Security Analyst – SOC

Moder Solutions Inc.

Cebu City

On-site

PHP 420,000 - 720,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Moder Solutions Inc. in Cebu City is seeking an experienced Security Analyst to support SOC activities, including real-time monitoring, incident detection and response, and vulnerability assessment.

The role collaborates with infrastructure, network, server, and application teams to address threats within defined SLAs. Hands-on experience with SIEM, CrowdStrike, FortiGate, Windows/Linux environments, Active Directory, and ServiceNow is required, along with strong analytical and communication

Qualifications

  • 3–5 years of relevant experience in Cybersecurity, Information Security, or Security Operations.
  • Strong understanding of SOC operations, security monitoring, incident investigation, incident response, and log analysis.
  • Experience with Endpoint Detection & Response / Endpoint Security, preferably CrowdStrike.
  • Experience monitoring and analyzing firewalls, IDS/IPS, proxies, antivirus, email security, servers, databases, and network security devices.
  • Working knowledge of FortiGate or similar next‑generation firewalls.
  • Good understanding of Windows and Linux server security.
  • Experience with Active Directory, user access privileges, and authentication/sign‑in logs.
  • Experience with ServiceNow or equivalent ITSM/ticketing platforms.
  • Understanding of vulnerability assessment, remediation tracking, and vulnerability reporting.
  • Ability to differentiate false‑positive and true‑positive security alerts through detailed investigation.

Responsibilities

  • Monitor and analyze security alerts and events from SIEM, EDR, firewalls, IDS/IPS, proxies, antivirus, servers, databases, and applications.
  • Perform end‑to‑end security incident investigation and determine true security incidents.
  • Perform root cause analysis and manage incidents per Incident Response frameworks.
  • Monitor network traffic and logs to identify anomalous or malicious activity.
  • Investigate user activity and sign‑in logs using Active Directory and security controls.
  • Escalate incidents to appropriate teams and track through closure.
  • Create and track security incident tickets using ServiceNow, ensuring SLAs are met.
  • Onboard security logs from various sources into monitoring platforms.
  • Conduct vulnerability assessments across OS, ports, apps, and infrastructure.
  • Coordinate vulnerability scans on weekly/monthly/quarterly schedules.
  • Prepare vulnerability, remediation, security incident, compliance, and operational reports.
  • Analyze daily/monthly incident management reports and support security compliance activities.
  • Collaborate with Network/Infrastructure/Server/Application teams to remediate issues.
  • Participate in knowledge-sharing sessions and lessons-learned discussions to improve SOC capabilities.

Skills

SOC operations
log analysis
incident investigation
incident response
vulnerability assessment
EndPoint security
Active Directory
ServiceNow
Windows/Linux security
Analytical skills

Education

Bachelor’s degree in engineering, Computer Science, IT, Cybersecurity, or related

Tools

CrowdStrike
FortiGate
Active Directory
ServiceNow
Windows Server
Linux Server

Job description

Role Summary

We are seeking an experienced Security Analyst to support Security Operations Center activities, including real-time security monitoring, incident detection, investigation, response, vulnerability assessment, and security event analysis. The candidate will work closely with infrastructure, network, server, and application teams to identify, investigate, contain, and remediate security threats while ensuring incidents are addressed within defined SLAs.

The role requires hands‑on experience with SIEM platforms, endpoint security tools such as CrowdStrike, next‑generation firewalls such as FortiGate, Windows/Linux environments, Active Directory, and ServiceNow.

Key Responsibilities
  • Monitor and analyze security alerts and events generated from SIEM, EDR, firewalls, IDS/IPS, proxy servers, antivirus solutions, databases, applications, Windows/Linux servers, and other network security devices.
  • Perform end‑to‑end security incident investigation and determine whether security events represent false positives or true security incidents.
  • Perform root cause analysis and manage incidents in accordance with established Incident Response and Incident Management frameworks.
  • Monitor network traffic and security logs to identify anomalous behavior, attempted compromises, and potentially malicious activity.
  • Investigate user activity, sign‑in logs, and access privileges using Active Directory and related security controls.
  • Escalate confirmed security incidents to appropriate infrastructure, network, server, application, and management teams and track incidents through closure.
  • Create, manage, and track security incident tickets using ServiceNow, ensuring incidents are resolved within agreed SLAs.
  • Configure and onboard security logs from firewalls, IDS/IPS, Windows servers, Linux servers, databases, and applications into monitoring platforms.
  • Conduct vulnerability assessments across operating systems, ports, applications, hardware, servers, and network infrastructure.
  • Coordinate vulnerability scans for critical servers and applications on weekly, monthly, and quarterly schedules.
  • Prepare vulnerability, remediation, security incident, compliance, and operational reports.
  • Analyze daily and monthly incident management reports and support security compliance activities.
  • Collaborate with Network, Infrastructure, Server, and Application teams to troubleshoot and remediate security issues.
  • Participate in knowledge‑sharing sessions, incident reviews, and lessons‑learned discussions to improve SOC capabilities and security processes.
Required Skills & Experience
  • 3–5 years of relevant experience in Cybersecurity, Information Security, or Security Operations.
  • Strong understanding of SOC operations, security monitoring, incident investigation, incident response, and log analysis.
  • Experience with Endpoint Detection & Response / Endpoint Security, preferably CrowdStrike.
  • Experience monitoring and analyzing firewalls, IDS/IPS, proxies, antivirus, email security, servers, databases, and network security devices.
  • Working knowledge of FortiGate or similar next‑generation firewalls.
  • Good understanding of Windows and Linux server security.
  • Experience working with Active Directory, user access privileges, and authentication/sign‑in logs.
  • Experience with ServiceNow or equivalent ITSM/ticketing platforms.
  • Understanding of vulnerability assessment, remediation tracking, and vulnerability reporting.
  • Ability to differentiate false‑positive and true‑positive security alerts through detailed investigation.
  • Knowledge of SLA‑driven incident management and security escalation procedures.
  • Strong analytical, troubleshooting, documentation, and communication skills.
Education

Bachelor’s degree in engineering, Computer Science, Information Technology, Cybersecurity, or a related discipline.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Analyst
IT Security Analyst

Ibex Limited • Davao del Sur

On-site
PHP 480,000 - 840,000
SOC Analyst
SOC Analyst

Paynamics • Philippines

On-site
PHP 600,000 - 900,000
Security Analyst / Network Security Analyst
Security Analyst / Network Security Analyst

RippedBoxStation • Philippines

On-site
PHP 260,000 - 420,000
SOC Analyst/Incident Response Analyst
SOC Analyst/Incident Response Analyst

PM Consulting • Metro Manila

On-site
PHP 320,000 - 520,000
IT Security Analyst
IT Security Analyst

IBEX Global Solutions (Philippines) Inc. • Davao del Sur

On-site
PHP 420,000 - 560,000
Senior Security Engineer – SOC
Senior Security Engineer – SOC

42 Gears Mobility Systems • Hinoba-an

On-site
PHP 995,000 - 1,592,000
SOC Analyst
SOC Analyst

Commit • Metro Manila

On-site
PHP 350,000 - 550,000
Junior SOC Analyst
Junior SOC Analyst

Kinettix Inc. • Manila

On-site
Associate Security Analyst
Associate Security Analyst

itm8 PH • Dumaguete

On-site
PHP 420,000 - 680,000
SOC Analyst – Splunk ES
SOC Analyst – Splunk ES

Outsourcea Services Incorporated • Pasay

On-site
PHP 600,000 - 900,000