L2 SOC Analyst

Mizuho

Pune District

On-site

INR 1,500,000 - 2,100,000

Full time

35 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Mizuho Pune is seeking an experienced Cyber Fusion Center Analyst (L2) to protect critical business operations through advanced threat investigation, incident response coordination, and cyber defense operations.

The successful candidate will collaborate with Threat Intelligence, Threat Hunting, DFIR, Infrastructure, Cloud, and Application Security teams to investigate sophisticated attacks, improve detection capabilities, and strengthen enterprise cyber resilience.

Qualifications

  • 4-7 years of experience in Security Operations or related cybersecurity roles.
  • Solid understanding of incident response methodologies and ATT&CK framework.
  • Experience investigating ransomware, phishing, malware, and insider threats.

Responsibilities

  • Protect critical business services by investigating escalated security alerts and incidents.
  • Lead technical analysis of malicious activity and map attacker techniques.
  • Coordinate containment, eradication and recovery during incidents with stakeholders.
  • Mentor L1 analysts and provide guidance to improve investigations.
  • Improve detection, reduce false positives, and contribute to automation initiatives.
  • Collaborate with Threat Intelligence, DFIR, Cloud, and Infrastructure teams.

Skills

Incident response
Threat hunting
Communication
Security operations
Cloud security
PowerShell

Education

Bachelor's degree in Cybersecurity or related field

Tools

Splunk Enterprise Security
Microsoft Sentinel
Palo Alto Cortex XSOAR
CrowdStrike Falcon
Palo Alto Cortex XDR
Microsoft Defender XDR
SentinelOne
VMware Carbon Black

Job description

At Mizuho, we provide the stability of an international industry leader with the career trajectory of a growing business. Our steady, strategic growth gives our people at all levels rewarding degrees of responsibility and richer work experience than a boutique firm or an established giant could offer alone.

It’s the local expertise of our employees that makes our global network so powerful. By collaborating with colleagues and clients who share the same ambition and drive, you can amplify your sphere of influence and base of knowledge as part of one of the largest banks in the world.

Summary:

Mizuho Global Services (MGS) is seeking an experienced Cyber Fusion Center Analyst (L2) to protect critical business operations through advanced threat investigation, incident response coordination, and cyber defense operations. As a technical escalation point within the Cyber Fusion Center, this role is responsible for validating security incidents, reducing cyber risk, supporting containment and recovery efforts, and enhancing the organization's security posture against evolving threats.

The successful candidate will collaborate closely with Threat Intelligence, Threat Hunting, DFIR, Detection Engineering, Infrastructure, Cloud, and Application Security teams to investigate sophisticated attacks, improve detection capabilities, and strengthen enterprise cyber resilience.

Key Responsibilities:

  • Protect critical business services by conducting advanced investigations of escalated security alerts and cyber incidents to determine scope, root cause, business impact, and remediation requirements.
  • Lead technical analysis of malicious activity by correlating data from multiple sources, identifying indicators of compromise, and mapping attacker tactics, techniques, and procedures.
  • Coordinate containment, eradication, and recovery activities during cybersecurity incidents while ensuring effective communication across security and technology stakeholders.
  • Serve as the primary escalation point for L1 analysts by providing technical guidance, investigative support, and mentorship to improve operational effectiveness and analyst capability.
  • Enhance detection and response capabilities by identifying monitoring gaps, reducing false positives, improving investigative workflows, and contributing to automation and operational efficiency initiatives.
  • Collaborate with Threat Intelligence, Threat Hunting, DFIR, Infrastructure, Cloud, and Application Security teams to proactively identify risks, support threat hunting activities, and improve visibility into emerging threats.
  • Develop and maintain investigation procedures, response playbooks, operational runbooks, executive incident summaries, and technical reports that support consistent and repeatable incident response operations.

Required Qualifications:

  • 4-7 years of experience in Security Operations, Cyber Fusion Centers, Incident Response, Cyber Defense, Threat Detection, Digital Forensics, or related cybersecurity functions.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related discipline.
  • Strong understanding of incident response methodologies, MITRE ATT&CK framework, cyber kill chain concepts, threat actor behavior, and adversary TTPs.
  • Experience investigating ransomware, phishing campaigns, malware infections, insider threats, credential compromise, business email compromise, and advanced cyber attacks.
  • Working knowledge of Windows, Linux, Active Directory, Microsoft Entra ID, cloud environments, networking technologies, and enterprise security architectures.
  • Experience conducting threat intelligence-driven investigations, forensic evidence collection, attack-path analysis, and incident scoping.
  • Proficiency in threat hunting, log analysis, security investigations, incident management, and security automation concepts.
  • Experience with SPL, KQL, Python, PowerShell, REST APIs, and automation scripting techniques.
  • Security Technologies: Splunk Enterprise Security, Microsoft Sentinel, Palo Alto Cortex XSOAR, CrowdStrike Falcon, Palo Alto Cortex XDR, Microsoft Defender XDR, SentinelOne, VMware Carbon Black, cloud security platforms, identity security technologies, email security solutions, network security controls, threat intelligence platforms, and security automation/orchestration technologies.
  • Strong analytical, communication, stakeholder management, and problem-solving skills with the ability to manage multiple investigations simultaneously.

Preferred Qualifications:

  • Industry certifications such as GCIH, GCIA, CySA+, SC-200, AZ-500, AWS Security Specialty, Splunk Power User, or equivalent.
  • Experience supporting cybersecurity operations within Financial Services or other highly regulated industries.
  • Exposure to threat hunting, malware analysis, detection engineering, purple team exercises, cyber simulations, or digital forensics programs.
  • Experience supporting cloud-native security operations and security automation initiatives.

Company Overview:

Mizuho Pune is an integral part of Mizuho Financial Group, one of the world’s leading financial institutions with a strong global presence across the Americas, EMEA, and Asia. Based in India, Mizuho Pune supports Mizuho’s international businesses by delivering high-quality, scalable, and resilient services across multiple functions.

Mizuho Pune plays a critical role in driving operational excellence, standardization, and innovation for Mizuho Americas. By combining deep domain expertise with strong process, technology, and analytical capabilities, it partners closely with regional and global teams to support corporate and investment banking, capital markets, and corporate services functions, while adhering to the highest standards of risk management, regulatory compliance, and control.

Mizuho Pune offers competitive compensation and benefits package aligned with industry standards and local market practices.

Mizuho Pune is an equal opportunity employer and is committed to fostering an inclusive and diverse workplace.

Employment is subject to applicable background verification checks in accordance with Indian laws and company policies.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Fusion Center Shift Lead
Cyber Fusion Center Shift Lead

Mizuho • Pune District

Hybrid
INR 2,000,000 - 3,500,000
Cyber Fusion Center Threat Intelligence Lead
Cyber Fusion Center Threat Intelligence Lead

Mizuho • Pune District

On-site
INR 2,500,000 - 4,500,000
Core Banking & Payments Platform Engineer (Automation & Production Support)
Core Banking & Payments Platform Engineer (Automation & Production Support)

Mizuho • Pune District

On-site
INR 1,800,000 - 3,000,000
Director -IT Data Architecture – Production Support
Director -IT Data Architecture – Production Support

Mizuho • Pune District

On-site
INR 3,200,000 - 5,200,000
Competitive compensation and benefits
Equal opportunity employer
Data Analytics (L2 Support Engineer)
Data Analytics (L2 Support Engineer)

Mizuho • Pune District

On-site
INR 1,200,000 - 2,200,000
L2 production support, Snowflake, Databricks, Python
L2 production support, Snowflake, Databricks, Python

Mizuho • Pune District

On-site
INR 900,000 - 1,500,000
Market Risk Production Support Lead
Market Risk Production Support Lead

Mizuho Global Services • Pune District

On-site
INR 3,500,000 - 5,200,000
Front Office-Banking Technology Application Support L1_L2
Front Office-Banking Technology Application Support L1_L2

Mizuho • Pune District

On-site
INR 800,000 - 1,000,000
Associate - ITDA Data Integration L2 Production Support
Associate - ITDA Data Integration L2 Production Support

Mizuho • Pune District

Hybrid
INR 1,500,000 - 2,100,000
Hybrid work model
Data Analytics Support lead – Power BI L2 production support in Investment Banking
Data Analytics Support lead – Power BI L2 production support in Investment Banking

Mizuho • Pune District

On-site
INR 4,000,000 - 7,000,000