We are seeking a skilled Senior SOC Analyst – L2 to join our Security Operations Center located in Bahria Town Phase 7, Rawalpindi. The ideal candidate will be responsible for monitoring, investigating, and responding to security alerts within both SOC and NOC environments. This role involves detailed incident analysis, supporting escalation processes, and managing incident response activities across multiple client environments. The candidate must demonstrate strong hands-on investigation skills and the ability to independently handle L2 incidents, going beyond simple alert monitoring and escalation.
Key Responsibilities
- Perform Level 2 monitoring, investigation, and triage of security alerts and incidents.
- Monitor and analyze security and infrastructure events across various client environments.
- Utilize SOC and NOC monitoring tools such as Elastic and Kibana for event detection.
- Investigate and correlate logs from diverse sources including network, security, endpoint, server, and infrastructure systems.
- Conduct security event investigations using IBM QRadar and Elastic/Kibana platforms.
- Analyze endpoint alerts with tools like CrowdStrike, Microsoft Defender, Trend Micro, and Sophos.
- Examine network and behavioral security alerts using Darktrace.
- Investigate email security and phishing incidents through Mimecast.
- Perform Indicator of Compromise (IOC) investigations involving IP addresses, domains, URLs, hashes, users, and endpoints.
- Correlate events across multiple security tools to assess the scope and impact of incidents.
- Execute incident escalation following severity levels and SOC/NOC procedures and SLAs.
- Prepare comprehensive incident investigation reports and escalation summaries.
- Support troubleshooting and investigation of infrastructure and availability alerts within NOC environments.
- Collaborate with NOC, IT, infrastructure, and client teams on security and infrastructure-related incidents.
- Conduct threat hunting and proactive investigations based on suspicious indicators and attack patterns.
- Apply the MITRE ATT&CK framework during security investigations where relevant.
- Maintain accurate documentation, investigation notes, and ticket updates.
- Support daily SOC/NOC operations including shift handovers, incident reviews, and reporting.
- Identify recurring false positives and contribute to improving alert rules, dashboards, and detection use cases.
- Provide guidance and support to Level 1 analysts during complex investigations.
- Escalate critical incidents to Level 3 or management according to defined SLAs and escalation protocols.
Required Qualifications
- Hands-on experience with SIEM platforms, preferably IBM QRadar and/or Elastic SIEM.
- Proficiency with EDR/XDR platforms such as CrowdStrike, Microsoft Defender, Trend Micro, or Sophos.
- Experience investigating network security and behavioral analytics alerts, ideally with Darktrace.
- Familiarity with email security platforms like Mimecast.
- Understanding of NOC monitoring and infrastructure logs is preferred.
- Strong knowledge of Windows and Linux security events.
- Experience with Active Directory / Entra ID.
- Solid grasp of network security concepts and authentication/access-related attacks.
- Skilled in malware and phishing investigations, IOC analysis, and incident response lifecycle.
- Ability to analyze and correlate logs across multiple security products.
- Good understanding of common attack techniques including credential attacks, lateral movement, privilege escalation, execution, persistence, and defense evasion.
- 3 to 5 years of experience in SOC, cybersecurity, or NOC operations.
Preferred Qualifications
- Relevant certifications such as Security+, CySA+, CEH, SC-200, or certifications related to Splunk, Elastic, or QRadar are preferred but not mandatory.
- Other recognized SOC or cybersecurity certifications will be considered an advantage.
This position requires a proactive and detail-oriented professional capable of managing complex security incidents independently, ensuring effective response and mitigation within a dynamic SOC/NOC environment.