Security Engineer – SIEM / SOC (Cybersecurity)
Work Setup: Onsite – Manila (Cyberpark, Cubao) Work Schedule: Shifting Schedule
Build the Future of Cyber Defense
We are seeking experienced Security Engineers (SIEM/SOC) who are passionate about cybersecurity, security monitoring, detection engineering, and security automation. In this role, you will design, implement, and optimize enterprise SIEM and SOAR solutions that improve threat detection, accelerate incident response, and strengthen overall security operations.
You will work closely with SOC Analysts, Threat Hunters, Incident Responders, and IT Infrastructure teams to enhance security visibility across enterprise environments.
Key Responsibilities
SIEM Engineering & Security Monitoring
- Design, deploy, administer, and optimize enterprise SIEM platforms.
- Build and maintain correlation rules, detection logic, dashboards, alerts, and security reports.
- Integrate log sources from endpoints, servers, network devices, cloud platforms, applications, and security appliances.
- Improve data ingestion, parsing, normalization, and enrichment for higher-quality detections and reduced false positives.
- Continuously enhance detection coverage based on emerging threats and attack techniques.
SOAR & Security Automation
- Implement and administer enterprise SOAR platforms.
- Develop automated incident response playbooks and workflows.
- Automate alert triage, enrichment, threat intelligence correlation, and remediation tasks.
- Integrate SIEM, ticketing systems, EDR/XDR, threat intelligence feeds, and other security technologies.
- Collaborate with SOC teams to improve response efficiency and reduce manual effort.
Security Operations & Incident Response
- Support Security Operations Center (SOC) teams during incident investigations.
- Develop engineering solutions that address recurring threats and operational gaps.
- Perform root cause analysis and recommend long-term security improvements.
- Maintain documentation, standard operating procedures, and knowledge articles.
- Provide technical guidance and enablement to SOC analysts and IT teams.
Governance, Risk & Compliance
- Support security control implementation aligned with industry best practices.
- Partner with internal stakeholders to ensure compliance with organizational and regulatory security requirements.
- Contribute to continuous improvement initiatives across cybersecurity operations.
Qualifications
Required Experience
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related discipline.
- At least 5 years of hands-on cybersecurity experience.
- Strong experience in SIEM engineering within enterprise environments.
- Previous experience working in a Security Operations Center (SOC) is highly preferred.
Technical Skills
Hands-on experience with one or more SIEM technologies, including:
- Splunk Enterprise Security
- Microsoft Sentinel
- IBM QRadar
- ArcSight
- Google SecOps
- Elastic SIEM
Experience with one or more SOAR platforms such as:
- Cortex XSOAR
- Splunk SOAR
- IBM Resilient
Additional technical expertise:
- Python, PowerShell, or Bash scripting
- Security automation and orchestration
- MITRE ATT&CK Framework
- NIST Cybersecurity Framework
- CIS Controls
- EDR/XDR technologies
- Firewalls
- IDS/IPS
- Cloud security (AWS, Microsoft Azure, or Google Cloud Platform)
Preferred Qualifications
Candidates with one or more of the following will have an advantage:
- SIEM content development
- Detection engineering
- Threat hunting
- Incident response automation
- Log management
- Security analytics
- Threat intelligence integration
- Cloud security monitoring
- DevSecOps exposure
- Security engineering certifications (Splunk, Microsoft, IBM, CompTIA Security+, GIAC, Microsoft Security, AWS Security, etc.)
Work Arrangement
- Willing to work onsite in Manila (Cyberpark, Cubao).
- Amenable to a shifting schedule.
- Able to work effectively in a fast-paced enterprise cybersecurity environment.
Ideal Candidate
We're looking for professionals who have experience in roles such as:
- Security Engineer
- SIEM Engineer
- SOC Engineer
- Detection Engineer
- Cybersecurity Engineer
- Security Operations Engineer
- Security Automation Engineer
- Blue Team Engineer
- Incident Response Engineer
- Security Platform Engineer
Recruitment Process
- Initial profile validation
- Recruiter screening
- Client CV review
- Interview process
Pre-Screening Questions
- How many years of hands-on cybersecurity experience do you have?
- How many years of SIEM engineering experience do you have?
- Which SIEM platforms have you worked with? (Splunk, Microsoft Sentinel, QRadar, ArcSight, Google SecOps, Elastic, etc.)
- Have you designed, implemented, or optimized enterprise SIEM environments? Please describe your experience.
- Which SOAR platforms have you used (Cortex XSOAR, Splunk SOAR, IBM Resilient, etc.)?
- What scripting languages do you use for automation (Python, PowerShell, Bash)?
- Do you have experience working in a Security Operations Center (SOC)?
- Are you willing to work onsite in Manila on a shifting schedule?