About the role
Job Purpose
The SOC L2 Analyst performs advanced investigation and response activities, conducts threat analysis, and supports containment and remediation of cybersecurity incidents. Protect multitenant GPU cloud with defenseindepth, ensuring zero****trust, auditability, and regulatory alignment.
Role Description
Key Responsibilities
- Investigate escalated incidents from L1 analysts.
- Conduct detailed log analysis and threat hunting activities.
- Perform malware analysis and forensic investigations.
- Execute containment, eradication, and recovery procedures.
- Correlate events across multiple security platforms.
- Develop detection use cases and SIEM/SOAR correlation rules.
- Investigate Kubernetes, container runtime, and cloud-native security incidents.
- Fine-tune security controls to reduce false positives.
- Lead incident response activities and root cause analysis.
- Collaborate with infrastructure, cloud, and application teams during investigations.
- Assist Vulnerability Management teams in validating exploitable vulnerabilities and prioritizing remediation.
- Provide mentoring and guidance to L1 analysts.
- Implementation
- Enforce IAM/RBAC, least privilege, and network micro****segmentation; secrets/KMS integration.
- Define secure baselines for OS, containers, CUDA drivers, and platform services; supplychain controls (image signing/SBOM).
- Implement and maintain cloud network security controls such as security groups, firewalls, WAF, DDoS, micro-segmentation, EDR, DLP, PIM/PAM and secure connectivity etc
- Operations
- Continuous vulnerability management, patch cadence, threat detection (EDR/XDR), and audit log integrity, PAM, DDOS, Firewalls & WAF
- Periodic access reviews, key rotation, and compliance evidence packs.
- Reliability & Incident
- Incident response (containment/forensics/eradication); purpleteam exercises; tabletop drills.
- Data Protection
- Encryption intransit/atrest, tenant isolation boundaries, data retention, legal holds, and purge workflows.
Experience & Educational Requirements
Qualifications and Experience
EDUCATIONAL QUALIFICATIONS: (degree, training, or certification required)
BE/B-Tech or equivalent with Computer Science or Electronics & Communication
RELEVANT EXPERIENCE: (no. of years of technical, functional, and/or leadership experience or specific exposure required)
- 47 years cybersecurity; strong cloud security, zerotrust, and data privacy in regulated environments.
- Strong expertise in SIEM technologies (Microsoft Sentinel, Splunk, QRadar).
- Hands-on experience with Microsoft Defender XDR, CrowdStrike, Sentinel One, or similar EDR tools.
- Knowledge of Azure, AWS, and GCP security monitoring.
- Experience in incident response and digital forensics.
- Understanding of attack techniques, malware behaviour, and threat actor tactics.
- Ability to analyze packet captures and network traffic.
- Knowledge of SOAR platforms and automation workflows.
- Experience with KQL, Python Scripts, or equivalent query languages.
- Participate in shift-based 24x7 SOC operations
Tools / Tech
SIEM (Splunk/ELK), EDR/XDR, image scanners (Trivy/Clair), OPA/Gatekeeper, Vault/KMS/HSM, HashiCorp Boundary (or equivalent), Firewalls, WAF, DDOS, ISO AUDITS, VAM, PAM.
Certifications
CISSP; CISM/CISA; CCSP; ISO 27001 Lead Implementer/Auditor, SC-200, SC-300, AZ-500, GCIH, GCIA, CEH, CompTIA CySA+
KPIs
Mean time to detect/respond, vulnerability backlog burndown, audit nonconformities, policy violation rate, False Positive Reduction Rate, Automation Coverage (SOAR Playbooks).
Millions of jobs, with real people getting hired every day
Questions, answered
Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.
Yes. This role at Larsen & Toubro (L&T) was screened before publishing – we confirmed the employer before listing it.
The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.
This position can be done from anywhere, with no in-office requirement.
Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.
