SOC Engineer L2

Larsen & Toubro

Chennai District

On-site

INR 900,000 - 1,300,000

Full time

11 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Larsen & Toubro is seeking a SOC L2 Analyst to perform advanced investigations, threat analysis, and containment/remediation for cybersecurity incidents within a multi-tenant GPU cloud. Focus areas include zero-trust, auditability, and regulatory alignment.

The role involves threat hunting, log analysis, malware forensics, and development of detection use cases along with SIEM/SOAR rules. Collaboration with infra, cloud, and app teams is essential.

Qualifications

  • 4–7 years cybersecurity experience with strong cloud security and data privacy in regulated environments.
  • Hands-on experience with SIEM technologies (Microsoft Sentinel, Splunk, QRadar).
  • Experience with Microsoft Defender XDR, CrowdStrike, SentinelOne or similar EDR tools.
  • Knowledge of Azure, AWS, and GCP security monitoring.
  • Incident response and digital forensics experience.
  • Understanding of attack techniques, malware behaviour, and threat actor tactics.
  • Ability to analyze packet captures and network traffic.
  • Knowledge of SOAR platforms and automation workflows.
  • Experience with KQL and Python scripting.

Responsibilities

  • Investigate escalated incidents from L1 analysts.
  • Conduct detailed log analysis and threat hunting activities.
  • Perform malware analysis and forensic investigations.
  • Execute containment, eradication, and recovery procedures.
  • Correlate events across multiple security platforms.
  • Develop detection use cases and SIEM/SOAR correlation rules.
  • Investigate Kubernetes, container runtime, and cloud-native security incidents.
  • Fine-tune security controls to reduce false positives.
  • Lead incident response activities and root cause analysis.
  • Collaborate with infrastructure, cloud, and application teams during investigations.
  • Assist Vulnerability Management teams in validating exploitable vulnerabilities and prioritizing remediation.
  • Provide mentoring and guidance to L1 analysts.

Skills

Threat analysis
Incident response
Log analysis
Zero-trust
Cloud security
SIEM
EDR/XDR
KQL
Python
Threat hunting

Education

Bachelor's degree in Cybersecurity / Computer Science
CISSP / CISM / CCSP (certifications)

Tools

Splunk
ELK Stack
Microsoft Defender XDR
CrowdStrike
SentinelOne
Azure
AWS
GCP

Job description

Job Description:
Job Purpose

The SOC L2 Analyst performs advanced investigation and response activities, conducts threat analysis, and supports containment and remediation of cybersecurity incidents. Protect multi?tenant GPU cloud with defense?in?depth, ensuring zero?trust, auditability, and regulatory alignment.

Role Description
Key Responsibilities
  • Investigate escalated incidents from L1 analysts.
  • Conduct detailed log analysis and threat hunting activities.
  • Perform malware analysis and forensic investigations.
  • Execute containment, eradication, and recovery procedures.
  • Correlate events across multiple security platforms.
  • Develop detection use cases and SIEM/SOAR correlation rules.
  • Investigate Kubernetes, container runtime, and cloud-native security incidents.
  • Fine-tune security controls to reduce false positives.
  • Lead incident response activities and root cause analysis.
  • Collaborate with infrastructure, cloud, and application teams during investigations.
  • Assist Vulnerability Management teams in validating exploitable vulnerabilities and prioritizing remediation.
  • Provide mentoring and guidance to L1 analysts.
  • Implementation
    • Enforce IAM/RBAC, least privilege, and network micro?segmentation; secrets/KMS integration.
    • Define secure baselines for OS, containers, CUDA drivers, and platform services; supply ? chain controls (image signing/SBOM).
    • Implement and maintain cloud network security controls such as security groups, firewalls, WAF, DDoS, micro-segmentation, EDR, DLP, PIM/PAM and secure connectivity etc
  • Operations
    • Continuous vulnerability management, patch cadence, threat detection (EDR/XDR), and audit log integrity, PAM, DDOS, Firewalls & WAF
    • Periodic access reviews, key rotation, and compliance evidence packs.
  • Reliability & Incident
    • Incident response (containment/forensics/eradication); purple?team exercises; tabletop drills.
  • Data Protection
    • Encryption in?transit/at?rest , tenant isolation boundaries, data retention, legal holds, and purge workflows.
Experience & Educational Requirements
Qualifications and Experience
EDUCATIONAL QUALIFICATIONS:

(degree, training, or certification required)

RELEVANT EXPERIENCE:
  • 4–7 years cybersecurity; strong cloud security, zero?trust, and data privacy in regulated environments.
  • Strong expertise in SIEM technologies (Microsoft Sentinel, Splunk, QRadar).
  • Hands-on experience with Microsoft Defender XDR, CrowdStrike, Sentinel One, or similar EDR tools.
  • Knowledge of Azure, AWS, and GCP security monitoring.
  • Experience in incident response and digital forensics.
  • Understanding of attack techniques, malware behaviour, and threat actor tactics.
  • Ability to analyze packet captures and network traffic.
  • Knowledge of SOAR platforms and automation workflows.
  • Experience with KQL, Python Scripts, or equivalent query languages.
  • Participate in shift-based 24x7 SOC operations
Tools / Tech

SIEM (Splunk/ELK), EDR/XDR, image scanners (Trivy/Clair), OPA/Gatekeeper, Vault/KMS/HSM, HashiCorp Boundary (or equivalent), Firewalls, WAF, DDOS, ISO AUDITS, VAM, PAM.

Certifications

CISSP; CISM/CISA; CCSP; ISO 27001 Lead Implementer/Auditor, SC-200, SC-300, AZ-500, GCIH, GCIA, CEH, CompTIA CySA+

KPIs

Mean time to detect/respond, vulnerability backlog burn?down, audit non?conformities, policy violation rate, False Positive Reduction Rate, Automation Coverage (SOAR Playbooks).

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Engineer (L2)
SOC Engineer (L2)

PeopleStrong • Chennai District

On-site
INR 900,000 - 1,400,000
Sr. SOC Engineer (L3)
Sr. SOC Engineer (L3)

PeopleStrong • Chennai District

On-site
INR 1,800,000 - 2,600,000
Sr. SOC Engineer (L3)
Sr. SOC Engineer (L3)

Larsen & Toubro • Chennai District

On-site
INR 2,500,000 - 4,000,000
Security Analyst - L2
Security Analyst - L2

Nopal Cyber, LLC. • Hyderabad

On-site
INR 1,200,000 - 1,600,000
SOC L1 Analyst
SOC L1 Analyst

Verint • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Lead SOC Analyst
Lead SOC Analyst

Sampoorna Consultants • Bengaluru

On-site
INR 1,000,000 - 1,500,000
SOC L3 Expert
SOC L3 Expert

Maandag® Middle East • India

On-site
INR 800,000 - 1,200,000
SOC L1 Analyst
SOC L1 Analyst

Verint Systems • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Flexible working hours
Collaborative environment for personal growth
SOC Principal
SOC Principal

HCLSoftware • Bengaluru

On-site
INR 4,500,000 - 7,500,000
SOC Analyst ( Security Analyst – L2)
SOC Analyst ( Security Analyst – L2)

Soffit Infrastructure Services (P) Ltd • Ernakulam

On-site
INR 700,000 - 1,000,000