
L2 SOC Analyst Lead
2 days ago
Roles & Responsibilities
We are seeking a seasoned Level 2 SOC Analyst Lead to spearhead threat operations, mentor junior analysts, and drive advanced investigations within a high-stakes 24/7 Security Operations Center. You will be responsible for incident response leadership, threat hunting, forensic analysis, and client governance, while ensuring alignment with government and industry cybersecurity compliance standards.
Key Responsibilities:
- Lead daily SOC shift operations, ensuring strict adherence to incident SLAs (e.g., MTTR < 15 mins for P1).
- Mentor L1 SOC analysts in triage techniques, alert validation, and incident response playbooks.
- Conduct quarterly purple team exercises to validate SOC detection effectiveness.
- Deliver monthly presentations of SOC threat reports to client CISOs and key stakeholders.
- Lead deep-dive forensic investigations involving:
- Memory/disk forensics using Autopsy, FTK, Volatility, Rekall.
- Malware analysis leveraging sandboxing and static/dynamic techniques.
- EDR tools: CrowdStrike, SentinelOne.
- SIEMs: Splunk ES, QRadar (with SOAR integrations).
- Network tools: Wireshark, Corelight.
- Perform proactive threat hunts leveraging MITRE ATT&CK and threat intel sources.
- Engineer and implement custom detection rules (YARA, Sigma) to detect regional APTs.
- Serve as primary POC during high-severity incident response calls with clients.
- Ensure alignment with regulatory frameworks: IM8, NIST 800-53, CSA Cybersecurity Act.
- Compile and present monthly SOC threat trend reports and gap analysis to clients.
- Represent SOC at quarterly threat briefings (e.g., GovWare, ASEAN CERT meetups).
- Correlate intel from ASEAN CERT, MISP, ThreatConnect, and ISC2 Singapore.
- Disseminate timely IOCs and TTPs to analysts during active threats.
- Maintain and manage CTI using MISP, STIX/TAXII, and OpenCTI platforms.
Requirements:
- Minimum 5+ years in Security Operations Center roles.
- At least 2 years in a leadership role within a 24/7 SOC environment.
- Proven record in:
- Managing 200+ critical incidents/year.
- Reducing false positives by ?40% through tuning and detection engineering.
- Leading threat hunts that uncovered ?3 APT campaigns.
- Prior experience on government cybersecurity projects (e.g., IM8, CSA Cyber Essentials).
Certifications (Mandatory):
- CISSP
- GCIH or GCFA
- Singapore SC Security Clearance (or equivalent, if applicable)
Tool Proficiency (Must-Have):
- Incident Response: Velociraptor, Autopsy, SIFT Workstation
- Threat Hunting: Atomic Red Team, Kestrel analytics, ELK Stack
- Digital Forensics: Volatility, Rekall, FTK Imager
- CTI Management: MISP, OpenCTI, STIX/TAXII feeds
-
SOC Analyst
7 hours ago
Singapore OX Consultancy Full timejob Title:SOC Analyst L2: (10+ Yrs of exp) Location:Singapore/Onsite job Title :SOC Analyst L2: (10+ Yrs of exp) The primary function of an L2 Analyst is to ensure that the SOC team is performing its Items functions as required and to trouble shoot problematic incidents and events. In summary, the L2 Analyst shall also act as the technical...
-
SOC Analyst
1 week ago
Singapore CYBEROWL PTE. LTD. Full timeWe're CyberOwl, a dynamic venture capital backed start-up that operates globally with colleagues based in the UK, Greece, Singapore, Malaysia, Poland and Portugal. CyberOwl helps maritime and CNI asset operators gain visibility, cybersecurity and compliance of systems on their distributed, remote assets. We work with ship owners and managers where our...
-
Cybersecurity Analyst SOC L2
4 days ago
Singapore Capgemini Full time**About Capgemini** A global leader in partnering with companies to transform and manage their business by harnessing the power of technology. The Group is guided everyday by its purpose of unleashing human energy through technology for an inclusive and sustainable future. It is a responsible and diverse organization of 270,000 team members in nearly 50...
-
L2 SOC Analyst Lead
3 weeks ago
Singapore PERCEPT SOLUTIONS PTE. LTD. Full timeRoles & ResponsibilitiesWe are seeking a seasoned Level 2 SOC Analyst Lead to spearhead threat operations, mentor junior analysts, and drive advanced investigations within a high-stakes 24/7 Security Operations Center. You will be responsible for incident response leadership, threat hunting, forensic analysis, and client governance, while ensuring alignment...
-
soc analyst lead
4 weeks ago
Singapore INFINITY CYBERSEC PTE. LTD. Full timeRoles & ResponsibilitiesJob OverviewWe seek an L2 SOC Lead with active threat hunting, incident response, and team leadership experience to manage a 5-8 member SOC team serving government and critical infrastructure sectors. Operating in 24/7 shifts, you will perform advanced triage, conduct forensic investigations, front client engagements, and maintain...
-
SOC Lead
1 week ago
Singapore GOLDTECH RESOURCES PTE LTD Full timeRoles & ResponsibilitiesJoin our global Security Operations Center (SOC) as a Security Analyst III, where you'll play a crucial role in delivering Managed Security Services (MSS) to global clients. You'll lead incident investigations, optimize detection strategies and collaborate across teams to proactively defend enterprise infrastructure. This role is...
-
SOC Analyst
7 days ago
Singapore ITCAN Full time**SOC** **Analyst** To perform threat monitoring, advance triage, incident response, and follow up on customer query - Monitor, review and profile the events. - Assess each event based on factual information and wider contextual information available - Produce reports to provide an accurate depiction of the current threat landscape and associated risk. -...
-
SOC Analyst L2
6 days ago
Singapore ENSIGN INFOSECURITY (CYBERSECURITY) PTE. LTD. Full time**Responsibilities**: - Monitor third party security feeds, forums, and mailing lists to gather information related to the client through automated means - Produce intelligence outputs to provide an accurate depiction of the current threat landscape and associated risk through the use of customer, community, and open source reporting - Produce actionable...
-
SOC Analyst
2 weeks ago
Singapore Snow Software Full time**Job Description**: The SOC Analyst is responsible for monitoring and responding to the security events and risks of the business and documenting their research, triage, and mitigation efforts. They are expected to assess the effectiveness of detections, risk management controls, and policies used to prevent security threats. They are involved in the...
-
Immediate Hires
4 days ago
Singapore Hays Full timeSOC Analyst Hays Technology is looking for a SOC Analyst to help our client perform monitoring and review new cases for emerging threats - Performing analysis on suspicious files - Perform complex data analysis in support of security event management - Participate Incident Response that includes root cause - Identify opportunities to improve process to...