CybergateActive opening

Soc Analyst - L2

Abu Dhabi officeOn-siteIndividual contributorFound 2 days ago
Apply to this job

Free credits included. Sign up to start applying with Jobfinder.

splunkibm qradarsiemincident responsethreat huntingforensicsplaybook developmentmentoring

Job Description: SOC L2 Analyst

Location: [Abu Dhabi - UAE]

Experience: 4 to 6 Years

Department: Cyber Security / Security Operations Center (SOC)

Reporting to: SOC Manager / Team Lead

Role Overview

The SOC L2 Analyst is responsible for advanced security monitoring, deep-dive incident investigation, and complex threat analysis. Acting as the critical escalation point for Level 1 Analysts, you will lead the response to sophisticated threats and ensure the continuous improvement of our detection capabilities. You will play a hands-on role in incident containment, eradication, and recovery, while proactively hunting for emerging threats within our environment.

Key Responsibilities

1. Advanced Investigation & Incident Response

  • Deep-Dive Analysis: Perform advanced threat analysis and investigate complex security incidents escalated from Tier 1.
  • Incident Leadership: Lead incident response activities, including the containment of active threats, eradication of malicious actors, and recovery of systems.
  • Root Cause Analysis (RCA): Conduct comprehensive RCAs to identify how breaches occurred and recommend preventative controls.
  • Threat Hunting: Proactively hunt for threats using IOCs (Indicators of Compromise) and TTPs (Tactics, Techniques, and Procedures) to uncover hidden malicious activity.

2. SIEM & Detection Engineering

  • Tool Mastery: Analyze logs and correlate security events using complex queries within Splunk and IBM QRadar.
  • Rule Optimization: Develop and optimize SIEM use cases, correlation rules, and alerts to reduce false positives and improve detection accuracy.
  • Playbook Development: Create and refine incident response playbooks and automated detection logic to standardize response efforts.

3. Intelligence & Mentorship

  • Threat Intel Integration: Monitor and integrate threat intelligence feeds into the SIEM to ensure the environment is protected against the latest known threats.
  • Mentorship: Serve as a technical mentor for L1 analysts, providing guidance on investigation techniques and professional development.

Required Technical Skills

  • SIEM Platforms: High proficiency in Splunk (Search Processing Language - SPL, dashboards, alerting) and IBM QRadar (Offense management, rules engine, AQL queries).
  • Frameworks: Strong operational knowledge of the MITRE ATT&CK framework and the full Incident Response lifecycle.
  • Security Tooling: Experience with EDR/XDR solutions, Firewall logs, and IDS/IPS systems.
  • Threat Analysis: Expert knowledge of IOC analysis, malware behavior, and threat intelligence platforms.
  • Scripting: Basic automation skills using Python, PowerShell, or Bash to streamline repetitive tasks.

Required Experience & Qualifications

  • Experience: 4–6 years of dedicated experience in a SOC environment or Cyber Security operations.
  • Education: Bachelor’s degree in Computer Science, Cyber Security, or a related technical field.

Preferred Certifications:

  • Core: CompTIA CySA+ or Certified Ethical Hacker (CEH).
  • Platform Specific: Splunk Certified User/Admin or IBM QRadar Certification.
  • Advanced: GCIH, GCIA, or similar technical IR certifications.

Preferred Behavioral Competencies

  • Strong analytical thinking and problem-solving skills under pressure.
  • Excellent communication skills for documenting technical findings in clear business terms.
  • A proactive "hunter" mindset focused on continuous security improvement.
CybergateSoc Analyst - L2
Apply to this job