Source description
About the role
We are looking for candidates with Primary Skillset: SIEM, Splunk, SOC SOC L2/L3 Analyst with experience in Splunk, Azure Sentinel, XSIAM, and SPL/KQL/XQL. Good knowledge of SIEM architecture and incident troubleshooting using SIEM tools. Experience with EDR/XDR tools and familiarity with malware triage. Strong analytical and decisionmaking skills for whitelisting and blacklisting. Ability to create use cases for different log sources and validate SOPs. Knowledge of coordinating with L2 and L1 teams for incident resolution and documentation. Coordination with the SOC Monitoring team for issue resolution and reporting. Escalation of critical issues to the appropriate levels to prevent business risks. Building and maintaining incident reports, advisories, and reviews to ensure SLAs are met. Updating and maintaining the SOC knowledge base with new security incidents and documentation. Creating daily status reports and submitting them for review. Reviewing advisories and implementing necessary detection measures. Developing parsers for SIEM using regular expressions (regex). The SOC Level 2 Analyst will be responsible for supporting the client's incident response efforts. Responsibilities include monitoring, detecting, investigating, and mitigating incidents across various technologies and platforms. Ideal candidates should have strong analytical and incidenthandling skills, experience with SIEM and EDR tools, and a deep understanding of information security technologies.
More at ValueLabs