Job Summary : The SOC Operations Analyst L2 is responsible for monitoring and analyzing security alerts using tools like Microsoft Sentinel. The role includes investigating incidents, identifying real threats, and supporting response and remediation activities. The analyst works on alerts escalated from L1, performs log analysis, and helps improve detection by fine-tuning rules. They also support threat hunting, automation, and maintain proper documentation and reports. This role requires good knowledge of SIEM tools, security logs, and common cyber threats, along with close coordination with internal security and IT teams. Threat Monitoring & Analysis\\\\r\\\\n \\\\r\\\\nMonitor security alerts from SIEM tools (Sentinel, ArcSight, Splunk, QRadar)\\\\r\\\\nPerform in-depth analysis of escalated incidents (L1 L2)\\\\r\\\\nValidate true positives and eliminate false positives\\\\r\\\\n \\\\r\\\\n Incident Investigation & Response\\\\r\\\\n \\\\r\\\\nConduct root cause analysis (RCA) for security incidents\\\\r\\\\nPerform log correlation across multiple sources (EDR, Firewall, AD, Cloud logs)\\\\r\\\\nSupport incident containment and remediation actions\\\\r\\\\n \\\\r\\\\n Use Case Tuning & Optimization\\\\r\\\\n \\\\r\\\\nFine-tune SIEM correlation rules and alerts\\\\r\\\\nReduce noise and improve detection accuracy\\\\r\\\\nMap detections to MITRE ATT&CK; framework\\\\r\\\\n \\\\r\\\\n Threat Hunting (Proactive)\\\\r\\\\n \\\\r\\\\nPerform proactive threat hunting using SIEM, EDR, and threat intelligence\\\\r\\\\nIdentify hidden or advanced threats not detected by rules\\\\r\\\\nDevelop hypotheses-based hunting scenarios\\\\r\\\\n \\\\r\\\\n Automation & Playbooks\\\\r\\\\n \\\\r\\\\nSupport SOAR playbook execution (Sentinel Logic Apps, etc.)\\\\r\\\\nAssist in developing automation for repetitive tasks\\\\r\\\\nIntegrate SIEM with ticketing systems (ServiceNow)\\\\r\\\\n \\\\r\\\\n Reporting & Documentation\\\\r\\\\n \\\\r\\\\nDocument incidents, findings, and recommendations\\\\r\\\\nPrepare incident reports, dashboards, and metrics\\\\r\\\\nMaintain SOPs, runbooks, and knowledge base\\\\r\\\\n \\\\r\\\\n Collaboration\\\\r\\\\n \\\\r\\\\nWork closely with L1 analysts, L3 engineers, and IR teams\\\\r\\\\nCoordinate with IT teams for remediation actions\\\\r\\\\nSupport audits and compliance activities