Jobless Developer
W

Posted Today

Open

Engineer II - L2 SOC

PuneOn-siteFull-time

AI Summary

Engineer II - L2 SOC monitors and analyzes security alerts from SIEM and EDR tools, investigates incidents, classifies alerts, and supports vulnerability assessments and client security reviews.

About this role

Overview

Position: Engineer II- L2 SOC

(3 to 5 years of experience)

Type: Full Time Employee (FTE)

Roles and Responsibilities:

  • Monitor and analyze security alerts generated by SIEM platforms including Elastic SIEM, Microsoft Sentinel, and other SIEM tools (e.g., Wazuh, Splunk, QRadar).
  • Perform continuous security monitoring of network traffic, endpoint activity, and system logs to identify suspicious or malicious behavior.
  • Investigate potential security incidents by performing detailed log analysis to detect anomalies and attack patterns.
  • Classify security alerts accurately as True Positive or False Positive based on evidence and analysis.
  • Respond to security incidents promptly by following defined incident response playbooks and SOPs.
  • Escalate confirmed or high‑severity incidents to senior SOC engineers with proper documentation, context, and impact analysis.
  • Track and investigate malware alerts, performing basic static and behavioral analysis using EDR telemetry and sandbox results.
  • Monitor and analyze endpoint activity using EDR tools such as Sentinel One and Microsoft Defender for Endpoint.
  • Conduct phishing email analysis, including:
  • Header and sender analysis
  • URL and attachment inspection
  • Identification of credential-harvesting and malware delivery attempts
  • Support vulnerability assessment activities by reviewing scan results, validating findings, and assisting with remediation tracking.
  • Maintain accurate incident reports, investigation notes, and SOC documentation.
  • Follow daily threat intelligence updates and apply relevant insights to ongoing investigations.
  • Adherent to SOC SLAs, escalation procedures, and operational best practices
  • Support client Baseline Security Reviews by reviewing security tool configurations and documenting gaps against defined security baselines.

Technology skills and Competencies:

  • Basic to intermediate understanding of networking, security, and system administration concepts.
  • Knowledge of:
  • Network security fundamentals
  • Firewalls, IDS/IPS, and SIEM to
  • Vulnerability assessment concepts and security best practices
  • Familiarity with Windows and/or Linux environments.
  • Hands‑on exposure to:
  • SIEM monitoring and alert investigation
  • Incident response and alert triage
  • Endpoint detection and response (EDR) tools •
  • Understanding of common attack techniques including phishing, malware, brute force, and credential abuse.

Certifications:

  • CEH (Certified Ethical Hacker)
  • Microsoft SC‑200 – Security Operations Analyst
  • Microsoft SC‑900 or equivalent security fundamentals certification

Qualifications and experience:

  • Bachelor’s degree in computer science, Information Security, Information Technology, or a related field (or equivalent practical experience).
  • Exposure to SOC operations
  • Exposure to Cybersecurity monitoring
  • Hands‑on experience with SIEM tools and security alert investigation is preferred.

No. of positions: 01

Work Location: Wipfli India, Bengaluru or Pune

Skills

Alert TriageCEHEDR TelemetryElastic SIEMFirewallsIDS/IPSIncident Response PlaybooksLinuxMicrosoft Defender For EndpointMicrosoft SC-200Microsoft SC-900Microsoft SentinelNetwork Security FundamentalsPhishing Email AnalysisQRadarSandbox AnalysisSentinel OneSIEM MonitoringSplunkVulnerability AssessmentWazuhWindows

Explore related jobs

Browse these categories

Market data for this role

All reports →