(ACTIVE) I SIEM Platform Engineer (SIEM & SOAR) I Hybrid in Cubao

Gratitude Philippines

Manila

Hybrid

PHP 900,000 - 1,700,000

Full time

5 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Day 1 HMO and Life Insurance coverage
13th Month Pay
Performance bonus
Company-sponsored training
Flexible working arrangements
Employee Stock Purchase Plan
Expanded maternity/paternity benefits

Job summary

Gratitude Philippines is seeking a SIEM Platform Engineer (SIEM & SOAR) to design, implement, and optimize security monitoring and automation platforms. The role focuses on threat visibility, detections, and automated incident response within a hybrid setup at Cubao, Quezon City.

The candidate should have 3+ years of hands-on SIEM/SOAR experience, with familiarity in SOC environments and with platforms like Splunk, Microsoft Sentinel, Google SecOps, or QRadar.

Qualifications

  • 3+ years hands-on experience in SIEM and/or SOAR engineering or administration.
  • SOC environment experience preferred.
  • Experience with a major SIEM platform (Splunk, QRadar, etc.).
  • Scripting experience in Python, PowerShell, or Bash.
  • Familiar with security frameworks MITRE ATT&CK, NIST, or CIS.
  • Knowledge of EDR/XDR, IDS/IPS, firewalls and cloud security.
  • Strong analytical and problem-solving skills.

Responsibilities

  • Design, implement, configure, and optimize SIEM platforms.
  • Develop correlation rules, dashboards, alerts, and reports.
  • Integrate security data from networks, endpoints, cloud environments, and applications.
  • Build and maintain automated security response workflows with SOAR.
  • Create playbooks for alert triage and incident response.
  • Support security operations and incident response activities.

Skills

SIEM engineering
SOAR tooling
SOC experience
Python/PowerShell/Bash
MITRE ATT&CK/NIST/CIS
EDR/XDR/cloud security
Troubleshooting

Tools

Splunk
Microsoft Sentinel
Google SecOps
IBM QRadar
ArcSight

Job description

SIEM Platform Engineer (SIEM & SOAR)

Work Setup: Hybrid – Cubao, Quezon City
Work Shift: Shifting
Salary: Confidential

Job Overview

We are looking for a SIEM Platform Engineer (SIEM & SOAR) to design, implement, optimize, and support security monitoring and automation platforms. The role will focus on improving threat visibility, developing security detections, automating incident response workflows, and strengthening security operations.

Key Responsibilities
SIEM Engineering
  • Design, implement, configure, and optimize SIEM platforms such as Google SecOps, Splunk, IBM QRadar, Microsoft Sentinel, and Elastic.
  • Develop and maintain correlation rules, dashboards, alerts, and security reports.
  • Integrate security data from networks, endpoints, cloud environments, and applications.
  • Improve data parsing, quality, normalization, and ingestion to enhance detection accuracy.
  • Monitor and optimize SIEM performance and security data pipelines.
SOAR & Security Automation
  • Build and maintain automated security response workflows using SOAR platforms such as Cortex XSOAR, Splunk SOAR, IBM Resilient, and Google SecOps SOAR.
  • Develop and maintain playbooks for alert triage, incident response, and threat intelligence enrichment.
  • Automate repetitive SOC processes and integrate security tools to improve operational efficiency.
  • Continuously enhance security automation workflows based on operational requirements.
Security Operations Support
  • Support incident response activities through actionable detections and automated workflows.
  • Investigate recurring security issues and implement long-term engineering solutions.
  • Collaborate with compliance, audit, IT, and security teams to strengthen security controls and processes.
  • Support continuous improvement of security monitoring and response capabilities.
Requirements
  • Minimum 3 years of hands-on experience in SIEM and/or SOAR engineering or administration.
  • Experience working in a Security Operations Center (SOC) environment is preferred.
  • Hands-on experience with at least one major SIEM platform such as Google SecOps, Splunk, Microsoft Sentinel, IBM QRadar, ArcSight, or similar.
  • Experience developing SOAR playbooks and security automation workflows.
  • Scripting experience with Python, PowerShell, or Bash.
  • Knowledge of security frameworks such as MITRE ATT&CK, NIST, or CIS Controls.
  • Familiarity with EDR/XDR, IDS/IPS, firewalls, threat intelligence platforms, and cloud security technologies.
  • Strong analytical, troubleshooting, and problem‑solving skills.
Work Arrangement
  • Hybrid work arrangement.
  • Office location: Cubao, Quezon City.
  • Must be amenable to shifting schedules.
  • Applicants must currently be in the Philippines and have the legal right to live and work in the country.
Benefits & Perks
  • Competitive salary package.
  • Performance bonus and 13th Month Pay.
  • Day 1 HMO and Life Insurance coverage.
  • Flexible working arrangements.
  • Company-sponsored training, upskilling, and certifications.
  • Expanded maternity and paternity benefits.
  • Employee Stock Purchase Plan.
  • Inclusive and collaborative work culture.
Recruitment Process
  1. Screening with CV Reviewer.
  2. Endorsement for validation and further CV screening through Workday, including the HRI Toolkit, FCV, and CV.
  3. Client review.
Pre-Screening Questions
  1. How many years of relevant hands-on experience do you have in SIEM and/or SOAR engineering or administration?
  2. Do you have hands‑on experience with at least one major SIEM platform such as Google SecOps, Splunk, Microsoft Sentinel, QRadar, or ArcSight?
  3. On a scale of 1–10, with 10 being the highest, how would you rate your scripting experience in Python, PowerShell, or Bash?
  4. What was your last drawn salary?
  5. What is your expected salary?
  6. Are you amenable to working in a hybrid setup with a shifting schedule in Cubao, Quezon City?
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SIEM Platform Engineer (SIEM & SOAR)
SIEM Platform Engineer (SIEM & SOAR)

Gratitude Philippines • Manila

Hybrid
PHP 800,000 - 1,600,000
Competitive salary package
Performance bonus and 13th Month Pay
Day 1 HMO and Life Insurance coverage
+5
SIEM Platform Engineer (SIEM & SOAR)
SIEM Platform Engineer (SIEM & SOAR)

Gratitude Philippines • Philippines

Hybrid
PHP 900,000 - 1,300,000
Security Engineer – SIEM/SOC Specialist
Security Engineer – SIEM/SOC Specialist

Gratitude Philippines • Quezon City

On-site
PHP 900,000 - 1,300,000
(ACTIVE) Security Engineer (SIEM & SOAR) | Onsite/ Hybrid in QC
(ACTIVE) Security Engineer (SIEM & SOAR) | Onsite/ Hybrid in QC

Gratitude Philippines • Manila

Hybrid
PHP 700,000 - 1,000,000
Security Engineer (SIEM & SOAR) | Associate Manager
Security Engineer (SIEM & SOAR) | Associate Manager

Gratitude Philippines • Manila

Hybrid
PHP 1,200,000 - 1,800,000
Security Engineer – SIEM / SOC (Cybersecurity)
Security Engineer – SIEM / SOC (Cybersecurity)

Gratitude Philippines • Quezon City

On-site
PHP 900,000 - 1,300,000
Security Engineer (SIEM & SOAR) | Specialist / Team Lead
Security Engineer (SIEM & SOAR) | Specialist / Team Lead

Gratitude Philippines • Philippines

Hybrid
PHP 1,800,000 - 2,400,000
Hybrid work arrangement
Cubao office location
Shifting schedules
SECURITY ENGINEER (SIEM & SOAR) | SPECIALIST / TEAM LEAD
SECURITY ENGINEER (SIEM & SOAR) | SPECIALIST / TEAM LEAD

Gratitude Philippines • Cebu City

On-site
PHP 900,000 - 1,500,000
Security Engineer (SIEM & SOAR) | Specialist / Team Lead
Security Engineer (SIEM & SOAR) | Specialist / Team Lead

Gratitude Philippines • Manila

Hybrid
PHP 900,000 - 1,300,000
Hybrid work setup
Security Engineer
Security Engineer

JetSon Manpower Agency • Manila

Hybrid