SOC & MSS Consultant - SOC L2
Posted Aug 25, 2026
About the Role
The SOC L2 - SOC & MSS Consultant is responsible for hands-on operation, tuning, and continuous improvement of the security stack deployed for iConnect's managed clients. The role owns SIEM use-case tuning, SOAR playbook/workflow engineering, EDR/AV platform administration, email security operations, and DLP/data classification programs - while supporting L1 escalations and driving incident response quality across the client base.
Responsibilities
SIEM Operations & Fine-Tuning (primary platform: FortiSIEM; Splunk, QRadar or Microsoft Sentinel an advantage)
- Tune correlation rules and thresholds to reduce false positives/negatives across client tenants.
- Build and maintain custom parsers for new/unsupported log sources.
- Onboard new log sources, agents and collectors; validate log flow and event mapping.
- Maintain use-case coverage mapped to MITRE ATT&CK; identify and close detection gaps.
- Build dashboards, reports and health-check views for client and internal SOC use.
SOAR - Workflow & Playbook Development (primary platform: FortiSOAR; Shuffle an advantage)
- Design, build and maintain automated playbooks for triage, enrichment, containment and notification.
- Integrate SOAR with SIEM, EDR, email security, ticketing and ITSM tools.
- Automate repetitive L1 triage steps to reduce mean-time-to-respond (MTTR).
- Maintain playbook version control, testing and documentation.
EDR / Antivirus Platform Management
- Deploy, configure and manage EDR/AV agents across managed client endpoints and servers.
- Tune detection policies, exclusions and response actions to minimise noise without reducing coverage.
- Investigate EDR alerts, perform root-cause analysis and execute containment (isolate host, kill process, quarantine file).
- Conduct proactive threat hunting using EDR telemetry.
Email Security Operations
- Administer and tune email security gateways: anti-spam, anti-phishing, anti-malware, impersonation protection.
- Investigate suspicious emails - header analysis, sandbox verdicts, URL/attachment triage.
- Manage quarantine, allow/block lists and policy exceptions across client tenants.
- Configure and monitor SPF, DKIM and DMARC; support brand protection initiatives.
DLP & Data Classification
- Configure and maintain DLP policies across endpoint, email and cloud channels.
- Support clients in building data classification taxonomies (Public, Internal, Confidential, Restricted).
- Investigate DLP incidents and potential data exfiltration; recommend policy refinements.
Incident Response & SOC Monitoring
- Perform L2 investigation and validation of alerts escalated by L1 analysts.
- Lead incident response within defined runbooks; document timelines and findings.
- Support post-incident reviews and continuous improvement of detection content.
- Ensure SLA adherence for detection, escalation and closure across all managed clients.
Client & MSS Delivery
- Operate across multiple client tenants/environments in a managed services model.
- Produce client-facing reports: incident summaries, health checks, tuning recommendations.
- Support onboarding of new MSS clients - log source integration, policy baseline, playbook setup.
- Coordinate with Presales and Professional Services on scope, HLDs and change requests.
Requirements
- Bachelor's degree in Computer Science, Information Security or a related field.
- 3-5 years of SOC experience, including a minimum of 2 years operating at L2 level.
- Hands-on experience fine-tuning at least one enterprise SIEM (FortiSIEM strongly preferred).
- Hands-on experience building playbooks/workflows in a SOAR platform (FortiSOAR preferred).
- Practical experience managing EDR/AV platforms in a multi-client or enterprise environment (Bitdefender GravityZone required; CrowdStrike, SentinelOne or Microsoft Defender for Endpoint an advantage).
- Practical experience administering an email security gateway (FortiMail, Proofpoint or Mimecast).
- Working knowledge of DLP concepts and data classification frameworks (Microsoft Purview, Proofpoint DLP or equivalent preferred).
- Solid understanding of the MITRE ATT&CK framework and incident response methodology.
- Comfortable working rotational shifts in a 24x7 managed services environment.
- Strong documentation and client communication skills.
Qualifications
Preferred / nice to have
- Scripting ability (Python or PowerShell) for automation and log parsing.
- Exposure to Microsoft 365 Defender, Entra ID and Intune in a security operations context.
- Exposure to PAM/PRA platforms (BeyondTrust) and vulnerability management tooling.
- Certifications: NSE4+ (Fortinet), CompTIA Security+ / CySA+, GCIH or equivalent.
What we offer
- Hands-on exposure to a full enterprise security stack across multiple industries and clients.
- Direct involvement in SOC platform engineering, not just alert monitoring.
- Career growth toward SOC L3, Detection Engineering or Security Architecture.