Soc Analyst - L2

Keka Technologies Private Limited

Abu Dhabi

On-site

AED 200,000 - 320,000

Full time

6 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Keka Technologies Private Limited is seeking a SOC L2 Analyst in Abu Dhabi to lead complex security investigations, drive incident containment and recovery, and uplift detection capabilities. You will act as the escalation point for Tier 1 analysts and mentor junior staff.

You will work with Splunk and IBM QRadar, develop playbooks, and integrate threat intel to protect the environment against evolving threats. A strong MITRE ATT&CK background and scripting skills are essential.

Qualifications

  • 4–6 years of dedicated SOC/cyber security operations experience.
  • Bachelor's degree in Computer Science, Cyber Security or related field.
  • Proficiency with Splunk SPL, dashboards, alerts and IBM QRadar offenses/rules.
  • Strong knowledge of the MITRE ATT&CK framework and the incident response lifecycle.
  • Experience with threat intelligence integration and automation scripting.

Responsibilities

  • Perform advanced threat analysis and investigate complex security incidents escalated from Tier 1.
  • Lead incident response activities including containment of active threats, eradication of malicious actors, and recovery of systems.
  • Conduct comprehensive root cause analyses to identify breach vectors and recommend preventive controls.
  • Proactively hunt for threats using IOCs and TTPs to uncover hidden activity.
  • Develop and optimize SIEM use cases, correlation rules, and alerts to reduce false positives.
  • Create and refine incident response playbooks and automated detection logic.
  • Mentor L1 analysts on investigation techniques and professional development.

Skills

Threat analysis
Incident response
Incident leadership
Mentorship
Scripting (Python/PowerShell/Bash)

Education

Bachelor’s degree in Computer Science, Cyber Security, or related field

Tools

Splunk
IBM QRadar
EDR/XDR
IDS/IPS

Job description

Department: Cyber Security / Security Operations Center (SOC)

Reporting to: SOC Manager / Team Lead

Role Overview

The SOC L2 Analyst is responsible for advanced security monitoring, deep-dive incident investigation, and complex threat analysis. Acting as the critical escalation point for Level 1 Analysts, you will lead the response to sophisticated threats and ensure the continuous improvement of our detection capabilities. You will play a hands-on role in incident containment, eradication, and recovery, while proactively hunting for emerging threats within our environment.

Key Responsibilities
1. Advanced Investigation & Incident Response
  • Deep-Dive Analysis: Perform advanced threat analysis and investigate complex security incidents escalated from Tier 1.
  • Incident Leadership: Lead incident response activities, including the containment of active threats, eradication of malicious actors, and recovery of systems.
  • Root Cause Analysis (RCA): Conduct comprehensive RCAs to identify how breaches occurred and recommend preventative controls.
  • Threat Hunting: Proactively hunt for threats using IOCs (Indicators of Compromise) and TTPs (Tactics, Techniques, and Procedures) to uncover hidden malicious activity.
2. SIEM & Detection Engineering
  • Tool Mastery: Analyze logs and correlate security events using complex queries within Splunk and IBM QRadar.
  • Rule Optimization: Develop and optimize SIEM use cases, correlation rules, and alerts to reduce false positives and improve detection accuracy.
  • Playbook Development: Create and refine incident response playbooks and automated detection logic to standardize response efforts.
  • Threat Intel Integration: Monitor and integrate threat intelligence feeds into the SIEM to ensure the environment is protected against the latest known threats.
  • Mentorship: Serve as a technical mentor for L1 analysts, providing guidance on investigation techniques and professional development.
Required Technical Skills
  • SIEM Platforms: High proficiency in Splunk (Search Processing Language - SPL, dashboards, alerting) and IBM QRadar (Offense management, rules engine, AQL queries).
  • Frameworks: Strong operational knowledge of the MITRE ATT&CK framework and the full Incident Response lifecycle.
  • Security Tooling: Experience with EDR/XDR solutions, Firewall logs, and IDS/IPS systems.
  • Threat Analysis: Expert knowledge of IOC analysis, malware behavior, and threat intelligence platforms.
  • Scripting: Basic automation skills using Python, PowerShell, or Bash to streamline repetitive tasks.
Required Experience & Qualifications
  • Experience: 4–6 years of dedicated experience in a SOC environment or Cyber Security operations.
  • Education: Bachelor’s degree in Computer Science, Cyber Security, or a related technical field.
Preferred Certifications:
  • Core: CompTIA CySA+ or Certified Ethical Hacker (CEH).
  • Platform Specific: Splunk Certified User/Admin or IBM QRadar Certification.
  • Advanced: GCIH, GCIA, or similar technical IR certifications.
  • Strong analytical thinking and problem-solving skills under pressure.
  • Excellent communication skills for documenting technical findings in clear business terms.
  • A proactive "hunter" mindset focused on continuous security improvement.

Required Skills

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Specialist- L3
SOC Specialist- L3

Keka Technologies Private Limited • Abu Dhabi

On-site
AED 446,000 - 781,000
SOC Manager
SOC Manager

Noventiq Seven Seas Technology • Dubai Emirate

On-site
AED 500,000 - 700,000
SOC Manager
SOC Manager

Noventiq Seven Seas Technology • Dubai

On-site
AED 380,000 - 660,000
Services Delivery Manager
Services Delivery Manager

Noventiq Seven Seas Technology • Dubai

On-site
AED 280,000 - 520,000
SOC Team Lead (Tier 1)
SOC Team Lead (Tier 1)

Recenso • Abu Dhabi

On-site
AED 200,000 - 250,000
Professional development opportunities
Leadership roles
Collaborative environment
Cyber Security Analyst (UAE National)
Cyber Security Analyst (UAE National)

Inspira Enterprise • Dubai

On-site
AED 67,000 - 112,000
Senior IT Security Operations Engineer
Senior IT Security Operations Engineer

VaporVM • Dubai

On-site
AED 250,000 - 390,000
Lead SOC Engineer (SIEM) (CPX)
Lead SOC Engineer (SIEM) (CPX)

CPX • Abu Dhabi

On-site
AED 300,000 - 420,000
SIEM Security Analyst SOC L3 Analyst
SIEM Security Analyst SOC L3 Analyst

Epergne Solutions • Dubai

On-site
AED 180,000 - 300,000
SOC L1 Analyst – SIEM Integration (Emirati National Only)
SOC L1 Analyst – SIEM Integration (Emirati National Only)

Talents of Endearment • Dubai

On-site
AED 100,000 - 167,000
Career growth potential
Emirati talent development program
Hands-on SIEM exposure