Security Analyst - L2

Nopal Cyber, LLC.

Hyderabad

On-site

INR 1,200,000 - 1,600,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Nopal Cyber, LLC. is seeking a SOC L2 Analyst to carry out in-depth security investigations and incident analysis. This role involves working with multiple security tools to assess impacts from security incidents and recommend effective containment actions.

The ideal candidate has 3-6 years of experience in cybersecurity operations, holds a Bachelor's degree in a related field, and possesses strong practical skills across SIEM and EDR/XDR tools. A proactive approach to investigation and effective communication skills are essential for this position.

Qualifications

  • 3 to 6 years of experience in SOC / Cyber Security Operations / Incident Response.
  • Strong hands-on experience with SIEM platforms.
  • Experience with EDR/XDR tools.

Responsibilities

  • Perform deep-dive investigations on alerts from various security tools.
  • Correlate logs and telemetry to identify root causes.
  • Analyze data movement patterns across endpoints, email, and cloud storage.

Skills

Cybersecurity operations
Incident response
SIEM platforms
EDR/XDR tools
Cloud security monitoring
DLP investigations
Phishing analysis

Education

Bachelor’s degree in Cybersecurity or related field

Tools

Sentinel
Splunk
CrowdStrike
Azure
Netskope

Job description

Role Overview

The SOC L2 Analyst is responsible for in-depth security investigation, incident analysis, and response coordination across enterprise environments. This role focuses on correlating multi-domain telemetry (SIEM, EDR/XDR, Cloud, DLP, DAM, EmailSecurity) to determine root cause, assess impact, and recommend containment actions. The analyst acts as a technical escalation point for L1 and contributes to improving detection use cases and SOC maturity.

Key Responsibilities
  • Perform deep-dive investigations on alerts from across SIEM, EDR/XDR, Cloud, DLP, DAM, and Email Security tools
  • Correlate logs and telemetry to reconstruct attack timelines and identify root cause
  • Investigate advanced threats such as lateral movement, privilege escalation, account compromise, and malware activity
  • Conduct endpoint analysis (process injection, persistence mechanisms, suspicious binaries, command-line artifacts)
  • Analyze cloud security incidents (Azure/AWS) including IAM misuse, impossible travel, token abuse, and misconfigurations
  • Perform advanced phishing and BEC investigations, including header analysis, URL detonation, and payload inspection
  • Investigate DLP (Netskope) alerts for potential data exfiltration, policy violations, and insider threats
  • Analyze data movement patterns across endpoints, email, and cloud storage
  • Tune and validate DLP policies to reduce false positives and improve detection accuracy
  • Investigate DAM alerts for unauthorized database access, privilege misuse, abnormal query patterns, and potential SQL injection attempts
  • Correlate database activity with user identity and endpoint behavior to detect malicious intent
  • Lead incident investigation and provide containment/remediation recommendations
  • Create and enrich IOCs (IP, domain, hash) and perform threat intelligence lookups
  • Ensure timely escalation to L3/IR teams for critical incidents (P1/P2)
  • Improve and tune SIEM use cases and detection rules to reduce false positives
  • Maintain detailed incident documentation, timelines, and reporting
  • Support threat hunting activities using SIEM and EDR tools
Required Qualifications
  • 3 to 6 years of experience in SOC / Cyber Security Operations / Incident Response
  • Bachelor’s degree in Cybersecurity, Computer Science, IT, or related field
  • Strong hands‑on experience with SIEM platforms (Sentinel, Splunk, QRadar, ArcSight)
  • Experience with EDR/XDR tools (Microsoft Defender, CrowdStrike, SentinelOne)
  • Practical knowledge of cloud security monitoring (Azure, AWS, GCP)
  • Experience in Netskope DLP and Database Activity Monitoring alert investigations
  • Understanding of email security solutions and phishing/BEC analysis
  • Relevant certifications: CySA+, CCSP, CEH, GCIA, GCIH, SC-200, Splunk Certified
  • Strong knowledge of MITRE ATT&CK framework and attack lifecycle mapping
  • Ability to correlate events across endpoint, network, cloud, and database layers
  • Solid understanding of network protocols, authentication mechanisms, and log analysis
  • Experience in incident handling, root cause analysis, and attack chain reconstruction
  • Strong analytical and problem‑solving skills with attention to detail
  • Ability to work independently and mentor L1 analysts
  • Effective communication skills for technical and non‑technical stakeholders
  • Ability to work in a 24x7 rotational shift environment
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Analyst L2
SOC Analyst L2

Keka Technologies Private Limited • Gurugram District

On-site
INR 1,200,000 - 2,500,000
Security Operations Center Analyst- L2
Security Operations Center Analyst- L2

Incedo Inc. • Gurugram District

On-site
INR 900,000 - 1,500,000
SOC L3 Expert
SOC L3 Expert

Maandag® Middle East • India

On-site
INR 800,000 - 1,200,000
L2 SOC Analyst
L2 SOC Analyst

UST • Thiruvananthapuram

Hybrid
INR 600,000 - 900,000
SOC L1 Analyst
SOC L1 Analyst

Verint • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Senior SOC L3 Analyst
Senior SOC L3 Analyst

Opt IT • India

On-site
INR 1,800,000 - 3,600,000
Soc Analyst
Soc Analyst

Incedo • Gurugram District

On-site
INR 1,800,000 - 2,400,000
24x7 Rotational Shift
Willingness to work on weekends/holid-
Sr SOC Analyst - CyberAxis
Sr SOC Analyst - CyberAxis

Cyberaxislabs • Hyderabad

On-site
INR 1,200,000 - 1,800,000
L3 SOC Analyst
L3 SOC Analyst

UST • Bengaluru

On-site
INR 1,500,000 - 2,100,000
SOC Analyst L2
SOC Analyst L2

Perydot • Bengaluru

On-site
INR 800,000 - 1,400,000