The SOC L2 Analyst will serve as a critical escalation point for security operations, conducting deep-dive triage and incident response across various security platforms. They will also drive operational improvements by leading post-incident reviews and refining automation playbooks to harden the security posture.
About the Role
Our client is building a world-class defense against an increasingly sophisticated threat landscape, and we are looking for a sharp, proactive SOC L2 Analyst to join the Information Security team. You will serve as a critical escalation point for our security operations, bridging the gap between automated detection and incident resolution. If you thrive in high-stakes environments and are passionate about threat hunting and incident hardening, this is your opportunity to directly influence the security posture of their fintech ecosystem.
What You Will Do
Elevated Monitoring: Maintain deep visibility into our infrastructure by actively monitoring security alerts across SIEM, IDS/IPS, firewalls, and EDR platforms.
Deep-Dive Triage & Analysis: Conduct detailed investigations of complex security events, analyzing network traffic and system logs to identify malicious patterns and vulnerabilities that bypass automated rules.
Incident Ownership: Lead the response and containment of security incidents, coordinating cross-functional efforts and ensuring timely, effective resolution during critical events.
Advanced Documentation: Maintain meticulous records of security investigations, contributing to high-level incident reporting and maintaining our internal knowledge base.
Continuous Hardening: Drive operational improvement by leading post-incident reviews, identifying gaps in our defenses, and refining SOC procedures and automation playbooks.
What You Bring
Experience: 5+ years of hands-on experience in security operations, incident response, or advanced threat monitoring.
Security Stack: Proven proficiency with industry-standard SIEM tools (e.g., Splunk, Microsoft Sentinel, QRadar, ELK) and familiarity with EDR, IDS/IPS, and perimeter security solutions.
Technical Acumen: Strong working knowledge of cybersecurity principles, threat vectors, network protocols, and application-layer attacks.
Cloud Proficiency: Practical experience securing cloud-native environments, with a preference for AWS and Azure.
Methodology: Strong grasp of security frameworks like MITRE ATT&CK and the Cyber Kill Chain to guide threat hunting activities.
Analytical Rigor: A demonstrated track record of successful security investigations and proactive threat hunting.
Communication: Exceptional attention to detail and the ability to articulate complex technical findings to both engineering teams and non-technical stakeholders.
Bonus Qualifications: A Bachelor’s degree in Computer Science, Cybersecurity, or a related field, and familiarity with compliance frameworks (ISO27001, ISO27701, PCI DSS, GDPR).
What's in It for You
True Ownership: You will have the autonomy to influence our security roadmap and make architectural decisions that protect our production environments.
Impactful Work: Your work directly safeguards real-money flows and critical financial data, making a tangible difference in the security of our users.
Collaborative Culture: Join a cross-functional team of experts in engineering, fraud, and payments who value security and knowledge sharing.
Continuous Growth: We invest in your professional development through support for advanced certifications, conference attendance, and research time.
Competitive Benefits: We offer a comprehensive benefits package, including competitive compensation, health coverage, and flexible working arrangements.
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”