Lead Security Engineer

Vaco by Highspring

Philippines

On-site

PHP 800,000 - 1,200,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Vaco by Highspring seeks a hands-on security analyst to provide after-hours coverage for escalated alerts and incidents in a fast-moving managed services environment.

The role requires investigating, containing, and documenting actions, with potential seniority based on experience. Strong Microsoft 365/Defender and EDR experience is preferred, along with change-ready wave support for 2nd/3rd shifts.

Qualifications

  • Experience in SOC and incident response with defined escalation judgments.
  • Ability to perform containment and basic remediation in SMB environments.
  • Proficient with Windows/Microsoft security stack and common firewalls.

Responsibilities

  • Triage escalated alerts, validate severity, enrich with context.
  • Document investigation notes and next steps.
  • Execute containment, preserve evidence, log scope/impact during incidents.
  • Maintain shift handoffs and ongoing continuity during surge.

Skills

SOC experience
Incident response
Shift flexibility
Containment decisions
Troubleshooting

Tools

Microsoft Entra ID
Microsoft Defender
Microsoft 365
EDR SentinelOne
CrowdStrike
LimaCharlie
WatchGuard
SonicWall
Tenable
Cyber Triage
Tines
KnowBe4
ConnectWise
Power BI

Job description

Our client is a rapidly expanding, award-winning technology solutions provider in the managed services space. Their vision is to be the North American leader in delivering and supporting technology solutions for small and mid-sized businesses. They are driven by their mission and core values to be a great place to work and a great company to work with.

What we are looking for:

We are seeking a hands-on security analyst and incident responder to provide dedicated after-hours coverage for escalated alerts, declared incidents, and overflow security operations work. The ideal candidate can independently investigate, contain, document, and transition work cleanly in a fast-moving managed services environment. This job description is designed to support multiple levels of hire, with core SOC and incident response expectations shared across roles and additional engineering or automation depth serving as a differentiator for more senior candidates.

Job Description & Daily Tasks

On-Shift (Steady State)

  • Triage escalated alerts, validate severity, enrich with endpoint/identity/network/cloud context
  • Document investigation notes and next steps

During Incidents / Surge

  • Execute containment, collect/preserve evidence, log correlation for scope/impact
  • Maintain "eyes-on-glass" continuity with clean shift handoffs

Overflow / Bench Support

  • Detection tuning, playbook/runbook updates, baseline cleanup, config normalization, visibility improvements
Requirements & Target Profile

Experience & Capability

  • Relevant SOC and/or incident response experience, generally aligned to level: approximately 3+ years for mid-level hires, 5+ years for senior hires, and 7+ years for lead hires
  • Tier 2 capability: run investigations end-to-end with minimal oversight and sound escalation judgment
  • Execution-oriented: able to perform containment, blocking, isolation, and basic remediation in small and mid-sized business environments
  • Windows and Microsoft-first environments, including Microsoft 365, Entra ID, Defender, and common firewalls such as WatchGuard and SonicWall
  • Comfortable working across EDR, firewall administration, identity and email security consoles, ticketing systems, RMM tools, and security telemetry sources

Documentation & Handoffs

  • Strong documentation discipline for investigative findings, decisions made, actions taken, and next steps
  • Structured shift-change deliverables including current status, pending actions, risks, and recommendations
  • Able to support 2nd/3rd shift schedules and maintain continuity during prolonged or multi-day incident response scenarios

Target Profile

  • Hands-on responder who investigates ambiguous or unfamiliar signals independently
  • Action-oriented and comfortable making containment decisions within defined guardrails
  • Calm under pressure and able to sustain quality through multi-day or concurrent incidents
  • Consistency-minded and interested in longer-term engagement within a dedicated team model

Coverage Goal

  • Dependable dedicated 2nd and 3rd shift coverage, with optional 1st shift augmentation as operational needs evolve

Surge Capacity

  • Multi-day incidents, concurrent incidents, zero-days impacting multiple customers
Technology Environment
  • Identity & Security: Microsoft Entra ID, Microsoft Defender, Microsoft 365
  • Operating Systems: Windows
  • Endpoint Detection & Response (EDR): SentinelOne preferred; experience with leading platforms (e.g., CrowdStrike or equivalent) also valued
  • SIEM / XDR & Monitoring: Microsoft-centric security stack and/or platforms such as LimaCharlie
  • Network Security: Firewalls including WatchGuard and SonicWall
  • Vulnerability Management: Tenable
  • Incident Response & Forensics: Cyber Triage and related IR tooling
  • Automation & SOAR: Tines or similar workflow automation tools
  • Security Tooling & Integrations: Security awareness platforms (e.g., KnowBe4)
  • Ticketing System: ConnectWise
Nice-to-Have

These capabilities are not required for success in the role, but they may distinguish stronger senior / lead candidates and expand the team's ability to support recovery, engineering, automation, and reporting needs.

  • Infrastructure Recovery & IT Engineering
  • Network, cloud, and endpoint recovery
  • Firewall, VPN, and zero-trust environments
  • Backup validation and isolated recovery environments
  • Active Directory, virtual hosts, domain controllers, migrations, and secure system restoration
  • Endpoint wipe-and-reload and related rebuild activities
  • Automation, Orchestration & Advanced SOC Capability
  • SOAR workflows in platforms such as Tines
  • Alert triage optimization and reporting pipeline improvement
  • AI-assisted detection and response workflows
  • API or scripting-based integrations using tools such as Python and PowerShell
  • Security Data, Reporting & Analytics
  • Dashboards and operational reporting views
  • Metrics and trend analysis
  • Visualization in Power BI, Microsoft Fabric, or similar platforms
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Security Engineer
Lead Security Engineer

Hammerjack Pty Ltd • Philippines

On-site
PHP 700,000 - 1,100,000
IT Security Specialist
IT Security Specialist

Ibex Limited • Manila

On-site
PHP 600,000 - 900,000
IT Security Specialist
IT Security Specialist

ibex • Mandaluyong

On-site
PHP 420,000 - 640,000
IT Security Analyst
IT Security Analyst

IBEX Global Solutions (Philippines) Inc. • Davao del Sur

On-site
PHP 420,000 - 560,000
Security Operations Center (SOC) - Head
Security Operations Center (SOC) - Head

SMITS, Inc. - IT Company of San Miguel Corporation • Mandaluyong

On-site
PHP 900,000 - 1,600,000
IT Security Analyst
IT Security Analyst

Ibex Limited • Davao del Sur

On-site
PHP 480,000 - 840,000
Security Operations and Incident Manager
Security Operations and Incident Manager

Private Advertiser • Mandaluyong

On-site
PHP 3,000,000 - 5,000,000
Junior Cyber Security Engineer/Analyst
Junior Cyber Security Engineer/Analyst

PM Consulting • Philippines

On-site
PHP 600,000 - 900,000
Senior Associate – Cyber Operations, Incident Response
Senior Associate – Cyber Operations, Incident Response

Jobtailor • Mexico

On-site
MXN 420,000 - 660,000
Security Incident Response Analyst
Security Incident Response Analyst

Philtech Inc. • Taguig

On-site
PHP 360,000 - 720,000