Dfir Specialist / Senior Soc Analyst

Theos Cyber Solutions

Philippines

Remote

PHP 900,000 - 1,300,000

Full time

9 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Theos Cyber Solutions seeks a DFIR Specialist / Senior SOC Analyst to lead client-facing incident response engagements, guiding organisations through investigations from detection to remediation.

You will perform digital forensics across cloud and endpoint environments, communicate findings to senior stakeholders, and mentor junior staff while improving playbooks to strengthen client resilience. Travel ~5% for on-site work.

Qualifications

  • Bachelor's degree in Information Security, Computer Science, Digital Forensics, Cybersecurity, or related field, or equivalent experience.
  • Experience administering, monitoring, or investigating cloud platforms (Azure, AWS, Google Workspace, Alibaba Cloud).
  • Minimum of four years in cybersecurity operations.
  • Strong incident response, problem-solving, and report writing skills.

Responsibilities

  • Lead end-to-end incident response engagements across investigation, containment, and remediation.
  • Conduct forensic analysis across cloud, Windows, Linux, and macOS; review network traffic and logs from FWs, endpoints, clouds, and apps.
  • Identify IOCs, TTPs, root cause, and impact; communicate findings and deliver reports to clients and stakeholders.
  • Mentor junior staff and share expertise in incident response and digital forensics.

Skills

Incident response
Digital forensics
Cloud platforms
Report writing

Education

Bachelor's degree or equivalent

Tools

CrowdStrike
FTK
Magnet AXIOM
Next-gen SIEM

Job description

DFIR Specialist / Senior SOC Analyst

Company: Theos Cyber Solutions

Job Type: Full Time Remote / Work from Home

Manila | Kuala Lumpur | Hong Kong | Singapore | APAC Remote

Our Mission

Our mission is to empower businesses to thrive in the digital security age by defining and executing practical strategies that build true cyber resilience. At Theos, security is not an afterthought. It is our foundation. We believe in disciplined execution over silver bullets, and real outcomes over noise.

Who We Are

Theos is a cybersecurity company delivering premium services across Asia and beyond. We support SMEs and enterprises with capabilities traditionally reserved for global Tier-1 firms, spanning Penetration Testing, Red Teaming, Managed Detection and Response, and Digital Forensics and Incident Response. We combine deep technical capability with commercial discipline and operational maturity.

Our Culture

Our culture is grounded in five core values: Security as Our Foundation; Global Collaboration and Respect; Embrace Change and Innovate; Integrity and Accountability; and Strive for Excellence.

As we grow, we are building a culture that moves from heroics to process, from reaction to discipline, and from surviving to thriving. We value ownership, clarity, execution, and people who continuously raise the standard for themselves, their teams, and our clients.

Job Summary

As a DFIR Specialist / Senior SOC Analyst at Theos, you will lead client-facing engagements across the full incident response lifecycle. You will work closely with diverse customers and senior stakeholders to deliver critical outcomes and guide organisations through complex investigations.

Your role will be central to managing engagements, containing security incidents with precision, and providing clear, actionable remediation plans that strengthen client resilience and enhance overall security posture.

Key Responsibilities
  • Lead end-to-end incident response engagements, guiding clients through investigation, containment, and long-term remediation across business email compromise (BEC), ransomware, data breaches, insider threats, and compromise assessment cases.
  • Conduct forensic analysis across cloud, Windows, Linux, and macOS environments, including network traffic and log data from web application firewalls, firewalls, endpoints, cloud platforms, and applications.
  • Use tools such as CrowdStrike, FTK, next-generation SIEM platforms, and Magnet AXIOM to identify indicators of compromise (IOCs), threat-actor tactics, techniques, and procedures (TTPs), root cause, and scope of impact.
  • Collaborate with clients and internal stakeholders to communicate findings, provide timely updates, and deliver comprehensive reports.
  • Mentor junior staff and share expertise in incident response and digital forensics best practices.
  • Maintain awareness of the evolving threat landscape, including emerging AI- and large language model-related threats.
  • Improve playbooks, methodologies, and tooling, including artefact collectors and parsers, and feed lessons from live engagements back into processes and automation.
  • Travel as required, approximately 5%, to support client and business needs through on-site engagements.
Required Qualifications
  • Bachelor's degree in Information Security, Computer Science, Digital Forensics, Cybersecurity, or a related discipline, or equivalent professional experience.
  • Experience administering, monitoring, or investigating cloud platforms such as Microsoft Azure, AWS, Google Workspace, or Alibaba Cloud.
  • Minimum of four years of direct experience in cybersecurity operations.
  • Strong proficiency in rapid incident response, creative problem-solving, and report writing.
  • An investigative mindset, with an interest in solving complex problems, learning new techniques, and continuously improving.
Preferred Qualifications
  • Prior experience in a client-facing incident response consulting role.
  • Direct experience in incident response and/or digital forensics, with practical experience using forensic and incident response tools.
  • Prior experience developing and delivering tabletop exercises.
  • Strong executive presence, with the ability to present complex technical findings to C-level stakeholders.
  • Proven ability to build collaborative relationships with internal teams, external partners, and clients.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote DFIR Specialist & Senior SOC Analyst
Remote DFIR Specialist & Senior SOC Analyst

Theos Cyber Solutions • Philippines

Remote
PHP 900,000 - 1,300,000
Senior Consultant – Digital Forensics & Incident Response (DFIR)
Senior Consultant – Digital Forensics & Incident Response (DFIR)

PM Consulting • Philippines

On-site
PHP 900,000 - 1,500,000
DFIR Associate Manager (Digital Forensics & Incident Response)
DFIR Associate Manager (Digital Forensics & Incident Response)

Gratitude Philippines • Manila

Hybrid
PHP 1,200,000 - 1,800,000
Certification sponsorship
Digital Forensic & Incident Response Senior Analyst - Hybrid Ortigas - 70K
Digital Forensic & Incident Response Senior Analyst - Hybrid Ortigas - 70K

weSource Management Consultancy Firm • Pasig

On-site
PHP 710,892 - 851,508
DFIR Associate Manager (Digital Forensics & Incident Response)
DFIR Associate Manager (Digital Forensics & Incident Response)

Accenture Inc. • Philippines

On-site
PHP 1,200,000 - 1,800,000
Joining bonus up to PHP80,000
Cybersecurity Engineer
Cybersecurity Engineer

Hrtx • Philippines

On-site
PHP 1,000,000 - 1,800,000
Hybrid work setup
SOC Analyst
SOC Analyst

OFFSHORE BUSINESS PROCESSING INC. • Philippines

On-site
PHP 446,000 - 558,000
HMO on Day 1
Receive promising perks and rewards
Experience travel opportunities
+3
IT.Senior SOC Analyst
IT.Senior SOC Analyst

Citco Group of Companies • Makati

On-site
PHP 1,004,400 - 1,674,000
GDS Consulting_Cyber Detection & Response Senior
GDS Consulting_Cyber Detection & Response Senior

Ernst & Young Advisory Services Sdn Bhd • Taguig

On-site
PHP 1,200,000 - 1,800,000
Competitive salary
Health benefits
Retirement plans
+1
Security Operations Center Analyst (Las Pinas)
Security Operations Center Analyst (Las Pinas)

TaskUs • Las Piñas

On-site
PHP 360,000 - 720,000
Benefits package
Professional development
Internal mobility