-02-25
Job specializations:
-
IT/Tech
Cybersecurity, Security Manager
Job Description & How to Apply Below
SOC Analyst L2/RE is an operational role, focusing on ticket quality and security incident deeper investigation and will be responsible to handle the escalated incidents from Level 1 team within SLA.
Responsibilities- SOC Analyst L2 would work closely with SOC L1 team, L3 team & customer and responsible for performing deeper analysis and need to interact with client in daily calls and need to take the responsibility of handling the True Positive incidents on time.
- Handle escalated incidents and coordinate with client when required.
- Work closely with Client Duty Officers on any ad-hoc operational requests.
- Collaborate with the Exabeam, Splunk, and Log Source teams to resolve issues as needed.
- Take appropriate action on IOCs received from client when required.
- Fine-tune and create new detection rules based on client requests.
- Create and manage the Incident handling playbook, process runbooks and ad-hoc documents whenever needed
- Recommend fine tuning for client with logic and threshold, and possibly the query as well for the SIEM
- Recommend new use cases with logic and threshold, and possibly the query as well for the SIEM
- Provide data from Splunk/Exabeam during client audit activities.
- Share monthly data to client for internal IMM meetings.
- Share top user-reported malicious emails from Abnormal Security for reward and recognition programs.
- Prepare RCA report when required
- Share knowledge to other analysts in their role and responsibilities
- Provide knowledge transfer to L1 such as advance hunting techniques, guides, cheat sheets etc
- Minimum 5 Years of experience in Security Operations
- Security event monitoring, alert triage, and thorough incident investigation.
- Research and understand log sources for effective security monitoring.
- Isolate issues, respond to incidents, and mitigate threats swiftly.
- Adjust SIEM rules for better alert and incident specifications.
- Optimize SIEM capabilities, aid in audit/logging, and generate timely reports.
- Develop and maintain security operation standards, procedures, and playbooks.
SOC, SIEM Platforms,Splunk, Exabeam, SOAR platform, Google Sec Ops, Log Source, Security Operations
#J-18808-LjbffrNote that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×