SOC Analyst (L2)

HybridSalary not specified
Romania

Tech Stack

Splunk

Job Description, Responsibilities & Requirements

About the Position

JOIN OUR TEAM

At Levi Nine we are passionate about what we do. We love our work and together in a team we are smarter and stronger. We work in a dynamic and challenging environment with talented and forward-thinking people who are part of creative and innovative teams. We are looking for skilled team players who make change happen. Are you one of these players?

OUR PARTNER:

Our partner, ABN AMRO Clearing, is a global leader in the domain of clearing, offering access to a wide range of listed instruments on markets across the globe.

IT is at the heart of their organization with more than 30 different product teams and 10 different platform teams that are trying to build the best products & services for their customers.

Their presence in important financial centers like Amsterdam, Chicago, Sydney, Singapore, Tokyo Hong Kong, London, Sao Paulo, Frankfurt and Iasi, allows them to effectively serve clients worldwide and maintain close proximity to their diverse customer base.

THE ROLE INVOLVES:

As a SOC Analyst (L2), you focus on detection engineering and incident investigation, working hands-on with Splunk Enterprise Security.

You contribute to a SOC in a build-up phase, helping shape detection engineering practices, playbooks, and processes.

Detection engineering is your primary focus, while investigations help continuously improve detection quality.

You will also contribute to the adoption of Detection as Code (DaC) practices, where detections are treated as structured, version-controlled, and reusable assets.

You work closely with the Senior L3 Detection Lead to implement detection use cases, improve coverage, and contribute to a structured detection engineering lifecycle.

Responsibilities

  • Investigate alerts escalated from L1 analysts.
  • Build and improve detection use cases in Splunk ES.
  • Tune alerts to improve quality and reduce false positives.
  • Develop and maintain detection & response playbooks.
  • Apply Detection as Code principles.
  • Contribute to version-controlled detection content.
  • Identify detection gaps and propose improvements.
  • Support threat hunting activities and translate findings into detections.
  • Collaborate with L3 to refine detection logic and standards.

Requirements

  • Experience: 3-5 years in SOC / incident response / blue team roles
  • Technical Skills:
    • Hands-on experience with SIEM (preferably Splunk ES)
    • Experience handling Tier 2 investigations
    • Strong understanding of detection engineering and use case development
    • Familiarity with MITRE ATT&CK framework
    • Ability to analyze logs across endpoint, network, and cloud environments
  • Soft Skills:
    • Fluent English, with good written and verbal communication skills
    • Strong analytical and investigative mindset
    • Ability to work under pressure
    • Clear communication and structured documentation
    • Proactive and improvement-driven approach

Nice to Have

  • Certifications such as the following would be desirable but not mandatory: GCIH, GDAT, GCDA, GISP, OSDA, CCFR, SC-900, SC-200, Splunk
  • Basic automation/scripting experience
  • Interest in detection engineering frameworks and best practices
  • A keen interest in cyber security and a desire to learn more and improve the current way of working
  • Relevant university degree in Computer Science, Engineering, or a related field

We Offer

  • Location: Hybrid remote (Iasi, Romania or Remote)
  • Categories: SOC, Cybersecurity, MITRE, Splunk

About the Company

Amanda Andriesanu

Delivery Director

Amanda Andriesanu brings over 20 years of experience in software service delivery across diverse industries, including telecom, banking, automotive, and education. With a proven track record of building strong client relationships and leading technology teams in complex business environments, Amanda excels at finding clarity in complexity. She strives to balance just the right amount of ambiguity with predictability, ensuring people and actions align with a meaningful purpose.

Anca Dana Gafiteanu

Delivery Centre Director

Anca Gafiteanu is the Delivery Centre Director at Levi9, overseeing operations in Romania.

With over 15 years of experience in IT and leadership, Anca specializes in managing large-scale delivery teams, driving operational excellence, and fostering collaborative cultures. Anca’s commitment to innovation and her passion for developing talent make her our invaluable leader at Levi9.

Job Details

Company name:
Levi9
Location:
Romania
Work Mode:
Hybrid
Posted on TheJob:
Jul 14, 2026
Last checked:
Jul 14, 2026
Apply Now
© 2026 TheJob, Inc. All rights reserved.