Search by job, company or skills

  • Posted 4 hours ago
  • Be among the first 10 applicants

Job Description

Job description

Role & responsibilities

SOC Analyst L2

Security Monitoring & Incident Response

  • Execute/lead initial containment, forensics scoping, and stakeholder updates; align with both best industry practice and internal IR playbooks.
  • Lead investigations across Defender XDR/MDE and CrowdStrike (process trees, lateral movement, identity signals).
  • Use Tanium for rapid endpoint scoping and live response actions (as per policy).
  • Analyse Joe Sandbox reports (behaviour trees, network indicators, dropped files); derive IOCs/YARA candidates; coordinate containment.
  • Design/maintain Cortex XSOAR playbooks (data enrichment, containment workflows, approvals, notifications); implement guardrails.

Threat Detection & Hunting

  • Deep familiarity with Azure AD/Entra ID, Azure Activity/Signin logs, M365 audit logs, as well as AWS and GCP logs.
  • Author and tune analytic rules in Sentinel (KQL), Elastic (DSL/EQL/KQL/ESQL), Sigma; reduce false positives; add entity mapping and suppression logic.
  • Proactive hunts using ATT&CK-aligned hypotheses (credential theft, persistence, C2); pivot across endpoint, identity, network, and cloud logs.
  • Maintain GitLab repos (branching, merge requests, CI checks for detections) and workflows for detection content (code reviews, approvals, CI quality checks).

Expertise:

  • Deep knowledge of SIEM, SOAR, and EDR platforms
  • Deep knowledge of threat intelligence, and incident response frameworks
  • Familiarity with MITRE ATT&CK, NIST, and ISO 27001 standards
  • Ability to analyse logs, network traffic, and malware indicators

More Info

Job Type:
Industry:
Function:
Employment Type:

Job ID: 153815775

Beware of Scammers

We don’t charge money for job offers