Get more replies from employers
Send a job-specific resume in minutes.
Insyghts Security Sdn Bhd is seeking a skilled L2 SOC Analyst/Engineer to act as the escalation point for the L1 SOC team and lead advanced investigations across endpoints, networks, cloud, and identity telemetry.
The role focuses on root-cause analysis, threat hunting, and driving detection engineering to mature the security monitoring program, including incident containment and post-incident lessons learned.
We are looking for a L2 SOC Analyst/Engineer to serve as the escalation point for our L1 SOC team. This role owns in-depth investigation of escalated alerts, performs root cause analysis, leads incident response activities, and drives detection engineering and threat hunting initiatives to continuously mature our security monitoring program. You will be a technical anchor for the SOC - turning raw alerts into confirmed incidents, confirmed incidents into lessons learned, and lessons learned into better detections.
Key responsibilities
Serve as the primary technical escalation point for L1 analysts on alerts requiring deeper analysis
Conduct in-depth investigations across endpoint, network, cloud, identity, and application telemetry
Correlate data across multiple tools/log sources (SIEM, EDR, NDR, cloud logs, identity providers) to determine scope and impact
Distinguish true positives from false positives and refine triage logic accordingly
Perform root cause analysis on confirmed incidents to determine initial vector, method, and any control gaps
Document attack timelines/kill chains and produce clear technical findings for stakeholders
Lead or co-lead containment, eradication, and recovery activities for security incidents
Design, build, test, and tune detection rules/use cases (SIEM correlation rules, EDR detections, Sigma rules, etc.)
Conduct proactive, hypothesis-driven threat hunts using threat intelligence, ATT&CK TTPs, and anomaly analysis
Mentor and provide technical guidance to L1 analysts, including escalation reviews and knowledge transfer
About you
3+ years of hands-on SOC experience, with demonstrated progression into L2/senior analyst responsibilities
Strong understanding of the attack lifecycle, common TTPs, and the MITRE ATT&CK framework
Hands-on experience with SIEM platforms (e.g., Splunk, Sentinel, QRadar, Elastic) - writing/tuning correlation rules and queries
Experience with EDR/XDR tools (e.g., CrowdStrike, Microsoft Defender, SentinelOne, TrendAI) for endpoint investigation
Solid grasp of networking fundamentals (TCP/IP, DNS, HTTP/S, proxies) and ability to read packet captures
Experience with incident response processes: containment, eradication, recovery, and post-incident reporting
Familiarity with cloud security monitoring (AWS/Azure/GCP logs, IAM, CloudTrail or equivalent)
Scripting/automation skills (Python, PowerShell, or similar) for detection logic, parsing, or workflow automation
Excellent written and verbal communication skills - able to translate technical findings for non-technical stakeholders
Ability to remain calm and methodical under pressure during active incidents
*Opportunity to be transferred to Singapore office for suitable candidates.
Researching careers? Find all the information and tips you need on career advice.