Get more replies from employers
Send a job-specific resume in minutes.
Ssquad Global is seeking an experienced L2 SOC Analyst for its Security Operations Centre in Malaysia. The role focuses on advanced security monitoring, incident investigation, threat hunting, SIEM operations, and detection rule tuning.
You will escalate security incidents and contribute to improving detection capabilities. Responsibilities include monitoring alerts, correlating logs from diverse sources, conducting root-cause analysis, and preparing incident reports.
Ssquad Global is looking for an experienced L2 SOC Analyst to join our Security Operations Centre. The role involves advanced security monitoring, incident investigation, threat hunting, SIEM operations, detection rule tuning, and escalation of security incidents.
Monitor and investigate security alerts using SIEM and integrated security tools.
Analyse and correlate logs from firewalls, endpoints, servers, networks, applications, authentication, email, and cloud environments.
Investigate L1 escalations and determine incident severity, impact, and scope.
Perform incident investigation, root cause analysis, containment, and escalation.
Develop, review, test, and tune SIEM correlation rules and detection use cases.
Identify and reduce false positives and improve detection capabilities.
Support SIEM log-source onboarding, parsing, normalization, and troubleshooting.
Conduct proactive threat hunting using IoCs, IoAs, threat intelligence, and MITRE ATT&CK.
Provide technical guidance and knowledge transfer to L1 SOC Analysts.
Prepare incident reports and SOC operational reports.
3-5 years of experience in SOC, security monitoring, incident response, or cybersecurity.
Hands-on experience as an L2 SOC Analyst or equivalent.
Strong experience with SIEM platforms and security event correlation.
Experience in SIEM rule creation, use-case development, tuning, and log-source onboarding.
Strong knowledge of TCP/IP, DNS, HTTP/HTTPS, VPN, firewalls, IDS/IPS, endpoint, and network security.
Experience in incident investigation and root cause analysis.
Knowledge of MITRE ATT&CK, Cyber Kill Chain, IoCs, IoAs, and TTPs.
Experience in threat hunting and threat intelligence.
Ability to work in an SLA-driven / 24×7 SOC environment.
Bachelor's Degree in Cybersecurity, Computer Science, IT, or a related field.
Ssquad Global is an IT Services & Cybersecurity company.