IT Security Specialist

ibex

Mandaluyong

On-site

PHP 420,000 - 640,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ibex is seeking a skilled SOC security practitioner to join our IT Security team in the Philippines. You will monitor security dashboards, analyze threats, and drive incident response while ensuring compliance with core standards.

The role involves archiving logs, coordinating with IT to contain incidents, and supporting vulnerability management across AWS/Azure/GCP environments where applicable. A strong focus on MITRE ATT&CK and SIEM/EDR tuning is required.

Qualifications

  • Non-Negotiable: Security Monitoring & Incident Handling in Core SOC operations.
  • Vulnerability Management & Security Hardening support.
  • Detection Engineering & Threat Intelligence (SIEM / EDR / MITRE/IDS).
  • Automation of incident escalation and RCA of recurring issues.
  • Actively guide and escalation contact for Level-1 SOC Analysts.

Responsibilities

  • Oversee daily monitoring of security dashboards, alerts, and events.
  • Review threats, risks, and indicators of compromise (IOCs).
  • Coordinate with IT for investigation, containment, and resolution.
  • Perform log review to support investigations and visibility.
  • Manage security incidents from identification to closure with proper docs.
  • Ensure timely categorization, prioritization, and closure in eService tickets.
  • Review eService tickets daily for SLA compliance and closure quality.
  • Validate incident resolution and supporting documentation before closure.
  • Support vulnerability scanning and track remediation with IT teams.
  • Follow up on vulnerability closure based on risk severity.
  • Identify security gaps and enforce baselines and configurations.
  • Support ISO 27001, SOC 2, PCI-DSS, CIS Controls requirements.
  • Assist in audit preparation through evidence collection and control validation.
  • Weekly review of wireless networks to detect rogue APs.
  • Periodic review of endpoint security alerts and EDR findings.
  • Quarterly review of firewall, VPN, and proxy logs for suspicious activity.
  • Monthly privileged access review and inactive account identification.
  • Assist in monthly validation of system security configurations against baselines.
  • Monitor patch compliance and coordinate with system owners.
  • Participate in threat hunting using MITRE ATT&CK.
  • Support development and tuning of SIEM use cases and alerts.
  • Support integration of threat intelligence feeds to enhance detection.

Skills

Security Monitoring
Incident Handling
Vulnerability Management
Threat Intelligence
SIEM / EDR
MITRE ATT&CK
Automation
L1 SOC Escalation
Cloud Security

Education

Bachelor's degree in CS/IT
Security certifications (e.g., CISSP/SEC+)

Tools

SIEM Tools
EDR Tools
Firewall/VPN

Job description

To protect organizational systems by monitoring, detecting, investigating, and responding to security threats while supporting compliance and continuous improvement of security operations.

This role is part of the IT Security team and is responsible for supporting day-to-day security operations, monitoring security tools, performing threat analysis, and assisting in the implementation of security controls and compliance requirements.

Responsibilities
  • Oversee daily monitoring of security dashboards, alerts, and security events
  • Review and analyze security threats, risks, and indicators of compromise (IOCs)
  • Coordinate with IT teams for investigation, containment, and resolution of security issues
  • Perform log review and analysis to support security investigations and operational visibility
  • Manage security incidents from identification to closure, ensuring proper documentation and tracking
  • Ensure timely categorization, prioritization, and resolution of security tickets in the eService system
  • Review eService security tickets daily to ensure SLA compliance and proper closure quality
  • Ensure validation of incident resolution and completeness of supporting documentation before closure
  • Support vulnerability scanning activities and track remediation with IT teams
  • Follow up on vulnerability closure and ensure timely remediation based on risk severity
  • Identify security gaps and support enforcement of security baselines and configurations
  • Support compliance with ISO 27001, SOC 2, PCI-DSS, and CIS Controls requirements
  • Assist in audit preparation through evidence collection and control validation
  • Conduct weekly review of wireless networks to detect rogue or unauthorized access points
  • Perform periodic review of endpoint security alerts and EDR findings for anomalies
  • Conduct quarterly review of firewall, VPN, and proxy logs for suspicious activities
  • Support monthly privileged access review and identification of inactive accounts
  • Assist in monthly validation of system security configurations against baseline standards
  • Monitor patch compliance and coordinate with system owners for delayed updates
  • Participate in threat hunting activities using MITRE ATT&CK framework
  • Support development, tuning, and maintenance of SIEM use cases, correlation rules, alerts, and detection logic to improve threat detection coverage and accuracy
  • Support integration and operational use of threat intelligence feeds (e.g., IOC enrichment, threat feed correlation) to enhance detection and monitoring capabilities
  • Mand Mand Mand
  • Monitor and investigate security events across cloud environments (AWS, Azure, GCP) where applicable, in coordination with cloud or infrastructure teams
  • Conduct root cause analysis (RCA) of recurring security incidents and support implementation of corrective and preventive actions to reduce recurrence
  • Identify opportunities for automation and continuous improvement in security operations processes, including detection, response, and reporting workflows
QualificationsNon-Negotiable:
  • Security Monitoring & Incident Handling (Core SOC Operations)
  • Vulnerability Management & Security Hardening Support
  • Detection Engineering Support & Threat Intelligence (SIEM / EDR / MITRE/IDS)
  • Supporting automation of incident escalation and RCA of recurring issues
  • Acitvely guide and escalation contact for Level-1 SOC Analysts
Additional Skills
  • Strong understanding of infrastructure security, SOC operations, and compliance frameworks
  • Experience in cloud security across AWS, Azure, and GCP environments
  • Knowledge of SIEM tools, including alert tuning, correlation, and detection rule creation
  • Understanding of threat detection using IDS/IPS, SPAN/TAP feeds, and network monitoring
  • Familiarity with firewalls, WAF, VPN, NAC, DNS security, and endpoint security tools
  • Ability to perform log analysis, event correlation, and security incident investigation
  • Knowledge of vulnerability assessment and remediation tracking processes
  • Understanding of MITRE ATT&CK framework and threat hunting concepts
  • Ability to review security configurations and ensure compliance with security baselines
  • Experience supporting incident response, escalation, and coordination with IT teams
  • Knowledge of PCI-DSS, SOC 2, ISO 27001, and CIS Controls compliance requirements
  • Ability to support security monitoring, alert triage, and continuous improvement of SOC processes
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Specialist
IT Security Specialist

Ibex Limited • Manila

On-site
PHP 600,000 - 900,000
IT Security Analyst
IT Security Analyst

Ibex Limited • Davao del Sur

On-site
PHP 480,000 - 840,000
Security Analyst / Network Security Analyst
Security Analyst / Network Security Analyst

RippedBoxStation • Philippines

On-site
PHP 260,000 - 420,000
Security Operations Center (SOC) - Head
Security Operations Center (SOC) - Head

SMITS, Inc. - IT Company of San Miguel Corporation • Mandaluyong

On-site
PHP 900,000 - 1,600,000
Security Analyst / Network Security Analyst - DFT - 08052026
Security Analyst / Network Security Analyst - DFT - 08052026

Rippedboxstation • Metro Manila

On-site
PHP 240,000 - 360,000
IT Security Analyst
IT Security Analyst

CallTek • Cebu City

On-site
PHP 200,000 - 360,000
Managed Security Services Lead
Managed Security Services Lead

PentagonPlus • Bangsar

On-site
PHP 3,385,000 - 4,615,000
Junior SOC Analyst
Junior SOC Analyst

Kinettix Inc. • Manila

On-site
Senior Security Consultant
Senior Security Consultant

Hunter's Hub Inc. • Taguig

On-site
IT Security Analyst
IT Security Analyst

CallTek, Inc. • Cebu City

On-site