DFIR Specialist / Senior SOC Analyst

THEOS

Hinoba-an

Hybrid

PHP 900,000 - 1,300,000

Full time

10 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Theos is a cybersecurity company delivering premium services across Asia and beyond. Theos seeks a DFIR Specialist / Senior SOC Analyst to lead client-facing engagements through the full incident response lifecycle, coordinating with senior stakeholders to deliver critical outcomes.

You will manage engagements, contain incidents with precision, and provide actionable remediation plans to strengthen client resilience and security posture, while mentoring juniors and keeping abreast of evolving

Qualifications

  • Bachelor's degree in information security or related field, or equivalent experience.
  • Experience administering or investigating cloud platforms (Azure, AWS, Google Workspace, or Alibaba Cloud).
  • Minimum four years of cybersecurity operations experience.
  • Strong incident response and report-writing skills.
  • Investigative mindset with drive to learn and improve.

Responsibilities

  • Lead end-to-end incident response engagements across BEC, ransomware, data breaches, insider threats.
  • Perform forensic analysis across cloud, Windows, Linux, macOS; review network traffic and logs.
  • Use CrowdStrike, FTK, SIEM, and Magnet AXIOM to identify IOCs and TTPs.
  • Communicate findings and provide timely updates and reports to clients.
  • Mentor junior staff in incident response and digital forensics.
  • Stay aware of evolving threats, including AI and LLM-related risks.
  • Improve playbooks, tooling, and automation; feed lessons into processes.
  • Travel approx. 5% to support on-site engagements.

Skills

Incident response
Digital forensics
Cloud platforms
Threat detection
Report writing

Education

Bachelor's degree or equivalent in a related field

Tools

CrowdStrike
FTK
Next-gen SIEM
Magnet AXIOM

Job description

DFIR Specialist / Senior SOC Analyst

Manila | Kuala Lumpur | Hong Kong | Singapore | APAC Remote

Our Mission

Our mission is to empower businesses to thrive in the digital security age by defining and executing practical strategies that build true cyber resilience. At Theos, security is not an afterthought. It is our foundation. We believe in disciplined execution over silver bullets, and real outcomes over noise.

Who We Are

Theos is a cybersecurity company delivering premium services across Asia and beyond. We support SMEs and enterprises with capabilities traditionally reserved for global Tier-1 firms, spanning Penetration Testing, Red Teaming, Managed Detection and Response, and Digital Forensics and Incident Response. We combine deep technical capability with commercial discipline and operational maturity.

Our culture is grounded in five core values: Security as Our Foundation; Global Collaboration and Respect; Embrace Change and Innovate; Integrity and Accountability; and Strive for Excellence.

As we grow, we are building a culture that moves from heroics to process, from reaction to discipline, and from surviving to thriving. We value ownership, clarity, execution, and people who continuously raise the standard for themselves, their teams, and our clients.

Job Summary

As a DFIR Specialist / Senior SOC Analyst at Theos, you will lead client-facing engagements across the full incident response lifecycle. You will work closely with diverse customers and senior stakeholders to deliver critical outcomes and guide organisations through complex investigations.

Your role will be central to managing engagements, containing security incidents with precision, and providing clear, actionable remediation plans that strengthen client resilience and enhance overall security posture.

Key Responsibilities
  • Lead end-to-end incident response engagements, guiding clients through investigation, containment, and long-term remediation across business email compromise (BEC), ransomware, data breaches, insider threats, and compromise assessment cases.
  • Conduct forensic analysis across cloud, Windows, Linux, and macOS environments, including network traffic and log data from web application firewalls, firewalls, endpoints, cloud platforms, and applications.
  • Use tools such as CrowdStrike, FTK, next-generation SIEM platforms, and Magnet AXIOM to identify indicators of compromise (IOCs), threat-actor tactics, techniques, and procedures (TTPs), root cause, and scope of impact.
  • Collaborate with clients and internal stakeholders to communicate findings, provide timely updates, and deliver comprehensive reports.
  • Mentor junior staff and share expertise in incident response and digital forensics best practices.
  • Maintain awareness of the evolving threat landscape, including emerging AI- and large language model-related threats.
  • Improve playbooks, methodologies, and tooling, including artefact collectors and parsers, and feed lessons from live engagements back into processes and automation.
  • Travel as required, approximately 5%, to support client and business needs through on-site engagements.
Qualifications
- Required Qualifications
  • Bachelor's degree in Information Security, Computer Science, Digital Forensics, Cybersecurity, or a related discipline, or equivalent professional experience.
  • Experience administering, monitoring, or investigating cloud platforms such as Microsoft Azure, AWS, Google Workspace, or Alibaba Cloud.
  • Minimum of four years of direct experience in cybersecurity operations.
  • Strong proficiency in rapid incident response, creative problem-solving, and report writing.
  • An investigative mindset, with an interest in solving complex problems, learning new techniques, and continuously improving.
- Preferred Qualifications
  • Prior experience in a client-facing incident response consulting role.
  • Direct experience in incident response and/or digital forensics, with practical experience using forensic and incident response tools.
  • Prior experience developing and delivering tabletop exercises.
  • Strong executive presence, with the ability to present complex technical findings to C-level stakeholders.
  • Proven ability to build collaborative relationships with internal teams, external partners, and clients.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DFIR Specialist / Senior SOC Analyst (Malaysia)
DFIR Specialist / Senior SOC Analyst (Malaysia)

THEOS • Manila

Hybrid
PHP 1,200,000 - 1,800,000
Remote DFIR Lead & Senior SOC Analyst
Remote DFIR Lead & Senior SOC Analyst

THEOS • Manila

Hybrid
PHP 1,200,000 - 1,800,000
Senior Consultant – Digital Forensics & Incident Response (DFIR)
Senior Consultant – Digital Forensics & Incident Response (DFIR)

PM Consulting • Philippines

Hybrid
PHP 900,000 - 1,500,000
Senior DFIR & SOC Analyst — Remote APAC
Senior DFIR & SOC Analyst — Remote APAC

THEOS • Hinoba-an

Hybrid
PHP 900,000 - 1,300,000
Incident Response Analyst
Incident Response Analyst

Check Point Software • Metro Manila

On-site
PHP 2,000,000 - 2,800,000
Digital Forensic & Incident Response Senior Analyst - Hybrid Ortigas - 70K
Digital Forensic & Incident Response Senior Analyst - Hybrid Ortigas - 70K

weSource Management Consultancy Firm • Pasig

Hybrid
DFIR Associate Manager (Digital Forensics & Incident Response)
DFIR Associate Manager (Digital Forensics & Incident Response)

Accenture Inc. • Philippines

Hybrid
PHP 1,200,000 - 1,800,000
Joining bonus up to PHP80,000
DFIR Associate Manager Digital Forensics And Incident Response Hybrid Cubao
DFIR Associate Manager Digital Forensics And Incident Response Hybrid Cubao

Accenture in the Philippines • Philippines

Hybrid
PHP 1,800,000 - 2,400,000
Flexible working arrangements
HMO Insurance
Training & Certifications
+5
IT.Senior SOC Analyst
IT.Senior SOC Analyst

Citco Group of Companies • Makati

Hybrid
Senior Analyst, Cyber Security Operations
Senior Analyst, Cyber Security Operations

Melco Resorts & Entertainment • Manila

On-site
PHP 1,004,000 - 1,674,000