Cyber Defence - Global Security Operations Centre (GSOC) Level 2 Analyst

Willis Towers Watson

Pateros

On-site

PHP 600,000 - 900,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Willis Towers Watson in the Philippines is seeking a L2 Security Operations Center analyst to monitor, triage, and investigate potential incidents, helping to continuously improve processes against evolving threats.

You will triage incidents using SIEM, UEBA, and EDR, coordinate with technical teams and business stakeholders, and mentor junior analysts while leading shift activities.

Qualifications

  • 4 - 5 years’ experience in a mature cyber defence centre or SOC.
  • Ability to troubleshoot security issues and communicate clearly with stakeholders.
  • Effectively manage time and complete tasks within shifts.
  • Hands-on experience using SIEM, UEBA, and EDR as a security analyst.
  • Lead investigations and collaborate with stakeholders for resolution.

Responsibilities

  • Investigate security incidents, detect threats via log analysis, using SIEM/UEBA/EDR.
  • Ensure timely response to incidents, coordinating with technical teams and stakeholders.
  • Act as escalation point for L1 analysts, perform root cause analysis and containment actions.
  • Escalate high-severity incidents to the appropriate team per process.
  • Preserve integrity of security data for incident analysis, to determine impact and scope.
  • Provide process and technical guidance to L1 analysts as needed.
  • Lead shift workload and prepare end-of-shift reports to leadership.
  • Lead handover calls to communicate updates and pending tasks to the next shift.
  • Perform quality audits on tickets to ensure adherence to processes.
  • Recommend alert tuning to reduce false positives and improve security posture.

Skills

SIEM
EDR
UEBA
Log analysis
Incident response
Communication
Shift leadership

Tools

SIEM
UEBA
EDR

Job description

As part of the Cyber Defence team in the Global Security Operations Centre, you will provide security monitoring, triage, and investigation of potential incidents, and help to constantly improve the ways that the team works so that we can keep up with the latest threats against our business.

Fast and effective identification and triage of potential incidents is essential for us to protect our critical data and assets, and you will be at the forefront of this exciting area of Cyber Security, protecting the business and our interests daily.

You will need to have a good technical aptitude, a calm approach under pressure, excellent communicative skills to technical and nontechnical audiences, and have a genuine passion for security.

Key Responsibilities
  • Perform investigations on security incidents, detect potential threats via log analysis, and leverage tools including SIEM, UEBA, and EDR.
  • Ensure that there is a timely response to any cyber incidents to minimize the impact to the business, including interacting with different technical teams and business stakeholders where needed.
  • Act as the primary escalation point of L1 analyst for complex incidents, performing investigations and root cause analysis, initiating containment actions, and collaborating with L3 analysts and other teams as required.
  • Escalate high/critical severity incidents to the appropriate escalations team according to the established process.
  • Safely acquire and preserve the integrity of cyber security data required for incident analysis to help determine the technical/operational impact, root cause(s), scope, and nature of incidents.
  • Escalation point to provide process and/or technical advice for L1 analyst.
  • The L2 analyst also acts as a shift lead, managing shift workload to ensure incidents and tasks are appropriately assigned and handled within the shift.
  • L2 analyst is also responsible in preparing and send the end of shift report to Leadership team.asnldasl,mhjklhwsjkfhkl;wjflkl;asd
  • Lead and document handover calls to ensure all updates, unassigned tickets, pending tasks, and ongoing investigations are effectively communicated to the next shift.
  • Perform quality audit for tickets that were handled by L1 analysts to ensure incidents were handled in accordance to established processes.
  • Recommend alert/s for tuning to minimize false positives and improve the businesses’ security posture against threat actors.
  • Contribute to SOC process maturity and continuous improvement by creating and updating process documentation and knowledge base content, and by enhancing alerts through tuning activities.
  • Provide in-shift guidance, training, and mentorship to help new joiners and L1 analysts develop operational skills
The Requirements
  • Work as part of a 24/7 SOC across multiple locations, requiring strong teamwork and the ability to collaborate with internal stakeholders and colleagues to consistently deliver exceptional service and support.
  • 4 - 5 Years’ Experience working as part of a mature cyber defence centre or security operations centre.
  • Ability to troubleshoot and research security issues effectively, and communicate clearly with technical and non-technical stakeholders, maintaining professionalism.
  • Effectively manage time and reliably complete assigned tasks/incidents within shift.
  • Hands on experience of using a SIEM, UEBA, and EDR as a security analyst.
  • Lead investigations and collaborate with business stakeholders to ensure thorough analysis and resolution of security alerts and incidents
Beneficial:
  • Any relevant security certifications (SC-200, SC-900, Security+, CySA+, CASP+, etc.).
  • Any relevant network certifications (Network +, CCNA, etc.).
  • Knowledge of other key IT fields (such as Web Applications Firewall, databases, Active Directory, data loss protection, EDR Solutions, SIEM, network security systems such as web proxies, and firewalls)

WTW is an Equal Opportunity Employer

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Analyst, Cyber Security Operations
Senior Analyst, Cyber Security Operations

Melco Resorts & Entertainment • Manila

On-site
PHP 900,000 - 1,300,000
Security Analyst / Network Security Analyst
Security Analyst / Network Security Analyst

RippedBoxStation • Philippines

On-site
PHP 260,000 - 420,000
Cybersecurity Operations Analyst
Cybersecurity Operations Analyst

UL Solutions • Makati

On-site
PHP 600,000 - 900,000
Security Operations Center (SOC) - Head
Security Operations Center (SOC) - Head

SMITS, Inc. - IT Company of San Miguel Corporation • Mandaluyong

On-site
PHP 900,000 - 1,600,000
Junior SOC Analyst
Junior SOC Analyst

Kinettix Inc. • Manila

On-site
Cybersecurity Analyst
Cybersecurity Analyst

ContactPoint360 • Cebu City

On-site
PHP 900,000 - 1,300,000
IT Security Analyst
IT Security Analyst

Ibex Limited • Davao del Sur

On-site
PHP 480,000 - 840,000
IT Security Analyst
IT Security Analyst

IBEX Global Solutions (Philippines) Inc. • Davao del Sur

On-site
PHP 420,000 - 560,000
Senior Security Engineer – SOC
Senior Security Engineer – SOC

42 Gears Mobility Systems • Hinoba-an

On-site
PHP 995,000 - 1,592,000
SOC L3 Analyst Lead
SOC L3 Analyst Lead

KPMG R.G. Manabat & Co. • Philippines

On-site
PHP 1,800,000 - 3,400,000
HMO with 2 Free Dependents
Communication Allowance
Rice Allowance
+10