368,611open jobs
9,439companies
50,719added this week
Browse all
Salary
$28k – $63k per year (Estimated)
Location
Remote/Hybrid (Hyderabad, India)
Seniority
Senior · 3+ years exp
Overview
Company
Impact
Profile match
Keyloop is a global supplier of technology solutions to the automotive industry. Keyloop's helps to create and connect technology that advances the car buying and ownership experience in partnership with dealers and OEMs.

Role Summary

    The L2 SOC Analyst plays a critical role in Keyloop’s 24/7 Security Operations Center, responsible for in-depth investigation, analysis, and response to security alerts and incidents. This role acts as the primary escalation point from L1 analysts (internal or MSP) and is accountable for validating incidents, performing root cause analysis, and driving effective containment and remediation actions.

    The L2 SOC Analyst is expected to demonstrate strong technical capability across multiple security technologies, contribute to continuous improvement of SOC processes and detections, and support compliance and assurance requirements. The role requires a proactive mindset, strong analytical skills, and the ability to communicate effectively with technical and non-technical stakeholders.

Key Responsibilities

    Incident Investigation & Response

    • Investigate and validate escalated security alerts and incidents from L1 SOC analysts.

    • Perform detailed analysis to determine scope, impact, root cause, and attacker activity.

    • Lead containment, eradication, and recovery actions in collaboration with IT, engineering, and other security teams.

    • Ensure incidents are handled in accordance with defined incident response policies, runbooks, and SLAs.

    • Document incidents thoroughly, including timelines, findings, actions taken, and recommendations.

    • Security Monitoring & Detection

      • Actively monitor SIEM dashboards, queues, and alerts as required.

      • Validate detection logic and identify false positives, gaps, and improvement opportunities.

      • Propose and assist with the development of new SIEM use cases, correlation rules, and alert tuning.

      • Support continuous improvement of detection coverage across cloud, on-premise, and SaaS environments.

      SOAR & Automation Support

      • Execute and validate SOAR playbooks during incident response.

      • Identify opportunities for automation to improve response time, consistency, and quality.

      • Support the SOC Manager in testing, maintaining, and improving automated workflows.

      Security Technology Operations

      • Investigate alerts and events from a broad range of security technologies, including:

      • Web content filtering solutions

      • Email security gateways

      • Endpoint Detection & Response (EDR)

      • Managed Detection & Response (MDR)

      • Extended Detection & Response (XDR)

      • Correlate events across tools to build a complete incident narrative.

      Threat Intelligence

      • Consume and analyze threat intelligence relevant to Keyloop’s environment and industry.

      • Apply threat intelligence to investigations, detections, and response actions.

      • Support proactive threat hunting activities based on emerging threats and attacker techniques.

      Escalation & Collaboration

      • Act as the escalation point for complex or high-severity incidents.

      • Collaborate closely with the SOC Manager, L1 analysts, IT operations, engineering, and third-party providers.

      • Escalate incidents appropriately based on severity, impact, and business risk.

      Compliance & Assurance Support

      • Support SOC-related controls for NIST, ISO/IEC 27001, and SOC 2.

      • Ensure investigations, evidence collection, and logging meet audit and regulatory requirements.

      • Assist with audit requests by providing incident records, metrics, and operational evidence.

      Continuous Improvement & Knowledge Sharing

      • Contribute to the creation and maintenance of incident response runbooks and playbooks.

      • Participate in post-incident reviews and lessons-learned activities.

      • Share knowledge and mentor L1 analysts where appropriate.

      • Stay current with evolving threats, attack techniques, and defensive strategies.

Required Experience & Qualifications

    • 3-6 years of experience in a SOC, security operations, or incident response role.

    • Proven hands-on experience investigating and responding to security incidents.

    • Practical experience working with SIEM platforms and security alerting systems.

    • Exposure to SOAR tools and automated response workflows.

    • Experience with endpoint, email, network, and cloud security technologies.

    • Familiarity with threat intelligence sources and attacker methodologies.

Skills & Competencies

    Technical Skills

    • Incident analysis and response

    • Log analysis and event correlation

    • Endpoint, email, and network security investigation

    • Understanding of attacker tactics, techniques, and procedures (e.g., MITRE ATT&CK)

    Soft Skills

    • Strong analytical and problem-solving ability

    • Clear and concise written and verbal communication

    • Ability to work under pressure and manage multiple incidents

    • Collaborative mindset and willingness to support team objectives

    • Attention to detail and disciplined documentation

Education & Certifications (Preferred)

    • Bachelor’s degree in Computer Science, Information Technology, or a related field

    • Relevant certifications such as GCIA, GCIH, Security+, CEH, or equivalent

Working Pattern

    • 24/7 SOC environment with shift-based working as required

    • Based in Hyderabad, India

Values & Business Alignment

    • Demonstrates alignment with Keyloop’s values and ethical standards.

    • Understands how SOC activities support Keyloop’s products, customers, and business objectives.

    • Operates with a strong sense of ownership, accountability, and continuous improvement.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,611 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Hyderabad
SOC Senior Analyst 2 days ago
In office • Full-Time • Bachelor's Degree • Riyadh
DevOps
AWS
Azure
GCP
Cybersecurity
MITRE ATT&CK
Apply
SOC Analyst L1 1 day ago
In office • Full-Time • Bachelor's Degree • Riyadh
DevOps
AWS
Azure
GCP
SLI/SLO/SLA
Cybersecurity
MITRE ATT&CK
Apply
$80k – $169k per year (Estimated) • Equity • Remote • Full-Time • 5+ years exp
Go
Python
Databases
PostgreSQL
RabbitMQ
DevOps
Alertmanager
Ansible
Atlantis
Backstage
Chef
CI/CD
containerd
Docker
GCP
GitOps
Google GKE
Grafana
Helm
Incident Management
Kubernetes
Loki
Platform Engineering
Prometheus
Puppet
Terraform
Thanos
IAM
Cybersecurity
Checkov
SOC 2
Least Privilege
Apply
$112k – $217k per year (Estimated) • Equity • Remote • Full-Time • 5+ years exp
Go
Python
Databases
PostgreSQL
RabbitMQ
DevOps
Alertmanager
Ansible
Atlantis
Backstage
Chef
CI/CD
containerd
Docker
GCP
GitOps
Google GKE
Grafana
Helm
Incident Management
Kubernetes
Loki
Platform Engineering
Prometheus
Puppet
Terraform
Thanos
IAM
Cybersecurity
Checkov
SOC 2
Least Privilege
Apply
$42k – $106k per year (Estimated) • Equity • Remote • Full-Time • 5+ years exp
Go
Python
Databases
PostgreSQL
RabbitMQ
DevOps
Alertmanager
Ansible
Atlantis
Backstage
Chef
CI/CD
containerd
Docker
GCP
GitOps
Google GKE
Grafana
Helm
Incident Management
Kubernetes
Loki
Platform Engineering
Prometheus
Puppet
Terraform
Thanos
IAM
Cybersecurity
Checkov
SOC 2
Least Privilege
Apply
$94k – $170k per year (Estimated) • Remote/Hybrid • 5+ years exp
Node JS
Python
TypeScript
JavaScript
Node JS
Nest.JS
Databases
PostgreSQL
AI/ML
AI Agents
Claude
Claude Code
Copilot
Cursor
LangChain
LangGraph
LLM
Prompt Engineering
RAG
AWS Bedrock AgentCore
Function Calling
Frontend
React.js
DevOps
GitHub
Apply
Senior QA Engineer 12 days ago
$57k – $142k per year (Estimated) • Remote/Hybrid
Node JS
Python
TypeScript
JavaScript
Databases
PostgreSQL
AI/ML
AI Agents
Claude
Claude Code
Copilot
Cursor
Hallucination
LLM
Function Calling
Frontend
React.js
DevOps
GitHub
QA
Cypress
Jest
Playwright
Apply
Remote/Hybrid • Ho Chi Minh City
Assembly
Assembly
Keystone Engine
AI/ML
Claude
Claude Code
DevOps
AWS
Apply
Remote/Hybrid • Ho Chi Minh City
Apply
Tech Support Engineer 27 days ago
$28k – $35k per year • Remote/Hybrid • Prague
C++
Java
Visual Basic
DevOps
Bamboo
CI/CD
Jenkins
Apply
$19k – $49k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Hyderabad
SQL
C#
TypeScript
JavaScript
C#
.NET
Databases
MS SQL
Frontend
Angular
DevOps
CI/CD
Git
GitHub
Jenkins
Apply
$16k – $36k per year (Estimated) • In office • Full-Time • 2+ years exp • Bachelor's Degree • Hyderabad
Apply
Data Engineer 4 hours ago
$22k – $55k per year (Estimated) • In office • Full-Time • 3+ years exp • Hyderabad
Databases
Databricks
AI/ML
AI Agents
Analytics
ETL/ELT
Apply
LLM Model Developer 4 hours ago
$28k – $77k per year (Estimated) • In office • Full-Time • 3+ years exp • Hyderabad
AI/ML
AI Agents
Fine-tuning
LLM
Apply
Web Developer 4 hours ago
$25k – $67k per year (Estimated) • In office • Full-Time • 5+ years exp • Hyderabad
JavaScript
SQL
Java
Java
Spring Boot
Apply
See all jobs
This is one of many
368,611 more open roles from verified company boards, updated every day.