IT.Senior SOC Analyst

The Citco Group

Makati

On-site

PHP 900,000 - 1,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
Hybrid work model

Job summary

Citco in Makati is seeking a Senior SOC Analyst to join a 24x7x365 CSIRT environment. You will lead threat investigations, tune SIEM/EDR/SOAR content, and mentor junior analysts while collaborating across IT security and DevSecOps teams.

The role requires 3–5+ years in a global enterprise SOC, strong scripting (PowerShell/Python), and familiarity with MITRE ATT&CK. Hybrid work setup and opportunities for skill enrichment are offered.

Qualifications

  • 3–5+ years in a 24x7 SOC, CSIRT, or cyber incident response role in a global enterprise.
  • Deep knowledge of SIEM, EDR, and SOAR platforms and security automation tools.
  • Familiarity with threat intel standards (STIX/TAXII) and MITRE ATT&CK.
  • Strong scripting abilities (PowerShell, Python).
  • Excellent written and verbal communication for documentation and briefings.
  • Willingness to work flexible hours including weekends, holidays, and on-call as needed.

Responsibilities

  • Serve as an escalation point for complex or high-risk security incidents.
  • Lead end-to-end investigations involving malware, APTs, lateral movement, and insider threats.
  • Conduct proactive threat hunting across on-prem and cloud environments using SIEM, EDR, and threat intelligence tools.
  • Analyze logs, security telemetry, and packet captures across Windows, Linux, and network infrastructure.
  • Enhance detection content and use cases by tuning SIEM and EDR rules aligned to MITRE ATT&CK.
  • Develop, test, and maintain SOAR playbooks to improve investigation efficiency and automate response actions.
  • Maintain accurate and detailed documentation in the SOC’s case management system.

Skills

SIEM
EDR
SOAR
MITRE ATT&CK
Threat intel STIX/TAXII
PowerShell
Python
Sysinternals
Wireshark
Communication skills

Tools

Sysinternals
Wireshark

Job description

Senior SOC Analyst

Makati - Hybrid Set-Up

Flexible Shift

POSITION DESCRIPTION

This position calls for a Senior SOC Analyst with proven expertise in cybersecurity monitoring, threat detection, and incident response across complex enterprise environments. As a key member of Citco’s Computer Security Incident Response Team (CSIRT), the Senior SOC Analyst is responsible for leading the analysis of security events, proactively identifying and mitigating threats, and mentoring junior analysts within a 24x7x365 SOC environment.

The Senior SOC Analyst is expected to be highly proficient with modern security technologies and have deep knowledge of adversary tactics, techniques, and procedures (TTPs). This role requires experience working across hybrid-cloud environments, supporting incident handling lifecycle from detection through containment, eradication, and recovery.

ORGANIZATIONAL RELATIONS

This position is part of the IT Security group, which oversees global cybersecurity at Citco and supports incident handling and detection initiatives across business units and platforms.

PRINCIPAL ACCOUNTABILITIES
  • Serve as an escalation point for complex or high-risk security incidents.
  • Lead end-to-end investigations involving malware, APTs, lateral movement, and insider threats.
  • Conduct proactive threat hunting across on-prem and cloud environments using SIEM, EDR, and threat intelligence tools.
  • Analyze logs, security telemetry, and packet captures across Windows, Linux, and network infrastructure.
  • Enhance detection content and use cases by tuning SIEM and EDR rules aligned to frameworks such as MITRE ATT&CK.
  • Develop, test, and maintain SOAR playbooks to improve investigation efficiency and automate response actions.
  • Contribute to post-incident reviews and root cause analyses, proposing hardening and lessons learned initiatives.
  • Conduct periodic evaluations of alert fidelity, detection coverage, and SOC operational metrics.
  • Collaborate with IT, Engineering, and DevSecOps teams to validate threat findings, coordinate remediation, and improve preventative defenses.
  • Lead knowledge transfer sessions and create training material for Junior SOC analysts.
  • Assist the SOC Manager in evaluating security tools and recommending operational improvements.
  • Maintain accurate and detailed documentation in the SOC’s case management system.
  • Stay current on emerging threats, adversary TTPs, and detection techniques.
EDUCATION, EXPERIENCE & SKILLS
  • 3–5+ years of experience in a 24x7 SOC, CSIRT, or cyber incident response role in a global enterprise.
  • Deep knowledge of SIEM, EDR and SOAR platforms and security automation tools.
  • Familiarity with threat intelligence standards (e.g., STIX/TAXII) and frameworks like MITRE ATT&CK.
  • Strong hands‑on experience with forensic tools and utilities (e.g., Sysinternals, Wireshark).
  • Proficient in scripting and automation (e.g., PowerShell, Python).
  • Excellent verbal and written communication skills, especially for documentation, briefings, and reporting.
  • Critical thinking and problem‑solving skills with a high attention to detail.
  • Comfortable working independently or collaboratively under pressure.
  • Preferred certifications: GCIH, GCIA, CEH, CySA+, or equivalent.
  • Willingness to work flexible hours including weekends, holidays, and on‑call as needed.
WHAT WE OFFER

We offer a challenging job in a growing international company, an opportunity to expand your business knowledge by working with prestigious clients and complex financial and technological instruments, and a friendly and fast‑paced environment. Additionally, Citco is proud to offer our employees competitive compensation, vacation and health insurance benefits.

Find out more about us!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT.Senior SOC Analyst
IT.Senior SOC Analyst

the citco group limited • Philippines

Hybrid
PHP 900,000 - 1,300,000
Vacation and health insurance
IT.Senior SOC Analyst
IT.Senior SOC Analyst

Citco Group of Companies • Makati

Hybrid
Senior SOC Analyst — Hybrid, Flexible Hours, 24x7 Response
Senior SOC Analyst — Hybrid, Flexible Hours, 24x7 Response

The Citco Group • Makati

Hybrid
PHP 900,000 - 1,800,000
Health insurance
Hybrid work model
Senior SOC Analyst — Hybrid, Lead Threat Hunting & IR
Senior SOC Analyst — Hybrid, Lead Threat Hunting & IR

Citco Group of Companies • Makati

Hybrid
Senior SOC Analyst
Senior SOC Analyst

Likha Careers • Pasig

Hybrid
Paid training
Health Insurance
Life Insurance
+2
Senior SOC Analyst - Makati
Senior SOC Analyst - Makati

NEXUS TECHNOLOGIES, INC. • Makati

Hybrid
PHP 600,000 - 900,000
Cybersecurity Incident Response Lead (SOC)
Cybersecurity Incident Response Lead (SOC)

RecruitNest Consulting • Taguig

On-site
PHP 1,200,000 - 2,400,000
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

Bounty Fresh Food, Inc. • Taguig

Hybrid
PHP 520,000 - 900,000
Senior SOC Analyst - Hybrid, Flexible Shifts
Senior SOC Analyst - Hybrid, Flexible Shifts

the citco group limited • Philippines

Hybrid
PHP 900,000 - 1,300,000
Vacation and health insurance
Senior Analyst, Cyber Security Operations
Senior Analyst, Cyber Security Operations

Melco Resorts & Entertainment Limited • Manila

On-site
PHP 900,000 - 1,500,000