Upload Button Icon Add office photos
Engaged Employer

i

This company page is being actively managed by IBM Team. If you also belong to the team, you can get access from here

IBM Verified Tick

Compare button icon Compare button icon Compare
filter salaries All Filters

2,064 IBM Jobs

XDR Analyst - L2

3-7 years

Bangalore / Bengaluru

XDR Analyst - L2

IBM

posted 5 days ago

Job Role Insights

Flexible timing

Job Description



Roles & Responsibilities:
1.Handling alerts and incident on XDR platform
2.Alert & incident triage and analysis
3.Proactively investigating suspicious activities
4.Log all findings, actions taken, and escalations clearly in the XDR and ITSM platform
5.Execute predefined actions such as isolating blocking IPs or disabling user accounts, based on set protocols.
6.Adhere to established policies, procedures, and security practices.
7.Follow-up with tech team for incident closure
8.Participating in daily standup and review meeting
9.L2 Analyst has responsibility to closely track the incidents and support for closure.
10.Working with logsource and usecase management in integrating log sources and developing & testing usecase
11.Work & support on multiple cybersecurity tool (DLP, GRC, Cloudsec tool, DAM)
12.Developing SOP / instruction manual for L1 team
13.Guiding L1 team for triage/analysis and assist in clousure of cybersecurity alert and incidents
14.Handle XDR alerts and followup with customer team for agent updates
15.Escalate more complex incidents to L3 SME for deeper analysis.
Key Responsibilities:
Security Monitoring & Incident Response Governance
Define and maintain security monitoring, threat detection, and incident response policies and procedures.Establish and mature a threat intelligence program, incorporating tactical and strategic threat feeds.Align SOC operations with evolving business risk priorities and regulatory frameworks.Platform & Toolset Management
Evaluate, implement, and enhance SIEM platforms, ensuring optimal log ingestion, correlation, and rule effectiveness.Assess and manage deployment of EDR, XDR, SOAR, and Threat Intelligence solutions.Maintain and update incident response playbooks and automation workflows.Ensure consistent platform hygiene and technology stack effectiveness across SOC tooling.SOC Operations & Threat Detection
Oversee 24x7 monitoring of security events and alerts across enterprise assets.Lead and coordinate proactive threat hunting across networks, endpoints, and cloud.Manage and support forensic investigations to identify root cause and recovery paths.Govern use case development, log source onboarding, and alert/event triage processes.Regulatory Compliance & Incident Management
Ensure timely and accurate incident reporting in compliance with RBI, CERT-In, and other authorities.Retain logs in accordance with regulatory data retention mandates.Enforce and monitor security baselines for endpoints, in line with internal and regulatory standards.Advanced Threat Management & Reporting
Plan, conduct, and report on Red Teaming and Purple Teaming exercises to test detection and response capabilities.Participate in and contribute to the Risk Operations Committee (ROC) meetings and initiatives.Review and track SOC effectiveness through KPIs, metrics, and regular reporting dashboards.


Required education
Bachelor's Degree

Preferred education
Master's Degree

Required technical and professional expertise

Bachelor’s or Master’s degree in Cybersecurity, Computer Science, or related field.3-7 years of experience in SOC management, incident response, or cyber threat detection roles.Hands-on expertise with SIEM (e.g., Splunk, QRadar, Sentinel), EDR/XDR tools, and SOAR platforms.Proven experience in playbook development, forensics, and threat hunting methodologies.Strong understanding of RBI/CERT-In incident reporting guidelines and log retention requirements.Familiarity with MITRE ATT&CK, threat modeling, and adversary emulation techniques.


Preferred technical and professional experience

Preferred Certifications:
GCIA, GCIH, GCFA, CISSP, OSCP, CEH, CHFI, or similar certifications"

Employment Type: Full Time, Permanent

Read full job description

Prepare for Your IBM Interview with Real Experiences!

View interviews
Office worker

What people at IBM are saying

What IBM employees are saying about work life

based on 23.7k employees
77%
85%
66%
79%
Flexible timing
Monday to Friday
No travel
Day Shift
View more insights

IBM Benefits

Submitted by Company
Flexible Work Options
Medical Plans
Volunteering Rewards
Submitted by Employees
Work From Home
Soft Skill Training
Health Insurance
Job Training
Cafeteria
Free Transport +6 more
View more benefits

Compare IBM with

Oracle

3.7
Compare

TCS

3.6
Compare

Cognizant

3.7
Compare

Accenture

3.7
Compare

Infosys

3.6
Compare

Capgemini

3.7
Compare

Wipro

3.7
Compare

Deloitte

3.7
Compare

Google

4.4
Compare

Amazon

4.0
Compare

Amdocs

3.7
Compare

SAP

4.2
Compare

Microsoft Corporation

3.9
Compare

Tech Mahindra

3.5
Compare

PwC

3.3
Compare

Ernst & Young

3.4
Compare

Nagarro

3.9
Compare

NetApp

3.8
Compare

Salesforce

4.0
Compare

SAS

4.1
Compare

Similar Jobs for you

Security Analyst at IBM India Pvt. Limited

Bangalore / Bengaluru

3-7 Yrs

Not Disclosed

Technical Analyst at IBM India Pvt. Limited

Bangalore / Bengaluru

2-7 Yrs

Not Disclosed

Security Analyst at IBM India Pvt. Limited

Bangalore / Bengaluru

2-7 Yrs

Not Disclosed

Security Specialist at IBM India Pvt. Limited

Bangalore / Bengaluru

3-5 Yrs

Not Disclosed

Cyber Security Lead at iLink Digital

Chennai

7-12 Yrs

₹ 15-25 LPA

Cyber Security Engineer at PRUDENT GLOBALTECH SOLUTIONS PRIVATE LIMITED

Hyderabad / Secunderabad

4-9 Yrs

Not Disclosed

Cyber Security Engineer at PRUDENT GLOBALTECH SOLUTIONS PRIVATE LIMITED

Hyderabad / Secunderabad

1-4 Yrs

Not Disclosed

SOC Analyst at UST GLOBAL TECHNOLOGY SERVICES

Kochi, Chennai + 1

8-13 Yrs

Not Disclosed

Engineer at Capgemini Technology Services India Limited

Bangalore / Bengaluru

5-10 Yrs

Not Disclosed

Cyber Security Engineer at iLink Digital

Chennai

7-12 Yrs

Not Disclosed

IBM Bangalore / Bengaluru Office Locations

View all
Bangalore Office
Headquarter
IBM India Pvt Ltd, No. 4/1, Tower D, 2nd & 3rd Floor, Dairy Circle, Bannerghatta Main Road Bangalore
Karnataka 560029
Bengaluru Office
IBM, No.12, Subramanya Arcade, Bannerghatta Road Bengaluru
Karnataka 560029

XDR Analyst - L2

3-7 Yrs

Bangalore / Bengaluru

Cyber Security, RBI, Penetration Testing +13 more

5 days ago·via naukri.com

PROCESS DELIVERY SPECIALIST-TALENT DEVELOPMENT OPTIMIZATION -ANALYST

3-5 Yrs

₹ 2.9L/yr - 7.1L/yr (AmbitionBox estimate)

Bangalore / Bengaluru

HRIS, Recruitment, Human Resource Management +11 more

1 day ago·via naukri.com

Sr. Process Analyst - Finance & Administration Delivery

3-6 Yrs

Mumbai

Finance, Accounting, Tally +11 more

1 day ago·via naukri.com

Assistant Manager - Finance & Administration Delivery

6-11 Yrs

Noida

Finance, Accounting, Financial Analysis +13 more

1 day ago·via naukri.com

Sr. Process Analyst - Finance & Administration Delivery

3-6 Yrs

₹ 2.2L/yr - 7.5L/yr (AmbitionBox estimate)

Bangalore / Bengaluru

Finance, Accounting, Tally +11 more

1 day ago·via naukri.com

NodeJS Developer - 5-8 years, Nodejs, DSA, JavaScript, Kubernetes

5-10 Yrs

Bangalore / Bengaluru

Digital Marketing, AWS, Java +17 more

1 day ago·via naukri.com

PROCESS DELIVERY SPECIALIST-TALENT DEVELOPMENT -ANALYST

3-5 Yrs

₹ 2.9L/yr - 7.1L/yr (AmbitionBox estimate)

Bangalore / Bengaluru

HRIS, Recruitment, Human Resource Management +11 more

1 day ago·via naukri.com

PROCESS DELIVERY SPECIALIST-LEAD To CASH

4-7 Yrs

₹ 4.5L/yr - 6L/yr (AmbitionBox estimate)

Bangalore / Bengaluru

Finance, Customer Service, Project Management +11 more

1 day ago·via naukri.com

Ceph L3 Engineer - Pune

6-11 Yrs

Pune

DevOps, Python, AWS +20 more

2 days ago·via naukri.com

CPU Verification Manager

12-17 Yrs

Bangalore / Bengaluru

Digital Marketing, DevOps, Python +20 more

2 days ago·via naukri.com
write
Share an Interview