The Cyber Security Lead Analyst – SOC (L2/L3) will be part of a global Security Operations Center (SOC) team responsible for continuous security monitoring, incident detection, response, and prevention across enterprise IT environments. This role focuses on handling high-priority and critical security incidents, supporting SOC analysts, improving detection and response capabilities, and contributing to the overall cybersecurity operations and security roadmap across global regions.
Lead and manage high-priority and critical security incidents with end-to-end incident management ownership
Support and guide SOC L1 and L2 analysts in resolving complex security incidents
Participate in study, evaluation, and proof-of-concept (POC) of security tools and technologies aligned with the security roadmap
Act as a subject matter expert in one or two core security domains such as threat hunting, forensic analysis, EDR, IPS, or DLP
Perform advanced security investigations and provide deep-dive analysis for complex incidents
Contribute to threat detection strategies aligned with the MITRE ATT&CK framework and industry best practices
Enhance incident response procedures, runbooks, and reaction workflows
Identify security gaps, define mitigation strategies, implement controls, and track remediation to closure
Collaborate with regional SOC and CERT teams on incident response and security operations as required
Support cybersecurity technical planning, incident analysis methodologies, and operational improvements
Proven experience working in a Security Operations Center (SOC) environment at L2 or L3 level
Strong hands-on experience handling critical and high-severity security incidents
Experience supporting and mentoring junior SOC analysts
Exposure to global or multi-region SOC operations
Strong understanding of incident response lifecycle, detection engineering, and security operations processes
Experience working with industry frameworks such as MITRE ATT&CK
Ability to analyze complex security incidents and drive remediation initiatives
Willingness to support global security operations as per business needs
SIEM, Incident Response, Threat Hunting, MITRE ATT&CK, EDR, IPS, DLP, Forensic Analysis, Security Monitoring, SOC Operations, Cyber Defense, Runbook Development, Risk Detection, Security Tools Evaluation