Cybersecurity Senior Analyst

Thumbtack Philippines

Philippines

On-site

PHP 1,200,000 - 2,400,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Thumbtack Philippines seeks a Cybersecurity Senior Analyst to strengthen detection and response across cloud, SaaS, endpoints, and identity systems. You will own day-to-day security operations, tune SIEM, manage MDR partnerships, and drive automation with SOAR and detection-as-code, while collaborating with global teams to reduce risk and improve security posture.

The role emphasizes incident response leadership, proactive threat hunting, and metrics-driven reporting on MTTD/MTTR, with

Qualifications

  • 6+ years in security operations, detection & response.
  • Hands-on SIEM tuning and log pipeline management.
  • Experience with MDR/MSSP partnerships and SLAs.
  • Strong incident response across cloud and SaaS environments.
  • Fluency with AI tools in daily security work.
  • Scripting and automation (Python), with SOAR playbooks.
  • Analytical, risk-based thinking to prioritize coverage vs. noise.
  • Familiarity with GRC and compliance frameworks (SOC 2, PCI DSS).
  • Excellent written and verbal communication with a distributed US-based team.

Responsibilities

  • Own day-to-day security operations: monitor, triage, investigate alerts across prod, corporate, and SaaS.
  • Tune and improve SIEM: log onboarding, parsing, normalization, and rule development.
  • Manage MDR partnership: escalation workflows and SLAs.
  • Lead security incidents end-to-end: containment, eradication, recovery, post-incident reviews.
  • Build automation: SOAR playbooks, detection-as-code, enrichment integrations.
  • Conduct proactive threat hunting informed by threat intel.
  • Define, track, and report metrics like MTTD/MTTR and ATT&CK coverage.
  • Apply AI tools to accelerate security operations and adapt detections.
  • Partner with Security Eng, Platform, IT, and Compliance to close gaps.
  • Support broader security program: GRC, endpoint/network security, third-party risk.

Skills

Security operations
SIEM tuning
Incident response
Threat hunting
Python scripting
AI in security

Tools

SIEM
SOAR
Python

Job description

About the Cybersecurity Team

The Security Engineering team at Thumbtack is focused on enabling innovation at scale by making the secure path the easiest path. We believe strong security is not a blocker to velocity, but a force multiplier when it is designed into systems, platforms, and developer workflows from the start.

We partner closely with Product, Engineering, Platform, and Data teams to shape system design, guide architectural decisions, and evolve Thumbtack’s security posture as the company scales. Through collaboration, automation, and thoughtful tradeoffs, we help ensure Thumbtack can ship fast, innovate boldly, and maintain customer trust.

About the role

As Thumbtack scales, the volume and variety of security telemetry grows with it, spanning cloud infrastructure, SaaS applications, endpoints, and identity systems. We’re looking for a Cybersecurity Senior Analyst to help build and operate a detection and response capability that is fast, high-fidelity, and increasingly automated.

In this role, you’ll be a cornerstone of our day-to-day security operations, treating detections as code, tuning our SIEM for signal over noise, partnering closely with our MDR provider, and automating response workflows so that human attention is reserved for the incidents that matter most. You’ll combine hands-on security operations with an engineering mindset, continuously finding ways to improve our detections, processes, and tooling as Thumbtack evolves.

While security operations will be your primary focus, you’ll also support the broader security program and flex into areas such as GRC, third-party risk, and vulnerability management as needed.

What you’ll do
  • Own day-to-day security operations: monitoring, triage, and investigation of security alerts across our production, corporate, and SaaS environments.
  • Manage and continuously improve our SIEM: log source onboarding, parsing and normalization, detection rule development and tuning, and cost/coverage optimization.
  • Manage our MDR (Managed Detection & Response) partnership: escalation workflows, SLAs, detection feedback loops, and quality of response.
  • Lead security incidents end-to-end: triage, scoping, containment, eradication, recovery, and blameless post-incident reviews.
  • Build automation that reduces manual toil and response times: SOAR playbooks, detection-as-code pipelines, enrichment integrations, and response scripting.
  • Conduct proactive threat hunting informed by threat intelligence and knowledge of Thumbtack’s environment.
  • Define, track, and report on operational metrics (e.g. MTTD, MTTR, alert fidelity, coverage against ATT&CK) and use them to drive improvement.
  • Apply AI tools to accelerate security operations, and continuously adapt our detections, processes, and tooling to address evolving and novel threats, including AI-related risks.
  • Partner with Security Engineering, Platform, IT, and Compliance to close detection gaps and improve our overall security posture.
  • Support the broader security program as needed: GRC (audit support, evidence collection, control monitoring), endpoint security, network security, third party risk reviews, vulnerability management (scanning, triage, and remediation coordination), etc.
In order to be successful, you must bring
  • 6+ years of experience in security operations, detection & response, or a related security engineering discipline.
  • Deep hands-on experience operating and tuning a SIEM, including detection engineering and log pipeline management.
  • Experience managing or working closely with an MDR/MSSP partner, including escalation design and holding vendors accountable to quality and SLAs.
  • Strong incident response skills across cloud-native environments (AWS and/or GCP), SaaS applications, endpoints, and identity systems.
  • Fluency with AI tools in daily security work, and the adaptability to evolve detections, processes, and tooling to address novel and emerging threats, including AI-related risks.
  • Scripting and automation proficiency (e.g. Python), with experience building SOAR playbooks, detection-as-code, or similar automation.
  • Risk-based, analytical thinking: the judgment to prioritize what matters, tune out noise, and articulate trade-offs between coverage, fidelity, and effort.
  • Working familiarity with adjacent security domains, including GRC and compliance frameworks (e.g. SOC 2, PCI DSS), third party risk assessment, and vulnerability management, with the flexibility to support them as needed.
  • Excellent written and verbal communication skills, including clear incident communications, and the ability to collaborate effectively with a distributed, primarily US-based team
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Analyst - Detection & Automation
Senior Cybersecurity Analyst - Detection & Automation

Thumbtack Philippines • Metro Manila

Remote
PHP 1,200,000 - 2,000,000
Security Operations Lead — Detection & Response
Security Operations Lead — Detection & Response

Thumbtack Philippines • Philippines

On-site
PHP 1,200,000 - 2,400,000
IT Security Specialist
IT Security Specialist

Ibex Limited • Manila

On-site
PHP 600,000 - 900,000
IT Security Specialist
IT Security Specialist

ibex • Mandaluyong

On-site
PHP 420,000 - 640,000
Cybersecurity Operations Analyst
Cybersecurity Operations Analyst

UL Solutions • Makati

On-site
PHP 600,000 - 900,000
IT Security Analyst
IT Security Analyst

Ibex Limited • Davao del Sur

On-site
PHP 480,000 - 840,000
Sr Cybersecurity Analyst
Sr Cybersecurity Analyst

Dexcom Inc. • Philippines

Hybrid
PHP 1,200,000 - 2,400,000
IT Security Analyst
IT Security Analyst

IBEX Global Solutions (Philippines) Inc. • Davao del Sur

On-site
PHP 420,000 - 560,000
Cybersecurity Incident Commander - CIRT
Cybersecurity Incident Commander - CIRT

Thrive • Tarlac City

On-site
PHP 1,200,000 - 1,800,000
Junior Cyber Security Engineer
Junior Cyber Security Engineer

Dormont Manufacturing Co • Philippines

On-site
PHP 420,000 - 620,000