SIEM Platform Engineer (SIEM & SOAR)
Work Setup: Hybrid – Cubao, Quezon City
Work Shift: Shifting
Salary: Confidential
Job Overview
We are looking for a SIEM Platform Engineer (SIEM & SOAR) to design, implement, optimize, and support security monitoring and automation platforms. The role will focus on improving threat visibility, developing security detections, automating incident response workflows, and strengthening security operations.
Key Responsibilities
SIEM Engineering
- Design, implement, configure, and optimize SIEM platforms such as Google SecOps, Splunk, IBM QRadar, Microsoft Sentinel, and Elastic.
- Develop and maintain correlation rules, dashboards, alerts, and security reports.
- Integrate security data from networks, endpoints, cloud environments, and applications.
- Improve data parsing, quality, normalization, and ingestion to enhance detection accuracy.
- Monitor and optimize SIEM performance and security data pipelines.
SOAR & Security Automation
- Build and maintain automated security response workflows using SOAR platforms such as Cortex XSOAR, Splunk SOAR, IBM Resilient, and Google SecOps SOAR.
- Develop and maintain playbooks for alert triage, incident response, and threat intelligence enrichment.
- Automate repetitive SOC processes and integrate security tools to improve operational efficiency.
- Continuously enhance security automation workflows based on operational requirements.
Security Operations Support
- Support incident response activities through actionable detections and automated workflows.
- Investigate recurring security issues and implement long-term engineering solutions.
- Collaborate with compliance, audit, IT, and security teams to strengthen security controls and processes.
- Support continuous improvement of security monitoring and response capabilities.
Requirements
- Minimum 3 years of hands-on experience in SIEM and/or SOAR engineering or administration.
- Experience working in a Security Operations Center (SOC) environment is preferred.
- Hands-on experience with at least one major SIEM platform such as Google SecOps, Splunk, Microsoft Sentinel, IBM QRadar, ArcSight, or similar.
- Experience developing SOAR playbooks and security automation workflows.
- Scripting experience with Python, PowerShell, or Bash.
- Knowledge of security frameworks such as MITRE ATT&CK, NIST, or CIS Controls.
- Familiarity with EDR/XDR, IDS/IPS, firewalls, threat intelligence platforms, and cloud security technologies.
- Strong analytical, troubleshooting, and problem‑solving skills.
Work Arrangement
- Hybrid work arrangement.
- Office location: Cubao, Quezon City.
- Must be amenable to shifting schedules.
- Applicants must currently be in the Philippines and have the legal right to live and work in the country.
Benefits & Perks
- Competitive salary package.
- Performance bonus and 13th Month Pay.
- Day 1 HMO and Life Insurance coverage.
- Flexible working arrangements.
- Company-sponsored training, upskilling, and certifications.
- Expanded maternity and paternity benefits.
- Employee Stock Purchase Plan.
- Inclusive and collaborative work culture.
Recruitment Process
- Screening with CV Reviewer.
- Endorsement for validation and further CV screening through Workday, including the HRI Toolkit, FCV, and CV.
- Client review.
Pre-Screening Questions
- How many years of relevant hands-on experience do you have in SIEM and/or SOAR engineering or administration?
- Do you have hands‑on experience with at least one major SIEM platform such as Google SecOps, Splunk, Microsoft Sentinel, QRadar, or ArcSight?
- On a scale of 1–10, with 10 being the highest, how would you rate your scripting experience in Python, PowerShell, or Bash?
- What was your last drawn salary?
- What is your expected salary?
- Are you amenable to working in a hybrid setup with a shifting schedule in Cubao, Quezon City?