Security Operations Center Analyst- L2
Incedo Inc. · Gurugram, Haryana, India
Apply & track with Apply EdgeJob Description – SOC Analyst (L2)Role: Security Operations Center (SOC) – L2 AnalystExperience4–7 years of experience in Cyber Security Operations / SOC3+ years of hands-on experience in security monitoring, incident investigation, and incident responseKey ResponsibilitiesInvestigate and analyze security incidents escalated by the L1 SOC teamPerform alert triage, log analysis, event correlation, and root cause analysisValidate security alerts and distinguish true positives from false positivesInvestigate phishing, malware, unauthorized access, privilege escalation, and cloud security incidentsMonitor and analyze security events across endpoints, networks, cloud, and identity platformsCoordinate with L3 engineers, infrastructure teams, and other stakeholders for incident remediationMaintain incident documentation, investigation reports, and ticket updatesEnsure SLA adherence in a 24x7 SOC environmentMust-Have SkillsSIEM: Splunk, QRadar, Microsoft Sentinel, LogRhythmEDR/XDR: CrowdStrike, Microsoft Defender, SentinelOne, Cortex XDRSecurity Monitoring: Firewall, IDS/IPS, WAF, VPN, Email Security, Endpoint SecurityLog Analysis: Windows, Linux, Active Directory, Microsoft 365, CloudTrailThreat Analysis: IOC validation, Threat Intelligence, MITRE ATT&CKNetworking: TCP/IP, DNS, HTTP/HTTPS, SMTPGood-to-Have SkillsAWS or Azure securityPowerShell or PythonKnowledge of the NIST Incident Response FrameworkPreferred CertificationsSecurity+SC-200CEHCySA+Splunk Certified UserIBM QRadar SIEM FoundationEducationBachelor's degree in Computer Science, Information Technology, Cyber Security, or a related field.Work Location & Shift24x7 rotational shiftWillingness to work on weekends and holidays as requiredKeywordsSOC, SIEM, Splunk, QRadar, Microsoft Sentinel, EDR, CrowdStrike, Incident Response, Threat Hunting, Log Analysis