
at Capgemini
ConsultanciesPosted 4 days ago
No clicks
**Senior Cybersecurity Consultant - SOC L2 Engineer: Advance, Investigate, and Automate** Drive advanced cybersecurity in Capgemini's global team. Seasoned professional required (3-6 years) to: - Investigate incidents, analyze threats, and assess severity across cloud and on-premise environments. - Identify attack patterns, recommend containment, and perform root cause analysis. - Build and optimize Microsoft Sentinel detection use cases, reduce false positives. - Collaborate across teams (Threat Intelligence, DFIR, DLP) and mentor SOC L1 analysts. - Leverage Azure AI Foundry to develop AI-assisted triage, incident classification models, and zero-touch response playbooks. - Experience with Microsoft Sentinel, Defender XDR, Azure Monitor, KQL, Log Analytics, MITRE ATT&CK, and detection engineering. - Preferred certifications: GCIH, GCDA, AZ-500, SC-200, CEH. As a responsible, diverse global team, Capgemini empowers employees to shape their careers and deliver AI-powered transformation to leading organizations.
- Compensation
- Not specified
- City
- Not specified
- Country
- Not specified
Currency: Not specified
Full Job Description
Choosing Capgemini means choosing a company where you will be empowered to shape your career in the way youd like, where youll be supported and inspired by a collaborative community of colleagues around the world, and where youll be able to reimagine whats possible. Join us and help the worlds leading organizations unlock the value of technology and build a more sustainable, more inclusive world.
Job Description
Experience 3-6 Years
Role Overview
The SOC L2 Engineer performs advanced investigations, incident analysis, threat correlation, containment recommendations, and detection engineering activities. The role is expected to contribute towards AI-driven SOC modernization initiatives and Sentinel content development.
Key Responsibilities
Conduct advanced incident investigations and correlation analysis.
Perform severity assessment and impact analysis.
Identify attack patterns across cloud and on-premise environments.
Recommend containment and remediation actions.
Execute root cause analysis and lessons learned activities.
Build and tune Microsoft Sentinel detection use cases.
Reduce false positives through detection optimization.
Develop and maintain automation runbooks and playbooks.
Collaborate with Threat Intelligence, Threat Hunting, DFIR, and DLP teams.
Mentor SOC L1 analysts.
Participate in major incident response activities.
Job Description - Grade Specific
Technical Skills
Microsoft Sentinel SIEM/SOAR
Defender XDR
Azure Monitor
KQL
Log Analytics
MITRE ATT&CK
Detection Engineering
Incident Response
Threat Correlation
Cloud Security Monitoring
AI & Automation Requirements
Experience with Azure AI Foundry.
Develop AI-assisted triage workflows.
Build automated incident classification models.
Design zero-touch response playbooks.
Develop AI-powered investigation workflows.
Implement GenAI-assisted analyst productivity use cases.
Certifications (Preferred)
GCIH
GCDA
AZ-500
SC-200
CEH
Capgemini is an AI-powered global business and technology transformation partner, delivering tangible business value. We imagine the future of organizations and make it real with AI, technology and people. With our strong heritage of nearly 60 years, we are a responsible and diverse group of 420,000 team members in more than 50 countries. We deliver end-to-end services and solutions with our deep industry expertise and strong partner ecosystem, leveraging our capabilities across strategy, technology, design, engineering and business operations. The Group reported 2024 global revenues of €22.1 billion.
Make it real | www.capgemini.com




