SOC Analyst (L2)
Muscat, OMAN, Oman
Full Time
Mid Level
Location: Oman
Nationality: Omani Nationals Only
Experience: 5+ Years
Employment Type: Full-Time
Working Hours: 8×5 (Business Hours)
About the Role
KalSoft is looking for an experienced SOC Analyst (L2) to support Security Operations Center activities, including real-time monitoring, alert investigation, incident escalation, and security incident response. The role will provide second-level analysis, support the L1 SOC team, investigate critical and recurring incidents, and contribute to improving SOC detection, response, and incident-handling processes.
Key Responsibilities
- Monitor security events in real time and perform alert triage and in-depth investigation during business hours.
- Support the L1 SOC team with analysis, investigation, and recommendations.
- Perform second-level review of security alerts to ensure potential incidents are not overlooked.
- Handle incident escalations and coordinate response activities according to agreed SLAs.
- Conduct detailed investigations of critical and recurring security incidents.
- Identify incident trends and recommend detection-rule tuning and improvements.
- Contribute to the development and refinement of SOC use cases, playbooks, and incident-handling procedures.
- Track and monitor incident SLAs daily and ensure timely closure or escalation.
- Review daily incident summary reports for quality assurance.
- Prepare weekly and monthly reports covering incident statistics, SOC performance, and improvement recommendations.
- Coordinate with engineering teams and vendors for issue resolution and system integration.
- Escalate critical security issues and SLA breaches to management when required.
Key Deliverables
- Daily security monitoring and escalation reports.
- Coordination with engineering team.
- Weekly summaries of detection performance and improvement recommendations.
Requirements
- Omani National only.
- Minimum 5+ years of SOC experience.
- Hands-on experience in SOC monitoring, alert triage, incident investigation, and escalation.
- Strong understanding of security incidents, detection rules, use cases, and incident response processes.
- Experience working with SOC teams, engineering teams, and security technology vendors.
- Strong analytical and investigation skills.
- Good understanding of SLA-based incident management and reporting.
- CEH and/or Fortinet NSE certification is required/preferred.
- Good communication and documentation skills.
Apply for this position
Required*