
Senior SOC Analyst
- Manila City, Metro Manila
- Permanent
- Full-time
- Monitor SIEM, EDR, and other security tools for detection and identification of security events
- Document security investigations in a clear and consistent manner
- Develop new use cases for security alerts
- Tune existing use cases to improve accuracy
- Tune endpoint and network security tools as needed
- Perform threat hunting to identify potential security threats
- Perform vulnerability and threat intelligence research
- Review threat intelligence reports
- Ability to work after hours if needed
- Perform security anomaly and event detection
- Investigate, contain, and resolve security anomalies and events
- Perform threat attribution
- Identification of likely threat vector for security events and incidents
- Ability to read, write, speak and understand the English language to communicate with employees, customers, suppliers, in person, on the phone, and by written communications in a clear, straightforward, and professional manner
- Experience working with multiple SIEM, EDR, Log Aggregators, and Incident Response Management solutions
- Strong technical knowledge of Networking, Operating Systems, and enterprise integrations
- Firm understanding of the security incident lifecycle
- Thorough understanding of TCP/IP
- Understand IDS / IPS rules to identify and/or prevent malicious activity
- Basic knowledge of forensic methodologies and best practices to investigate intrusions, preserve evidence and coordinate a unified security response
- Ability to proactively perform threat hunting to identify undetected security events
- Basic knowledge of malware analysis
- Basic understanding of SQL
- Understanding of Packet Analysis (PCAP) and Packet Analysist software
- Bachelor’s degree in Cybersecurity, Computer Engineering, Information Technology, or related field.
- Candidate will possess ability to be a successful self-starter
- Understanding of Advanced Persistent Threats
- Experience with Python, PowerShell, and API programming is a plus
- Understanding of the VERIS and MITRE ATT&CK frameworks is a plus