We are seeking a highly motivated and skilled SOC L2 Analyst to join our security team at Bangalore & Chennai. The ideal candidate will be responsible for advanced security incident analysis, threat hunting, and the development of new detection rules and playbooks. This role will also have a partial focus on security governance, including assisting with policy development and ensuring compliance. This is a hybrid position with dedicated L2 resources operating on-site, while the majority of monitoring activities are conducted by the remote SOC team. Key Responsibilities Security Operations & Incident Response: Act as a primary responder for escalated security incidents, performing detailed analysis and leading the incident response process. Conduct proactive threat hunting using security data from various sources to identify potential threats and vulnerabilities. Develop, test, and maintain security playbooks and automated response actions to improve efficiency and reduce Mean Time to Respond (MTTR). Fine-tune security tools and platforms, including XSIAM, to minimize false positives and enhance detection capabilities. Collaborate with internal IT teams and external partners to remediate identified security issues. Provide mentorship and guidance to L1 analysts, assisting with complex incident triage and analysis. Governance & Compliance: Assist in the creation and maintenance of security policies, procedures, and standards. Ensure the SOC operations and processes adhere to internal policies and relevant industry compliance frameworks. Participate in security audits and assessments, providing necessary data and documentation to validate compliance. Contribute to regular reporting on the company's security posture and key performance indicators (KPIs) to leadership. This role will be part of a dedicated on-site team of L2 analysts. The on-site team will be responsible for in-person support and direct collaboration with local stakeholders, while security monitoring and a larger portion of the incident analysis will be handled by the remote SOC team. This hybrid model requires a high degree of independence, initiative, and clear communication.