We are seeking an experienced Senior SOC Analyst – L2 to join our Security Operations Center located in Bahria Town Phase 7, Rawalpindi. The ideal candidate will be responsible for monitoring, investigating, and responding to security alerts within both SOC and NOC environments. This role involves detailed incident analysis, supporting escalation processes, and managing incident response activities for multiple clients. The candidate will work closely with various teams to ensure timely and effective handling of security events and infrastructure alerts.
Key Responsibilities
- Perform Level 2 monitoring, investigation, and triage of security alerts and incidents across multiple client environments.
- Utilize SOC and NOC monitoring tools such as Elastic and Kibana to analyze security and infrastructure events.
- Correlate logs from diverse sources including network, security, endpoint, server, and infrastructure systems.
- Investigate security events using platforms like IBM QRadar and Elastic/Kibana.
- Analyze endpoint alerts with CrowdStrike, Microsoft Defender, Trend Micro, and Sophos.
- Examine network and behavioral security alerts using Darktrace.
- Investigate email security and phishing alerts through Mimecast.
- Conduct IOC investigations involving IP addresses, domains, URLs, hashes, users, and endpoints.
- Correlate events across multiple security tools to assess incident scope and impact.
- Escalate incidents based on severity, following defined SOC/NOC procedures and SLAs.
- Prepare detailed incident investigation reports and escalation summaries.
- Support troubleshooting and investigation of infrastructure and availability alerts within NOC environments.
- Coordinate with NOC, IT, infrastructure, and client teams for incident resolution.
- Perform threat hunting and proactive investigations based on suspicious indicators and attack patterns.
- Apply the MITRE ATT&CK framework during investigations where applicable.
- Maintain accurate incident documentation, investigation notes, and ticket updates.
- Support daily SOC/NOC operations, including shift handovers, incident reviews, and reporting.
- Identify recurring false positives and assist in refining alert rules, dashboards, and detection use cases.
- Provide guidance and support to Level 1 analysts during complex investigations.
- Escalate critical incidents to Level 3 or management as per SLA and escalation protocols.
Required Qualifications
- 3 to 5 years of experience in SOC, cybersecurity, or NOC operations.
- Hands-on experience with SIEM platforms, preferably IBM QRadar and/or Elastic SIEM.
- Proficiency with EDR/XDR tools such as CrowdStrike, Microsoft Defender, Trend Micro, or Sophos.
- Experience investigating network security and behavioral analytics alerts, ideally using Darktrace.
- Familiarity with email security platforms like Mimecast.
- Understanding of NOC monitoring and infrastructure logs is preferred.
- Strong knowledge of Windows and Linux security events.
- Solid understanding of Active Directory / Entra ID.
- Good grasp of network security concepts, authentication, and access-related attacks.
- Experience in malware and phishing investigations, IOC analysis, and incident response lifecycle.
- Ability to analyze and correlate logs across multiple security products.
- Knowledge of common attack techniques including credential attacks, lateral movement, privilege escalation, execution, persistence, and defense evasion.
- Ability to independently handle Level 2 incidents with strong hands-on investigation skills rather than just monitoring and forwarding alerts.
Preferred Qualifications and Certifications
Certifications are preferred but not mandatory and may include:
- Security+
- CySA+
- CEH
- SC-200
- Splunk, Elastic, or QRadar-related certifications
- Other relevant SOC or cybersecurity certifications
This role offers an opportunity to work in a dynamic SOC environment, collaborating with cross-functional teams and contributing to the security posture of multiple clients through proactive threat detection and incident response.