The Cybersecurity Analyst is responsible for monitoring. detecting investigating, and responding to cyber security threats across the organization's environment. The role combines Security Operations, Incident Response, Threat Intelligence, Vulnerability Management, Governance, Risk & Compliance, and Security Awareness responsibilities.
Duties and Responsibilities:
1. Security Operations & Incident Response
- Monitor and investigate security events across SIEM, NDR, EDR/DR, firewalls, email security, and network security platforms.
- Perform incident triage, containment, eradication, and recovery activities.
- Manage high-volume security event monitoring and threat analysis.
- Conduct root cause analysis and post-incident reviews.
- Develop and maintain detection rules, use cases, and playbooks.
2. Vulnerability & Patch Management
- Conduct vulnerability assessments, penetration testing and risk analysis.
- Track remediation activities and validate corrective actions.
- Oversee deployment and verification of security patches.
- Support third-party security assessments and audits.
3. Governance, Risk & Compliance
- Develop and maintain SOPs aligned with ISO 27001, NIST CSF/RMF, and the Data Privacy Act of the Philippines.
- Support cybersecurity governance initiatives and security maturity improvement programs.
- Participate in internal and external audits.
- Prepare technical and executive-level cybersecurity reports.
4. Threat Intelligence & Threat Hunting
- Monitor threat intelligence feeds and emerging cyber threats.
- Analyze Indicators of Compromise (IOCs) and attacker tactics, techniques, and procedures (TTPs).
- Perform proactive threat hunting activities.
5. Security Awareness
- Lead phishing simulation exercises and awareness campaigns.
- Promote cybersecurity best practices across the organization.
QUALIFICATIONS
- Bachelor's Degree in Information Technology, Computer Science, Cybersecurity, or related field
- Relevant cybersecurity certifications are an advantage
- Minimum of 2 years experience in Security Operations Center (SOC), Cybersecurity Operations, or Information Security
- Experience working with SIEM platforms such as FortiSEM, Splunk, or equivalent
- Experience in incident detection. investigation, and response
- Knowledge in Windows, Linux, Active Directory, networking, and server administration
- Understanding of common cyber attack techniques including phishing, malware, ransomware, brute force attacks, and DDoS Experience in log analysis and event correlation
- Familiar with cybersecurity frameworks and standards such as NIST CSF and ISO 27001
- Strong analytical and problem-solving skills
- Good understanding of cybersecurity concepts and incident handling prodflures
- Excellent oral and written communication skills
- Attention to detail and strong documentation skills
- Background in scripting Python, or PowerShell is an advantage
- SIEM: FortiSIEM, Splunk, QRadar, Microsoft Sentinel
- Security Analytics: FortiAnalyzer
- EDR/DR: Trend Vision One, CrowdStrike, Microsoft Defender
- NDR: Trend Micro Deep Discovery Inspector
- Vulnerability Management: Nessus, Qualys, Rapid7
- Patch Management: Action1
- Threat Intelligence: SOCRadar, Resecurity
- Compliance: ISO 27001, NIST RMF, NIST SP 800 Series
- Linux Administration and Network Security
- Google Workspace and Hybrid Infrastructure Security
Preferred Certifications:
- CompTIA Security+
- CompTIA CySA+
- ISC2 CC
- ISC2 CISSP (Preferred)
- CEH
- GIAC
WORK ARRANGEMENT: FULL ONSITE IN BGC, TAGUIG | MON - FRI