SOC L2 Analyst

Capgemini

Bengaluru

On-site

INR 1,200,000 - 1,800,000

Full time

7 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Capgemini Bengaluru is seeking an experienced Security Operations Center (SOC) professional to monitor, investigate, and triage security alerts across enterprise, cloud, and hybrid environments. You will analyze diverse telemetry, perform threat hunting, and map activities to MITRE ATT&CK techniques, supporting rapid detection and response.

The role requires hands-on experience with SIEM/XDR platforms (preferably Microsoft Sentinel and Defender XDR), strong incident lifecycle management, and a

Qualifications

  • 4+ years of SOC experience in enterprise, cloud, or hybrid environments.
  • Strong knowledge of Windows, Linux, Active Directory, Entra ID, and enterprise attack methodologies.
  • Hands-on with SIEM and XDR platforms, preferably Microsoft Sentinel and Microsoft Defender XDR, incl. writing and analyzing KQL queries.

Responsibilities

  • Monitor, investigate, and triage security alerts using SIEM/XDR platforms to identify potential security incidents.
  • Analyze endpoint, identity, cloud, email, network telemetry to validate alerts, perform threat hunting, and determine incident impact.
  • Conduct phishing investigations, malware triage, log analysis, and MITRE ATT&CK-based threat mapping to detect and respond to advanced threats.
  • Create detailed incident reports, maintain evidence, document investigation findings, and prepare escalation packages for L3, CSIRT, and IT response teams.
  • Recommend detection tuning, false-positive reduction, playbook improvements, and ensure effective shift handovers for 24x7 SOC operations.

Skills

Security monitoring
Incident analysis
Threat hunting
KQL queries
Microsoft Defender XDR
Microsoft Sentinel
SIEM/XDR platforms
Windows
Linux

Tools

Microsoft Sentinel
Microsoft Defender XDR
KQL
MITRE ATT&CK

Job description

Choosing Capgemini means choosing a company where you will be empowered to shape your career in the way youd like, where youll be supported and inspired bya collaborative community of colleagues around the world, and where youll be able to reimagine whats possible. Join us and help the worlds leading organizations

Your Role
  • Monitor, investigate, and triage security alerts using Microsoft Sentinel, Microsoft Defender XDR, and other SIEM/XDR platforms to identify potential security incidents.
  • Analyze endpoint, identity, cloud, email, network, DNS, and firewall telemetry to validate alerts, perform threat hunting, and determine incident impact and scope.
  • Conduct phishing investigations, malware triage, log analysis, and MITRE ATTCK-based threat mapping to detect and respond to advanced threats.
  • Create detailed incident reports, maintain evidence, document investigation findings, and prepare escalation packages for L3, CSIRT, and IT response teams.
  • Recommend detection tuning, false-positive reduction, playbook improvements, and ensure effective shift handovers to support continuous 24x7 SOC operations.
Your Profile
  • 4+ years of experience in Security Operations Center (SOC) environments with expertise in security monitoring, incident analysis, and response within enterprise, cloud, or hybrid infrastructures.
  • Strong understanding of Windows, Linux, Active Directory, Entra ID, endpoint telemetry, cloud logs, network fundamentals, email security, authentication mechanisms, and enterprise attack methodologies.
  • Hands-on experience with SIEM and XDR platforms, preferably Microsoft Sentinel and Microsoft Defender XDR, including the ability to create, modify, and analyze KQL queries for investigations, threat hunting, and alert validation.
  • Proven ability to analyze endpoint, identity, cloud, email, DNS, firewall/proxy, SaaS, and network telemetry, perform phishing and malware triage, and map observed activities to MITRE ATTCK techniques and adversary behaviors.
  • Experience managing the incident lifecycle, including evidence collection, severity assessment, containment support, escalation to L3/CSIRT teams, preparation of incident reports, tuning recommendations, playbook enhancements, and shift handover documentation.
What you will love working in Capgemini
  • Be a key contributor in 24x7 SOC operations by monitoring, investigating, and responding to security alerts using Microsoft Sentinel, Microsoft Defender XDR, and other security monitoring tools.
  • Analyze endpoint, identity, cloud, email, DNS, firewall, proxy, and network telemetry to identify potential threats, validate alerts, and support incident containment and remediation activities
  • Clear career progression paths from engineering roles to architecture and consulting.
  • Be part of mission-critical projects that ensure security, compliance, and operational efficiency for Fortune 500 clients
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SIEM Engineer L3
SIEM Engineer L3

Capgemini • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Cloud Security Consultant
Cloud Security Consultant

Capgemini • Coimbatore District

On-site
INR 1,500,000 - 2,200,000
Health checks & wellness benefits
Telemedicine
Insurance with top-ups
+3
SOC L3 Expert
SOC L3 Expert

Maandag® Middle East • India

On-site
INR 800,000 - 1,200,000
SOC L1 Analyst
SOC L1 Analyst

Verint Systems • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Flexible working hours
Collaborative environment for personal growth
SOC L3 Analyst
SOC L3 Analyst

Isix • India

On-site
INR 2,500,000 - 4,500,000
Security Analyst - L2
Security Analyst - L2

Nopal Cyber, LLC. • Hyderabad

On-site
INR 1,200,000 - 1,600,000
SOC L1 Analyst
SOC L1 Analyst

Verint • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Security Operations Center Analyst - L2 || Mumbai || Only Immediate Joiner
Security Operations Center Analyst - L2 || Mumbai || Only Immediate Joiner

Innova ESI • Mumbai

On-site
INR 800,000 - 1,200,000
Soc Analyst
Soc Analyst

Genpact • Hyderabad, Bengaluru, Delhi

Hybrid
INR 800,000 - 1,200,000
Cloud Security Consultant
Cloud Security Consultant

Capgemini • Gurugram District

On-site
INR 1,400,000 - 2,200,000
Health checks & telemedicine
Insurance top-ups
New parent support