Responsibilities
Investigate and qualify escalated SOC alerts, correlate and enrich evidence across security platforms, and determine incident verdict, severity, impact, and appropriate actions. Recommend or initiate initial mitigation and escalation measures, document investigations, support level 1 analysts, and improve detection rules, queries, runbooks, and playbooks.
Requirements
The role requires experience analyzing escalated security alerts, correlating events across SIEM, XDR, EDR, identity, email, network, and cloud sources, and enriching investigations with logs, indicators of compromise, and threat intelligence. The posting specifies no required degree, certification, language, or named tool; it describes a level 2 SOC role and emphasizes technical analysis, documentation, analyst support, and process-based response.