Hiring.Camp

L2 - Security Analyst

Ensigninfosecurity

·

Today

Location
Malaysia (Kuala Lumpur)
Type
Full-time
Department
Security
Experience
2+ years
Source
Workday

Description

Ensign is hiring !

As a Level 2 Security Analyst in a Managed Security Service Provider (MSSP) environment, you will serve as an advanced escalation point for Tier 1 analysts, handling complex alerts and security incidents across multiple client environments. Your primary responsibility is to investigate threats in-depth, guide incident response efforts, enhance detection capabilities, and ensure clients are protected with timely and accurate responses. This role demands strong technical, analytical, and communication skills to succeed in a fast-paced, multi-tenant SOC.

Key Responsibilities:

Analyze and respond to escalated alerts from Tier 1 analysts across multiple clients.

Conduct in-depth investigations using SIEM, EDR, NDR, firewall logs, and other security tools.

Perform malware analysis, log correlation, and network traffic analysis to identify attack vectors.

Execute containment, eradication, and recovery procedures using predefined runbooks and playbooks.

Escalate and coordinate with Level 3 analysts or incident response teams for high-severity incidents.

Provide technical guidance, support, and mentoring to Tier 1 analysts.

Identify gaps in detection capabilities and recommend improvements in correlation rules, tuning, and alerts.

Support proactive threat hunting initiatives based on IOCs, TTPs, and contextual threat intelligence.

Monitor external threat intelligence feeds and correlate them with client telemetry to identify potential risks.

Maintain clear and accurate documentation of all investigations, actions taken, and incident outcomes.

Contribute to the continuous improvement of SOC processes, including the development of SOPs, playbooks, and runbooks.

Ensure all activities are performed in compliance with client-specific SLAs, internal policies, and applicable regulatory standards.

Participate in client-specific onboarding activities and ensure monitoring tools are correctly configured.

Join incident review meetings and provide root cause analysis and post-incident reporting when required.

Handle shift handovers with detailed summaries and ensure continuity of investigations and tasks.

Participate in internal knowledge-sharing sessions and contribute to SOC-wide initiatives and improvements.

Requirements:

Education & Experience:

Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field—or equivalent work experience.

2–4 years of experience in a Security Operations Center or similar cybersecurity environment.

Experience working in an MSSP or multi-tenant environment is highly desirable.

Technical Skills:

Strong experience with SIEM platforms (e.g., Splunk, Sentinel, QRadar).

Hands-on experience with EDR tools (e.g., CrowdStrike, SentinelOne, Microsoft Defender).

Familiarity with NDR and SOAR platforms is a plus (e.g., Darktrace, Corelight, Cortex XSOAR).

Strong understanding of networking protocols, log analysis, and system administration (Windows/Linux).

Knowledge of malware behaviors, phishing techniques, and MITRE ATT&CK framework.

Experience with scripting and automation tools (e.g., Python, PowerShell) is a plus.

Familiarity with case management tools (e.g., Jira, ServiceNow, TheHive).

Certifications (preferred):

CompTIA Security+, CySA+, or equivalent.

GIAC certifications (e.g., GCIH, GCIA, GCFA).

CEH, or vendor-specific certifications (e.g., Microsoft SC-200, CrowdStrike CCFR).

Key Competencies:

Strong analytical and problem-solving skills.

Excellent written and verbal communication—especially in client-facing documentation and briefings.

Ability to handle multiple investigations and prioritize effectively under pressure.

Customer-centric mindset with attention to SLA adherence and service quality.

Collaborative, team-oriented, and proactive with continuous learning attitude.

Shift Expectations:

Participation in shift rotations (24/7 support model, if applicable), including weekends and public holidays.

On-call support may be required depending on client SLAs and incident severity.

Skills

PythonLinuxJiraServiceNowCybersecuritySIEMSOCSplunkComplianceCompTIA

Similar Jobs

30

L2 Security Analyst

Ensigninfosecurity · Malaysia (Kuala Lumpur) +1

3 days ago

L2 Security Operations Engineer

Orange · Cairo, EG

6 days ago

SOC (L2) Security Specialist

Kyivstar · All · Hybrid

1 week ago

Domain Specialist (L2) - Security - Mātanga ā-Mahi

Inland Revenue · New Zealand, NZ

4 weeks ago

Network Security L2 support

Ironmountain · IND - Navi Mumbai, India

1 month ago

L2 Engineer(Network & Security Firewall)

Nttlimited · Mumbai, India · Hybrid

1 week ago

L2 SOC Security Engineer (SIEM / SOAR / UEBA) 3 to 4 Years

Black Box · Gurgaon, Haryana, India

3 weeks ago

L2 SOC Security Engineer (SIEM / SOAR / UEBA) 3 to 4 Years

Black Box · Gurgaon, Haryana, India

3 weeks ago

Collateral Security Specialist L2

Tutulu · Holloman Air Force Base, NM, US

1 month ago

L2 Network Security Engineer

Skaleart · Colombo

1 month ago

InfoSec - Application & Cloud Security Engineer (L2)

Openfx · Bangalore +1 · Hybrid

1 month ago

L2: Senior Security Analyst

Lumifi Cyber · Scottsdale, AZ · Remote, Onsite

2 months ago

SecOps Security Engineer (L2/L3) – Network & Security Operations

NorthBay Solutions · Islamabad

2 months ago

SecOps Security Engineer (L2/L3) – Network & Security Operations

NorthBay Solutions · Lahore, Punjab

2 months ago

SecOps Security Engineer (L2/L3) – Network & Security Operations

NorthBay Solutions · Karachi

2 months ago

MS Security Engineer (L2)

Nttlimited · Jakarta, Indonesia

2 months ago

Senior Cloud Security Engineer (L2)

LON3 London - 51 Lime Street · Atlanta, GA, United States, US

3 months ago

Security Analyst L2

Ensigninfosecurity · Malaysia (Kuala Lumpur)

3 months ago

SDWAN/L3 Test Engineering Technical Leader | L2/L3 security | Network automation | IPSEC and cloud security(11-15 Years)

Cisco · IND-BANGALORE, India +2 · Onsite

4 months ago

Security Engineer (L2)

Logicalis · Lisbon, Portugal

4 months ago

Security Analyst - L2

Nngroup · Digital Hub Prague, Czechia · Hybrid

6 months ago

MS Engineer L2, Network Security

Nttlimited · Mumbai, India · Onsite

7 months ago

Security Analyst - L2

Nttlimited · Mumbai, India · Onsite

1+ year ago

Network Security Engineer L2

SilverSky

1+ year ago

Senior Security Analyst (SOC L2/L3) - REF5729J

Deutsche Telekom IT Solutions · Debrecen, Budapest, Pécs, Szeged, Hungary · Hybrid

1 week ago

L2 CDN & Edge Security Engineer

Applied Cloud Computing · Pune, Maharashtra, India

1 month ago

Incident Response and Security Operations Consultant — L2

Armor · Pune, Maharashtra

2 months ago

Security Services Engineer (L2)

Nttlimited · IND, Bhubaneswar-West, India · Onsite

3 months ago

Security Services Engineer (L2)

Nttlimited · Mumbai, India · Onsite

3 months ago

Security Tools Engineer - L2

Mksinst · India Gurgaon

5 months ago