SOC L2 Analyst
-
Capgemini
- Bangalore
- Experienced Professionals
- Full Time
- Cloud Infrastructure Management
- Cloud Infrastructure Services
Posted September 19, 2026 applications close October 19, 2026
Sign in to apply
Please sign in or register for free to apply.
Job Description
Your Role
- Monitor, investigate, and triage security alerts using Microsoft Sentinel, Microsoft Defender XDR, and other SIEM/XDR platforms to identify potential security incidents.
- Analyze endpoint, identity, cloud, email, network, DNS, and firewall telemetry to validate alerts, perform threat hunting, and determine incident impact and scope.
- Conduct phishing investigations, malware triage, log analysis, and MITRE ATT&CK-based threat mapping to detect and respond to advanced threats.
- Create detailed incident reports, maintain evidence, document investigation findings, and prepare escalation packages for L3, CSIRT, and IT response teams.
- Recommend detection tuning, false-positive reduction, playbook improvements, and ensure effective shift handovers to support continuous 24×7 SOC operations.
Your Profile
- 4+ years of experience in Security Operations Center (SOC) environments with expertise in security monitoring, incident analysis, and response within enterprise, cloud, or hybrid infrastructures.
- Strong understanding of Windows, Linux, Active Directory, Entra ID, endpoint telemetry, cloud logs, network fundamentals, email security, authentication mechanisms, and enterprise attack methodologies.
- Hands-on experience with SIEM and XDR platforms, preferably Microsoft Sentinel and Microsoft Defender XDR, including the ability to create, modify, and analyze KQL queries for investigations, threat hunting, and alert validation.
- Proven ability to analyze endpoint, identity, cloud, email, DNS, firewall/proxy, SaaS, and network telemetry, perform phishing and malware triage, and map observed activities to MITRE ATT&CK techniques and adversary behaviors.
- Experience managing the incident lifecycle, including evidence collection, severity assessment, containment support, escalation to L3/CSIRT teams, preparation of incident reports, tuning recommendations, playbook enhancements, and shift handover documentation.
What you will love working in Capgemini
- Be a key contributor in 24×7 SOC operations by monitoring, investigating, and responding to security alerts using Microsoft Sentinel, Microsoft Defender XDR, and other security monitoring tools.
- Analyze endpoint, identity, cloud, email, DNS, firewall, proxy, and network telemetry to identify potential threats, validate alerts, and support incident containment and remediation activities
- Clear career progression paths from engineering roles to architecture and consulting.
- Be part of mission-critical projects that ensure security, compliance, and operational efficiency for Fortune 500 clients