O
OcIT2h ago
Indeed

SOC Analyst L2

Gurugram, Haryana
Full Time
Mid Level

Auto Apply to 50+ AI Matched SOC Analyst L2 Jobs

Use Auto Apply Agents to Bulk Apply jobs with ATS Optimised Resumes, find verified Insider Connections for jobs at OcIT

Full Job Description

Enhanced Job Description

The SOC L2 Analyst at OcIT is responsible for advanced security incident investigation, validation, and response. This role involves deep analysis of escalated alerts, threat intelligence correlation, and incident containment while ensuring adherence to SLAs. Key responsibilities include:

  • Performing detailed investigations of security alerts escalated from L1 teams using SIEM (Wazuh, Seceon aiSIEM) and log analysis tools.
  • Validating true positives and eliminating false positives through threat intelligence and forensic analysis.
  • Conducting root cause analysis and documenting incidents with timelines, impact assessments, and remediation steps.
  • Leading incident response activities, including containment, eradication, and recovery support across Windows, Linux, and cloud environments (Azure, AWS, Google Workspace).
  • Investigating email security incidents (phishing, malware, BEC) and cloud security alerts using Microsoft 365, Azure AD, and cloud audit logs.
  • Reviewing vulnerability assessments and supporting remediation tracking via platforms like ConnectSecure, Nessus, and Qualys.
  • Developing and optimizing SIEM correlation rules and detection use cases aligned with MITRE ATT&ACK techniques.
  • Supporting automation and orchestration initiatives to enhance SOC efficiency and incident response times.
  • Mentoring L1 analysts and assisting in shift leadership during peak operational periods.
  • Participating in post-incident reviews to recommend security improvements.
Key Skills & Requirements
  • 5–8 years of SOC/security operations experience.
  • Bachelor’s degree in Computer Science, Information Security, or related field.
  • Certifications preferred: CEH, Security+, CySA+, or equivalent.
  • Hands-on experience with SIEM platforms (Wazuh, Seceon aiSIEM), Linux OS, and EDR tools (Microsoft Defender for Endpoint, CrowdStrike Falcon).
  • Strong knowledge of firewalls, IDS/IPS, VPN, proxy logs, and cloud security monitoring (Azure AD, AWS CloudTrail, GCP Audit Logs).
  • Familiarity with scripting (PowerShell, Python, Bash), ticketing tools (ServiceNow, ConnectWise), and threat intelligence platforms.
  • Basic malware analysis and forensic investigation skills.
  • Ability to create and optimize detection rules using KQL, SPL, or equivalent query languages.

Company

O

OcIT

OcIT is a leading cybersecurity solutions provider based in Gurugram, Haryana, specializing in advanced threat detection, incident response, and security operations. With a focus on SOC (Security Oper...

Gurugram, Haryana
Posted on Indeed