L2 SOC Analyst
- Location : Cyberjaya
- Salary : Max RM8000
- Employment Type: Full-time Employment
- Open for : Local/PR
Job Summary
We are seeking an experienced L2 SOC Analyst to handle advanced security alert investigation, incident response, threat hunting, and technical escalation. The role will also provide guidance to junior analysts and support continuous improvement of SOC detection and response capabilities.
Key Responsibilities
- Perform L2 investigation and triage of security alerts/incidents.
- Analyze alerts from SIEM, EDR/XDR, identity, network, email, and cloud sources.
- Correlate logs and establish the incident timeline.
- Validate IOCs and assess threat severity and impact.
- Escalate confirmed/high-severity incidents within defined SLA.
- Support threat hunting and detection/use-case tuning.
- Perform RCA for significant incidents and recommend corrective actions.
- Maintain accurate investigation notes and incident documentation.
- Support L1 analysts with technical guidance and troubleshooting.
Requirements
- 3–5 years of SOC/Cybersecurity experience.
- Hands-on experience with Microsoft Sentinel and Defender XDR/EDR or equivalent.
- Good knowledge of KQL and security log analysis.
- Strong understanding of incident investigation, phishing, malware, identity, endpoint, and network security.
- Knowledge of MITRE ATT&CK and Threat Intelligence.
- Good analytical, communication, and escalation-management skills.
Preferred
- Experience with Defender for Endpoint, Entra ID, Defender for Identity, and Purview.
- Knowledge of SOAR, automation and Logic Apps.
- Experience with Splunk, QRadar, ArcSight, Trellix, or Palo Alto.
- Certifications: SC-200, GCIH, Security+ or CEH.
Pay: RM8,000.00 - RM11,000.00 per month
Experience:
- L2 SOC Analyst: 3 years (Preferred)
- Sentinel: 3 years (Preferred)
- Defender XDR/EDR: 3 years (Preferred)
Work Location: In person