L2 Security Analyst
Core
Lead investigation of higher-severity security incidents, perform targeted hunting, and provide response recommendations for clients.
Role type
Senior SOC Analyst (Incident Response & Threat Hunting)
Builds
Incident response outcomes and detection tuning for client security operations
Domain
Cybersecurity / Managed Detection and Response (MDR)
Deliverable
client delivery
Required skills
Incident investigation, threat hunting, scope assessment, evidence-based recommendations, Level 1 guidance, AI literacy, on-call escalation
Preferred skills
Microsoft Sentinel/Defender/Cortex XSOAR, KQL, SOAR workflows, PowerShell, ATT&CK analysis
Technologies
Microsoft Sentinel, Microsoft Defender XDR, Cortex XSOAR, Elastic Security, Vectra NDR, Logic Apps, PowerShell
Responsibilities
Lead investigation of higher-severity incidents, determine root cause and scope, use targeted hunting to validate suspicious activity, produce evidence-based response records, review escalations from Level 1 analysts, provide weekly on-call escalation support, identify visibility gaps for detection tuning, propose automation ideas, support technical growth of other analysts
Seniority
Senior, hands-on IC