Job Summary:
We are seeking a highly skilled and experienced Cyber Security Operations Analyst - L2 to join our dynamic Security Operations Center (SOC) team. The ideal candidate will be responsible for leading Level 2 (L2) investigations, serving as the point of contact (POC) for all clients, and conducting incident response and support sessions. This role requires a deep understanding of cybersecurity principles, excellent problem-solving skills, and the ability to work collaboratively with clients and team members.
Key Responsibilities:
· L2 Investigations: Lead and manage Level 2 investigations to identify, analyze, and respond to security incidents. Ensure timely and effective resolution of incidents while maintaining detailed documentation.
· Point of Contact (POC) for Clients: Act as the primary point of contact for all clients, addressing their cybersecurity concerns and providing expert guidance. Build and maintain strong client relationships to ensure satisfaction and trust.
· Troubleshooting Sessions: Conduct troubleshooting sessions with clients to resolve complex security issues. Collaborate with clients to understand their needs and provide tailored solutions.
· Creation of Standard Operating Procedures (SOPs): Develop, document, and maintain comprehensive SOPs for various security operations and processes. Ensure SOPs are up-to-date and aligned with industry best practices.
· Fine Tuning and Use Case Creation: Continuously fine-tune security tools and technologies to enhance detection and response capabilities. Create and implement use cases to address emerging threats and vulnerabilities.
· Threat Hunting: Proactively hunt for threats within the organization's network and systems. Utilize advanced threat hunting techniques to identify and mitigate potential security risks.
· Threat Intelligence (TI) Advisories Dissemination: Disseminate threat intelligence advisories to relevant stakeholders. Ensure timely communication of emerging threats and vulnerabilities.
· SIEM Health Analytics: Monitor and analyze the health and performance of Security Information and Event Management (SIEM) systems. Ensure SIEM systems are functioning optimally and provide actionable insights.
· Reporting: Prepare and deliver monthly, weekly, and incident reports to management and clients. Provide detailed analysis and recommendations based on findings.
· SOC Maturity and Gap Analysis: Conduct maturity and gap analysis of the SOC to identify areas for improvement. Develop and implement strategies to enhance SOC capabilities and effectiveness.
· Training and Mentorship: Provide training and mentorship to new joiners and junior analysts. Aid in investigations and ensure they are equipped with the necessary skills and knowledge.
Skills
Qualifications:
-
Bachelor's degree in Cybersecurity, Information Technology, or a related field.
-
5+ years of experience in SOC or similar cybersecurity role.
-
Strong knowledge of cybersecurity principles, threat landscapes, and incident response methodologies.
-
Proficiency in using SIEM tools including Qradar, Log rhythm & Microsoft Sentinel, threat intelligence platforms, and other security technologies.
-
Experienced in SOAR platform administration and the end-to-end implementation of automated security playbooks.
-
Excellent analytical, problem-solving, and communication skills.
-
Ability to work effectively under pressure and manage multiple priorities.
-
Relevant certifications such asBTL2, CySA+, CEH, SC-200, ECIR, eCTHP or equivalent are preferred.