Back to jobs

SOC L2- Qradar

SISABengaluru, Karnataka, IndiaAdded 1d ago
SOC Analyst
Craft my tailored resume free

Free to start · No card

Job description

The SOC Sr Analyst L2 serves as the escalation point for complex security incidents detected within IBM QRadar. The L2 analyst conducts deep-dive investigations, performs threat hunting, tunes correlation rules, and coordinates incident response activities. This role requires strong analytical and technical expertise in QRadar SIEM operations, along with proactive detection and threat mitigation skills. Key ResponsibilitiesAnalyze escalated incidents and offenses from L1 analysts for deeper investigation and containment.Perform in-depth log correlation and timeline reconstruction using IBM QRadar.Develop and fine-tune QRadar correlation rules, AQL searches, and custom use cases for improved detection.Perform proactive threat hunting across multiple data sources using QRadar and threat intelligence feeds.Coordinate response actions during security incidents, ensuring containment, eradication, and recovery.Lead the root cause analysis (RCA) and prepare incident summary reports with actionable recommendations.Integrate and validate external threat intelligence feeds (STIX/TAXII) within QRadar for advanced correlation.Collaborate with IT, network, and endpoint teams for incident validation and resolution.Support vulnerability management, patch validation, and policy enforcement activities.Provide mentorship and technical guidance to L1 analysts.Participate in continuous improvement initiatives for SOC processes and playbooks. Required Technical SkillsAdvanced proficiency with IBM QRadar SIEM – rule creation, offense management, AQL queries, dashboards.Strong understanding of network and endpoint telemetry, including firewall, proxy, and EDR logs.Experience with malware analysis, phishing investigation, and digital forensics concepts.Knowledge of scripting languages (Python, PowerShell, or Bash) for automation of analysis tasks.Understanding of threat intelligence platforms and integration mechanisms (STIX/TAXII).Experience in incident response processes aligned with NIST or SANS frameworks.Ability to work independently and collaboratively in high-pressure security incidents.Excellent report writing, communication, and documentation skills. Qualifications & CertificationsBachelor’s or master’s degree in computer science, Cybersecurity, or related discipline.2–5 years of experience in SOC, Incident Response, or Threat Analysis roles.Preferred certifications: IBM Certified Analyst – QRadar SIEM, GCIH, GCIA, CEH, CySA+, or MITRE ATT&CK Defender (MAD).

Prepare your application

Use the description above to assess your fit for SISA. This checklist is guidance from Resumize, rather than additional requirements from the employer. Imported listings can be shortened or change after collection, so confirm the complete description and current availability before sending an application.

Match requirements to evidence

Identify the responsibilities and skills the employer explicitly names. For each important requirement, choose one example from your work, education, training, or projects. Explain what you did, how you did it, and what changed as a result. Include a measurable outcome when you can support it. If you lack a requirement, describe related experience accurately instead of adding an unfamiliar skill to your resume.

Put the most relevant examples near the top of your resume. Keep job titles, dates, qualifications, and contact details consistent across your application materials. Use the employer’s terminology when it describes your experience accurately; a copied list of keywords does not explain your contribution. A short, specific bullet is easier to review than a paragraph that mixes several unrelated duties.

Check the working arrangement

Confirm the location, schedule, employment type, and any eligibility requirements on the employer’s site. A remote label does not establish worldwide eligibility or flexible hours. If compensation, benefits, equipment, travel, or contract duration are missing from this listing, write down your questions for the recruiter. Do not assume details from another opening at the same company apply to this role.

Review before submitting

Follow the employer’s requested file format and application instructions. Open your exported resume and check that its text is selectable, its sections read in order, and its links work. Proofread names, dates, and contact information. Share confidential work samples only when you have permission, and use an anonymized example when necessary.

Submit through a trusted employer or recruiting destination. If the original listing has disappeared, search the employer’s careers page for the title rather than assuming the vacancy remains open. Save the application date, job reference, and the version of your resume you sent. Those details help you prepare for a later conversation and avoid submitting conflicting information through several job boards.

Review your resume for writing and readability feedback, or browse other openings if this opportunity is unavailable.