Lead SOC Analyst
Job Description:
- Monitor security alerts and triage incidents at an L2 level, escalating or resolving as needed.
- Investigate security incidents to determine scope, impact, and root cause.
- Use SIEM and EDR tools to detect, analyze, and respond to threats.
- Conduct threat hunting and analyze indicators of compromise (IOCs) to identify potential risks.
- Perform malware analysis and apply threat intelligence to strengthen detection and response.
- Tune SIEM rules and improve detection logic to reduce false positives and catch real threats faster.
- Lead root cause analysis (RCA), forensic investigations, and prepare incident reports.
- Mentor and guide L1 analysts, helping them build stronger triage and investigation skills.
- Support the development and improvement of SOPs and incident response playbooks.
Requirements
- 6+ years of experience in a security operations or SOC role.
- Hands-on experience with L2 SOC monitoring, alert triage, and incident investigation.
- Practical experience using SIEM and EDR tools.
- Experience with threat hunting, IOC analysis, and incident response.
- Experience with malware analysis and applying threat intelligence.
- Experience tuning SIEM rules and improving detection capabilities.
- Experience conducting RCA, forensic analysis, and writing incident reports.
- Experience mentoring junior analysts and contributing to SOP/playbook development.
Skills Required
- SOC monitoring & alert triage
- SIEM & EDR tools
- Threat hunting & IOC analysis
- Malware analysis & threat intelligence
- SIEM rule tuning
- Root cause analysis & forensics
- Incident reporting
- Mentoring & SOP development