CyberGate Defense LLC
Soc Analyst - L2
Abu Dhabi, United Arab Emirates
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.6M live jobs from 190,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Mid level
- Country
- AE
- Work mode
- On-site / unstated
- First seen by hirly
- 23 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Job Description: SOC L2 Analyst
Location: [Abu Dhabi - UAE]
Experience: 4 to 6 Years
Department: Cyber Security / Security Operations Center (SOC)
Reporting to: SOC Manager / Team Lead
Role Overview
The SOC L2 Analyst is responsible for advanced security monitoring, deep-dive incident investigation, and complex threat analysis. Acting as the critical escalation point for Level 1 Analysts, you will lead the response to sophisticated threats and ensure the continuous improvement of our detection capabilities. You will play a hands-on role in incident containment, eradication, and recovery, while proactively hunting for emerging threats within our environment.
Key Responsibilities
1. Advanced Investigation & Incident Response
- Deep-Dive Analysis: Perform advanced threat analysis and investigate complex security incidents escalated from Tier 1.
- Incident Leadership: Lead incident response activities, including the containment of active threats, eradication of malicious actors, and recovery of systems.
- Root Cause Analysis (RCA): Conduct comprehensive RCAs to identify how breaches occurred and recommend preventative controls.
- Threat Hunting: Proactively hunt for threats using IOCs (Indicators of Compromise) and TTPs (Tactics, Techniques, and Procedures) to uncover hidden malicious activity.
2. SIEM & Detection Engineering
- Tool Mastery: Analyze logs and correlate security events using complex queries within Splunk and IBM QRadar .
- Rule Optimization: Develop and optimize SIEM use cases, correlation rules, and alerts to reduce false positives and improve detection accuracy.
- Playbook Development: Create and refine incident response playbooks and automated detection logic to standardize response efforts.
3. Intelligence & Mentorship
- Threat Intel Integration: Monitor and integrate threat intelligence feeds into the SIEM to ensure the environment is protected against the latest known threats.
- Mentorship: Serve as a technical mentor for L1 analysts, providing guidance on investigation techniques and professional development.
Required Technical Skills
- SIEM Platforms: High proficiency in Splunk (Search Processing Language - SPL, dashboards, alerting) and IBM QRadar (Offense management, rules engine, AQL queries).
- Frameworks: Strong operational knowledge of the MITRE ATT&CK framework and the full Incident Response lifecycle.
- Security Tooling: Experience with EDR/XDR solutions, Firewall logs, and IDS/IPS systems.
- Threat Analysis: Expert knowledge of IOC analysis, malware behavior, and threat intelligence platforms.
- Scripting: Basic automation skills using Python, PowerShell, or Bash to streamline repetitive tasks.
Required Experience & Qualifications
- Experience: 4–6 years of dedicated experience in a SOC environment or Cyber Security operations.
- Education: Bachelor’s degree in Computer Science, Cyber Security, or a related technical field.
Preferred Certifications:
- Core: CompTIA CySA+ or Certified Ethical Hacker (CEH).
- Platform Specific: Splunk Certified User/Admin or IBM QRadar Certification.
- Advanced: GCIH, GCIA, or similar technical IR certifications.
Preferred Behavioral Competencies
- Strong analytical thinking and problem-solving skills under pressure.
- Excellent communication skills for documenting technical findings in clear business terms.
- A proactive "hunter" mindset focused on continuous security improvement.
Listed on hirly, a job board. hirly is not the employer: CyberGate Defense LLC is hiring for this role.
Similar jobs
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job