SIEM Analyst Incident Responder L2
HCLTech · Fully Remote · Mid
Умения
Описание
Job Summary
The L2 Security Analyst will be responsible for real-time monitoring, investigation, and response to identity-based and endpoint security threats using Microsoft Defender for Endpoint (MDE). This role requires 24×7 support coverage and collaboration with global security teams to ensure threat detection, containment, and remediation in a fast-paced environment.
Candidate Persona
• Skilled in managing extensive and intricate networks.
• Brings substantial hands-on experience with continuous SIEM monitoring, validating alerts, and investigating across identity, endpoint, and network security data, demonstrating expertise in correlating events from multiple sources to detect real threats.
• Possesses strong analytical skills to refine SIEM use cases and detection logic based on monitoring feedback, false positive reviews, and evolving threat landscapes, ensuring an enhanced signal-to-noise ratio and greater operational effectiveness.
• Proficient at evaluating SIEM alerts and incident patterns, identifying detection coverage gaps, and delivering clear, actionable feedback to content management and detection engineering teams for optimizing and enhancing rules.
• Self-driven and innovative, takes initiative and ownership of responsibilities, collaborates effectively with team members, and consistently delivers organized, high-quality results.
• The ideal candidate is eager to comprehend complex issues and requirements, excels at turning them into practical solutions, and pays careful attention to details.
• Has knowledge or experience with various SIEM tools, Intrusion Detection Systems (IDS), and roles in network security.
• Familiar with the MITRE framework or similar standards; possesses hands-on expertise with EDR platforms, threat analysis, and has engaged in threat hunting or incident response.
• Understands network, system, and endpoint security disciplines.
• Experienced in event monitoring, analysis, escalation procedures, and providing feedback for content improvement.
• Adept at producing monthly, weekly, and daily reports.
• Open to working in a 24/7 operational environment.
• Reviews escalated SIEM incidents to verify true positive cases.
• Delivers monthly trend analyses and security summary reports.
• Supports SIEM event and incident analytics.
• Provides log analysis summaries and offers recommendations for incident detection and prevention.
• Conducts advanced triage and works collaboratively with resolution teams, third parties, or designated customer contacts.
• Coordinates with cross-functional teams to help develop security incident response reports.
• Promotes the implementation of protection and mitigation strategies derived from lessons learned.
Soft skills
• Shall have good verbal/written communication skills
• Should be willing to work in 24×7 environments
• From time-to-time travel opportunities may be assigned
• Incumbent should carry continual system improvement mindset and able to demonstrate in work.
• Client facing technical analysis report and presentation skills
Education: requirement:
• Batchelor Degree in a related field (Cybersecurity, Information Security, Computer Science, Information Technology, Computer Engineering )or equivalent practical experience
• English Language Fluency
История на обявата
- 16 юли 2026 г.Появи сеисторически запис
- 1 август 2026 г.Затворенапроверка на URL · URL no longer reachable
Очаквано възнаграждение
Обявата не посочва заплата. Оценката по-долу е за Incident Responder / DFIR на ниво Mid според бенчмарка на CSF.BG — не е предложение на работодателя.
Няма нито една обява за тази роля и ниво с публикувана заплата, с която да се сравни.
Знаеш колко се плаща за такава роля? — анонимно, за да станат тези числа по-точни.