Cybersecurity Analyst SOC L2

3 days ago


Singapore Capgemini Full time

**About Capgemini**

A global leader in partnering with companies to transform and manage their business by harnessing the power of technology. The Group is guided everyday by its purpose of unleashing human energy through technology for an inclusive and sustainable future. It is a responsible and diverse organization of 270,000 team members in nearly 50 countries. With its strong 50 year heritage and deep industry expertise, Capgemini is trusted by its clients to address the entire breadth of their business needs, from strategy and design to operations, fueled by the fast evolving and innovative world of cloud, data, AI, connectivity, software, digital engineering and platforms. The Group reported in 2020 global revenues of EUR 16 billion.

Group Cybersecurity creates and manages global security policies, tracks compliance from Business Units and Global Business Lines, provides strong communications, training and awareness campaigns to employees, designs global security architecture based on threats and market evolution, and manages Group Cybersecurity Projects and Operations.

In order to keep building the team, Group Cybersecurity is looking for a Security Analyst SOC L2.

Professionals help to protect an organization by employing a range of security tools and technologies and processes to prevent, detect and manage cyber threats.

You will be working within a team composed of 12 people located internationally as Group Cybersecurity Operations SOC. Your primary role would be to support all activities undertaken by the Threat Intelligence pillar.

You will work with the wider team to prioritize and schedule work within your pillar. You will work with various members of the team to develop and input into technical projects, report, and oversee progress to make sure goals are met.

**What you’ll be tasked with**:
To be a member of the Security Operations Centre (SOC), a team who deliver specific Cybersecurity Services to the CAPGEMINI GROUP. The role is focused on delivering Intrusion Detection / Prevention services and assisting with Investigations as a result of escalated problems and security alerts from client security information & event management systems (SIEM). Additional activities include periodic and ad-hoc host Vulnerability Assessments and Application security assessments. Security policy enforcement is also key, and is achieved through various assurance activities such as auditing Firewalls, and conducting privilege account reviews etc.

You will be responsible for ensuring the integrity of client IT infrastructures and protecting the information systems residing upon them from external and internal attack / compromise.

L2 provide support to L1 services and will analyse security events that have been triaged by L1 services or where further assistance is needed. This will involve responding to incidents and determining the appropriate next steps for the investigation and any remediation action.

Analysts will operate as Subject Matter Experts and will provide the relevant assistance to the L1 SIEM analyst to support them. They will also initiate security incidents, creating tickets, and where appropriate, initiating the process leading to declaration of a major incident.

L2 Analysts will perform slow time analysis of data to identify trends or other suspicious behavior that is not captured by use cases.

They are also responsible for creation and maintenance of playbooks and other processes used by the team along with some basic SIEM administration; including improvements such as Use Case creation and onboarding of devices already supported by the platform.
- Analytics and rule authoring
- Fine tuning of alerting
- Level 2 support for security incidents
- Validate, suggest or create knowledge base articles
- Reviews and updates SIEM security incidents, suspicious events and analyses recommendation
- Work with L1 to decrease false positives
- Creates/maintains dashboards, correlation rules, thresholds etc.
- Report review
**What you’ll need to excel in the role**:

- Knowledge and experience in IT Network Security
- IP Networking
- Experience in the use of Intrusion Detection systems, management and responding to and the tuning of alerts
- Experience in conducting host vulnerability assessments
- Experience in the use of SIEM platforms, preferably IBM QRadar.
- Unix & Microsoft Administration
Vulnerability Awareness / Understanding
- Experience using tools such as IBM Resilient, Falcon Crowdsike, FireEye HX, VirusTotal Enterprise, Onyphe, ThreatQuotient, Shodan, etc


  • SOC Analyst

    1 week ago


    Singapore CYBEROWL PTE. LTD. Full time

    We're CyberOwl, a dynamic venture capital backed start-up that operates globally with colleagues based in the UK, Greece, Singapore, Malaysia, Poland and Portugal. CyberOwl helps maritime and CNI asset operators gain visibility, cybersecurity and compliance of systems on their distributed, remote assets. We work with ship owners and managers where our...


  • Singapore Monster SG Pte Limited Full time

    Roles & Responsibilities We are seeking a seasoned Level 2 SOC Analyst Lead to spearhead threat operations, mentor junior analysts, and drive advanced investigations within a high-stakes 24/7 Security Operations Center. You will be responsible for incident response leadership, threat hunting, forensic analysis, and client governance, while ensuring...


  • Singapore Capgemini Full time

    **About Capgemini** A global leader in partnering with companies to transform and manage their business by harnessing the power of technology. The Group is guided everyday by its purpose of unleashing human energy through technology for an inclusive and sustainable future. It is a responsible and diverse organization of 270,000 team members in nearly 50...

  • L2 SOC Analyst Lead

    3 weeks ago


    Singapore PERCEPT SOLUTIONS PTE. LTD. Full time

    Roles & ResponsibilitiesWe are seeking a seasoned Level 2 SOC Analyst Lead to spearhead threat operations, mentor junior analysts, and drive advanced investigations within a high-stakes 24/7 Security Operations Center. You will be responsible for incident response leadership, threat hunting, forensic analysis, and client governance, while ensuring alignment...

  • SOC Analyst L2

    6 days ago


    Singapore ENSIGN INFOSECURITY (CYBERSECURITY) PTE. LTD. Full time

    **Responsibilities**: - Monitor third party security feeds, forums, and mailing lists to gather information related to the client through automated means - Produce intelligence outputs to provide an accurate depiction of the current threat landscape and associated risk through the use of customer, community, and open source reporting - Produce actionable...

  • SOC Manager

    2 weeks ago


    Singapore ENSIGN INFOSECURITY (CYBERSECURITY) PTE. LTD. Full time

    **Responsibilities** - Lead the overall day-to-day work of the security operations center in ensuring events and/or incidents are detected and responded to established process as per the agreed standing order. - Recruit, manage, develop, and retain the SOC analysts. - Develop and revise the framework, procedures and processes that are required to ensure...

  • SOC Director

    2 weeks ago


    Singapore ENSIGN INFOSECURITY (CYBERSECURITY) PTE. LTD. Full time

    The SOC Director is primarily responsible for overseeing the 24x7x365 Security Operation Center’s processes, technology and analysts who monitor security tools, assess threats, and risks involving client infrastructure. In this role, you will be responsible for ensuring that all Managed Service deliverables are produced on time and within strict SLA time...

  • SOC Analyst

    7 days ago


    Singapore INFINITE COMPUTER SOLUTIONS PTE LTD Full time

    **Job Summary**: We are looking for a Level 1 SOC Analyst to monitor and respond to security alerts. You will be the first point of contact for identifying potential security incidents and escalating them as needed. This is a great role for someone starting their career in cybersecurity. **Key Responsibilities**: - Monitor security alerts using tools like...

  • SOC Analyst L1

    2 weeks ago


    Singapore Xcellink Pte Ltd Full time

    SOC Analyst L1 role is for fresh grads/ experienced, mínimally some knowledge or certification in cybersecurity foundations. Their background should have relevant IT knowledge, certifications or education. This program will include a 3 day full-day intensive training in Level 1 Basics of Cybersecurity foundations such as Introduction to Cybersecurity,...

  • SOC Analyst

    2 weeks ago


    Singapore Snow Software Full time

    **Job Description**: The SOC Analyst is responsible for monitoring and responding to the security events and risks of the business and documenting their research, triage, and mitigation efforts. They are expected to assess the effectiveness of detections, risk management controls, and policies used to prevent security threats. They are involved in the...