Security Engineer – SIEM & SOAR (CL8)
Work Setup: Onsite – Manila
Work Shift: Shifting
Salary: Confidential – To be discussed during the Job Offer
Role Overview
We are looking for Security Engineers with strong hands-on experience in SIEM and SOAR engineering to design, implement, and manage security monitoring and automated response capabilities. The role involves working closely with SOC teams, threat analysts, and IT stakeholders to improve threat detection, automate incident response, and strengthen overall security operations.
Key Responsibilities
SIEM Engineering & Management
- Design, implement, and optimize SIEM solutions such as Splunk, Microsoft Sentinel, QRadar, ArcSight, Google SecOps, or Elastic.
- Develop and maintain correlation rules, dashboards, and reports to identify security threats and anomalies.
- Integrate network, endpoint, cloud, and application data sources into SIEM platforms.
- Improve data ingestion, parsing, and normalization to enhance detection quality and reduce noise.
SOAR & Automation
- Implement and manage SOAR platforms such as Cortex XSOAR, Splunk SOAR, or IBM Resilient.
- Develop automated playbooks for incident response, alert triage, and threat intelligence enrichment.
- Collaborate with SOC analysts to streamline security workflows and improve response efficiency.
- Maintain integrations with ticketing systems, threat intelligence feeds, and security tools.
Security Engineering & Operations Support
- Support incident response by providing actionable alerts and automation-driven insights.
- Conduct root cause analysis of recurring security threats and implement engineering solutions.
- Partner with audit and compliance teams to align security controls with regulatory requirements.
- Provide training and documentation for SOC and IT teams on SIEM/SOAR platforms.
Qualifications
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field.
- 3–8 years of cybersecurity experience with strong hands-on experience in SIEM and/or SOAR engineering.
- Experience working in a SOC environment is highly preferred.
- Hands-on experience with at least one SIEM platform such as Splunk, Microsoft Sentinel, QRadar, ArcSight, Google SecOps, or Elastic.
- Experience developing SOAR playbooks and automation workflows.
- Scripting knowledge in Python, PowerShell, or Bash for automation and integrations.
- Knowledge of security frameworks such as MITRE ATT&CK, NIST, or CIS Controls.
- Familiarity with EDR/XDR, firewalls, IDS/IPS, and cloud security platforms such as AWS, Azure, or GCP.
- Willingness to work on a shifting schedule.
- Willingness to work onsite in Manila.
Recruitment Process
- Endorsement for validation.
- Screening with CV review and submission through Workday, including required screening documents.
- Client review.
Pre-Screening Questions
- How many years of hands-on cybersecurity experience do you have, specifically in SIEM and SOAR engineering?
- Which SIEM platforms have you worked with?
- Have you designed, implemented, or optimized SIEM solutions? Please describe your experience.
- Which SOAR platforms have you worked with?
- What is your last drawn salary?
- What is your salary expectation?
- Are you willing to work onsite in Manila on a shifting schedule?
- Do you currently have an active or recent application with the company and an active Workday profile?