Job Description: SOC L2 Analyst
Location: [Abu Dhabi - UAE]
Experience: 4 to 6 Years
Department: Cyber Security / Security Operations Center (SOC)
Reporting to: SOC Manager / Team Lead
Role Overview
The SOC L2 Analyst is responsible for advanced security monitoring, deep-dive incident investigation, and complex threat analysis. Acting as the critical escalation point for Level 1 Analysts, you will lead the response to sophisticated threats and ensure the continuous improvement of our detection capabilities. You will play a hands-on role in incident containment, eradication, and recovery, while proactively hunting for emerging threats within our environment.
Key Responsibilities
1. Advanced Investigation & Incident Response
- Deep-Dive Analysis: Perform advanced threat analysis and investigate complex security incidents escalated from Tier 1.
- Incident Leadership: Lead incident response activities, including the containment of active threats, eradication of malicious actors, and recovery of systems.
- Root Cause Analysis (RCA): Conduct comprehensive RCAs to identify how breaches occurred and recommend preventative controls.
- Threat Hunting: Proactively hunt for threats using IOCs (Indicators of Compromise) and TTPs (Tactics, Techniques, and Procedures) to uncover hidden malicious activity.
2. SIEM & Detection Engineering
- Tool Mastery: Analyze logs and correlate security events using complex queries within Splunk and IBM QRadar.
- Rule Optimization: Develop and optimize SIEM use cases, correlation rules, and alerts to reduce false positives and improve detection accuracy.
- Playbook Development: Create and refine incident response playbooks and automated detection logic to standardize response efforts.
3. Intelligence & Mentorship
- Threat Intel Integration: Monitor and integrate threat intelligence feeds into the SIEM to ensure the environment is protected against the latest known threats.
- Mentorship: Serve as a technical mentor for L1 analysts, providing guidance on investigation techniques and professional development.
Required Technical Skills
- SIEM Platforms: High proficiency in Splunk (Search Processing Language - SPL, dashboards, alerting) and IBM QRadar (Offense management, rules engine, AQL queries).
- Frameworks: Strong operational knowledge of the MITRE ATT&CK framework and the full Incident Response lifecycle.
- Security Tooling: Experience with EDR/XDR solutions, Firewall logs, and IDS/IPS systems.
- Threat Analysis: Expert knowledge of IOC analysis, malware behavior, and threat intelligence platforms.
- Scripting: Basic automation skills using Python, PowerShell, or Bash to streamline repetitive tasks.
Required Experience & Qualifications
- Experience: 4–6 years of dedicated experience in a SOC environment or Cyber Security operations.
- Education: Bachelor’s degree in Computer Science, Cyber Security, or a related technical field.
Preferred Certifications:
- Core: CompTIA CySA+ or Certified Ethical Hacker (CEH).
- Platform Specific: Splunk Certified User/Admin or IBM QRadar Certification.
- Advanced: GCIH, GCIA, or similar technical IR certifications.
Preferred Behavioral Competencies
- Strong analytical thinking and problem-solving skills under pressure.
- Excellent communication skills for documenting technical findings in clear business terms.
- A proactive "hunter" mindset focused on continuous security improvement.