Apply Edge Start your job search

SOC Analyst L2

Tata Consultancy Services · Chennai, Tamil Nadu, India

Apply & track with Apply Edge
Job descriptionRole & responsibilitiesSOC Analyst L2Security Monitoring & Incident ResponseExecute/lead initial containment, forensics scoping, and stakeholder updates; align with both best industry practice and internal IR playbooks.Lead investigations across Defender XDR/MDE and CrowdStrike (process trees, lateral movement, identity signals).Use Tanium for rapid endpoint scoping and live response actions (as per policy).Analyse Joe Sandbox reports (behaviour trees, network indicators, dropped files); derive IOCs/YARA candidates; coordinate containment.Design/maintain Cortex XSOAR playbooks (data enrichment, containment workflows, approvals, notifications); implement guardrails.Threat Detection & HuntingDeep familiarity with Azure AD/Entra ID, Azure Activity/Signin logs, M365 audit logs, as well as AWS and GCP logs.Author and tune analytic rules in Sentinel (KQL), Elastic (DSL/EQL/KQL/ESQL), Sigma; reduce false positives; add entity mapping and suppression logic.Proactive hunts using ATT&CK-aligned hypotheses (credential theft, persistence, C2); pivot across endpoint, identity, network, and cloud logs.Maintain GitLab repos (branching, merge requests, CI checks for detections) and workflows for detection content (code reviews, approvals, CI quality checks).Expertise:Deep knowledge of SIEM, SOAR, and EDR platformsDeep knowledge of threat intelligence, and incident response frameworksFamiliarity with MITRE ATT&CK, NIST, and ISO 27001 standardsAbility to analyse logs, network traffic, and malware indicators