SOC L2 Analyst
Choosing Capgemini means choosing a company where you will be empowered to shape your career in the way you’d like, where you’ll be supported and inspired by a collaborative community of colleagues around the world, and where you’ll be able to reimagine what’s possible. Join us and help the world’s leading organizations unlock the value of technology and build a more sustainable, more inclusive world.
Your Role
- Monitor, investigate, and triage security alerts using Microsoft Sentinel, Microsoft Defender XDR, and other SIEM/XDR platforms to identify potential security incidents.
- Analyze endpoint, identity, cloud, email, network, DNS, and firewall telemetry to validate alerts, perform threat hunting, and determine incident impact and scope.
- Conduct phishing investigations, malware triage, log analysis, and MITRE ATT&CK-based threat mapping to detect and respond to advanced threats.
- Create detailed incident reports, maintain evidence, document investigation findings, and prepare escalation packages for L3, CSIRT, and IT response teams.
- Recommend detection tuning, false-positive reduction, playbook improvements, and ensure effective shift handovers to support continuous 24x7 SOC operations.
Your Profile
- 4+ years of experience in Security Operations Center (SOC) environments with expertise in security monitoring, incident analysis, and response within enterprise, cloud, or hybrid infrastructures.
- Strong understanding of Windows, Linux, Active Directory, Entra ID, endpoint telemetry, cloud logs, network fundamentals, email security, authentication mechanisms, and enterprise attack methodologies.
- Hands-on experience with SIEM and XDR platforms, preferably Microsoft Sentinel and Microsoft Defender XDR, including the ability to create, modify, and analyze KQL queries for investigations, threat hunting, and alert validation.
- Proven ability to analyze endpoint, identity, cloud, email, DNS, firewall/proxy, SaaS, and network telemetry, perform phishing and malware triage, and map observed activities to MITRE ATT&CK techniques and adversary behaviors.
- Experience managing the incident lifecycle, including evidence collection, severity assessment, containment support, escalation to L3/CSIRT teams, preparation of incident reports, tuning recommendations, playbook enhancements, and shift handover documentation.
What you will love working in Capgemini
- Be a key contributor in 24x7 SOC operations by monitoring, investigating, and responding to security alerts using Microsoft Sentinel, Microsoft Defender XDR, and other security monitoring tools.
- Analyze endpoint, identity, cloud, email, DNS, firewall, proxy, and network telemetry to identify potential threats, validate alerts, and support incident containment and remediation activities
- Clear career progression paths from engineering roles to architecture and consulting.
- Be part of mission-critical projects that ensure security, compliance, and operational efficiency for Fortune 500 clients
Capgemini is an AI-powered global business and technology transformation partner, delivering tangible business value. We imagine the future of organizations and make it real with AI, technology and people. With our strong heritage of nearly 60 years, we are a responsible and diverse group of 420,000 team members in more than 50 countries. We deliver end-to-end services and solutions with our deep industry expertise and strong partner ecosystem, leveraging our capabilities across strategy, technology, design, engineering and business operations. The Group reported 2024 global revenues of €22.1 billion.
Make it real | www.capgemini.com
Bangalore, IN