Tier 2 Cybersecurity Operations Analyst

🏢 Teladoc Health · all Teladoc Health jobs
📍 India
📅 Posted 2026-09-06 · via Himalayas
🏷 Cybersecurity-Operations,SOC-Analyst,Incident-Response,Threat-Hunting,Security-Operations,Tier-2-SOC-Analyst,SOC-Tier-2-Analyst,L2-Security-Analyst,Security-Operations-Analyst,Security-Operations-(SOC)-Analyst
Apply on original site ↗

Join the team leading the next evolution of virtual care.

At Teladoc Health , you are empowered to bring your true self to work while helping millions of people live their healthiest lives.

Here you will be part of a high-performance culture where colleagues embrace challenges, drive transformative solutions, and create opportunities for growth. Together, we’re transforming how better health happens.
Job Description

Summary of Position

The Tier 2 Cyber Security Operations Analyst is responsible for performing advanced analysis of security incidents, conducting in-depth investigations, and implementing mitigation strategies to protect organizational IT infrastructure. This role serves as an escalation point for Tier 1 analysts, requiring strong technical expertise, analytical skills, and the ability to handle complex cyber threats in a fast-paced SOC environment.

Key Responsibilities:

1. Incident Analysis and Response:

-
Investigate escalated security incidents from Tier 1, including malware infections, advanced persistent threats (APTs), phishing campaigns, and unauthorized access attempts.

-
Perform root cause analysis to identify the source, scope, and impact of incidents.

-
Implement containment, eradication, and recovery measures, such as isolating compromised systems or applying security patches.

2. Threat Hunting and Proactive Monitoring:

-
Conduct proactive threat hunting using SIEM tools and endpoint detection and response (EDR/XDR) platforms.

-
Analyze Indicators of Compromise (IoCs) and Tactics, Techniques, and Procedures (TTPs) to identify potential threats.

-
Correlate logs and alerts to detect patterns of malicious activity.

3. Security Tool Optimization:

-
Configure and fine-tune security tools, including SIEM and SOAR platform.

-
Develop and update SIEM rules, dashboards, and alerts to improve detection accuracy.

4. Documentation and Reporting:

-
Document incident details, including timelines, findings, and remediation steps, in ticketing systems.

-
Prepare detailed incident reports and post-incident reviews for management and compliance purposes.

-
Contribute to the development of standard operating procedures (SOPs) and playbooks for incident response.

5. Collaboration and Escalation:

-
Work closely with Tier 1 analysts to mentor and guide them on alert triage and basic incident handling.

-
Collaborate with Senior Analysts, threat intelligence teams, and IT departments for advanced investigations and remediation.

-
Liaise with external stakeholders, such as CERT-In or third-party vendors, during major incidents.

6. Threat Intelligence Integration:

-
Incorporate threat intelligence feeds into security monitoring processes.

-
Stay updated on emerging cyber threats, vulnerabilities, and attack trends relevant to the organization’s industry.

Skills and Qualifications:

-
Education: Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field. Relevant certifications or equivalent experience may substitute.

-
Experience: 4-7 years of experience in cybersecurity, preferably in a SOC environment or as a Tier 1 analyst. Hands-on experience with incident response is essential.

-
Technical Skills:

-
Advanced knowledge of networking protocols (TCP/IP, DNS, VPN) and operating systems (Windows, Linux, macOS).

-
Proficiency with SIEM platforms, EDR/XDR tools, and network security appliances.

-
Experience with log analysis, packet capture tools (e.g., Wireshark), and scripting (e.g., Python, PowerShell, Bash) for automation.

-
Familiarity with cloud security (e.g., AWS, Azure, Google Cloud) and related tools is a plus.

-
Understanding of attack frameworks like MITRE ATT&CK and common vulnerabilities (e.g., CVE database).

-
Certifications (preferred):

- CompTIA Security+, CISSP

- Certified Ethical Hacker (CEH)

- GIAC Certified Incident Handler (GCIH)

-
Strong problem-solving and critical-thinking skills.

-
A

← All remote jobs

Similar for you