Security Engineer – SIEM / SOC (Cybersecurity)

Gratitude Philippines

Quezon City

On-site

PHP 900,000 - 1,300,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Gratitude Philippines seeks an experienced Security Engineer (SIEM/SOC) to design, deploy, and optimize enterprise SIEM and SOAR solutions in Manila. You will integrate diverse data sources, develop detection logic, and automate responses while collaborating with SOC teams to improve detection and incident handling.

The ideal candidate has 5+ years in cybersecurity with strong SIEM engineering background and SOC exposure, and is prepared to work onsite in Manila with a shifting schedule.

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related discipline.
  • At least 5 years of hands-on cybersecurity experience.
  • Strong experience in SIEM engineering within enterprise environments.
  • Previous experience working in a SOC is highly preferred.

Responsibilities

  • Design, deploy, administer, and optimize enterprise SIEM platforms.
  • Build and maintain correlation rules, detection logic, dashboards, alerts, and security reports.
  • Integrate log sources from endpoints, servers, network devices, cloud platforms, applications, and security appliances.
  • Improve data ingestion, parsing, normalization, and enrichment for higher-quality detections and reduced false positives.
  • Continuously enhance detection coverage based on emerging threats and attack techniques.
  • Implement and administer enterprise SOAR platforms.
  • Develop automated incident response playbooks and workflows.
  • Automate alert triage, enrichment, threat intelligence correlation, and remediation tasks.
  • Integrate SIEM, ticketing systems, EDR/XDR, threat intelligence feeds, and other security technologies.
  • Collaborate with SOC teams to improve response efficiency and reduce manual effort.
  • Support SOC during incident investigations.
  • Develop engineering solutions addressing recurring threats and gaps.
  • Perform root cause analysis and recommend long-term security improvements.
  • Maintain documentation, SOPs, and knowledge articles.
  • Provide technical guidance to SOC analysts and IT teams.
  • Support security control implementation aligned with best practices.
  • Partner with stakeholders to ensure compliance with security requirements.
  • Contribute to continuous improvements across cybersecurity operations.

Skills

SIEM engineering
SOC
Threat hunting
Security automation
Python scripting

Education

Bachelor's degree in Cybersecurity/IT/CS

Tools

Splunk ES
Microsoft Sentinel
IBM QRadar
ArcSight
Google SecOps
Elastic SIEM
Cortex XSOAR
Splunk SOAR
IBM Resilient

Job description

Security Engineer – SIEM / SOC (Cybersecurity)

Work Setup: Onsite – Manila (Cyberpark, Cubao)
Work Schedule: Shifting Schedule

Build the Future of Cyber Defense

We are seeking experienced Security Engineers (SIEM/SOC) who are passionate about cybersecurity, security monitoring, detection engineering, and security automation. In this role, you will design, implement, and optimize enterprise SIEM and SOAR solutions that improve threat detection, accelerate incident response, and strengthen overall security operations.

You will work closely with SOC Analysts, Threat Hunters, Incident Responders, and IT Infrastructure teams to enhance security visibility across enterprise environments.

Key Responsibilities
SIEM Engineering & Security Monitoring
  • Design, deploy, administer, and optimize enterprise SIEM platforms.

  • Build and maintain correlation rules, detection logic, dashboards, alerts, and security reports.

  • Integrate log sources from endpoints, servers, network devices, cloud platforms, applications, and security appliances.

  • Improve data ingestion, parsing, normalization, and enrichment for higher-quality detections and reduced false positives.

  • Continuously enhance detection coverage based on emerging threats and attack techniques.

SOAR & Security Automation
  • Implement and administer enterprise SOAR platforms.

  • Develop automated incident response playbooks and workflows.

  • Automate alert triage, enrichment, threat intelligence correlation, and remediation tasks.

  • Integrate SIEM, ticketing systems, EDR/XDR, threat intelligence feeds, and other security technologies.

  • Collaborate with SOC teams to improve response efficiency and reduce manual effort.

Security Operations & Incident Response
  • Support Security Operations Center (SOC) teams during incident investigations.

  • Develop engineering solutions that address recurring threats and operational gaps.

  • Perform root cause analysis and recommend long-term security improvements.

  • Maintain documentation, standard operating procedures, and knowledge articles.

  • Provide technical guidance and enablement to SOC analysts and IT teams.

Governance, Risk & Compliance
  • Support security control implementation aligned with industry best practices.

  • Partner with internal stakeholders to ensure compliance with organizational and regulatory security requirements.

  • Contribute to continuous improvement initiatives across cybersecurity operations.

Qualifications
Required Experience
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related discipline.

  • At least 5 years of hands-on cybersecurity experience.

  • Strong experience in SIEM engineering within enterprise environments.

  • Previous experience working in a Security Operations Center (SOC) is highly preferred.

Technical Skills

Hands-on experience with one or more SIEM technologies, including:

  • Splunk Enterprise Security

  • Microsoft Sentinel

  • IBM QRadar

  • ArcSight

  • Google SecOps

  • Elastic SIEM

Experience with one or more SOAR platforms such as:

  • Cortex XSOAR

  • Splunk SOAR

  • IBM Resilient

Additional technical expertise:

  • Python, PowerShell, or Bash scripting

  • Security automation and orchestration

  • MITRE ATT&CK Framework

  • NIST Cybersecurity Framework

  • CIS Controls

  • EDR/XDR technologies

  • Firewalls

  • IDS/IPS

  • Cloud security (AWS, Microsoft Azure, or Google Cloud Platform)

Preferred Qualifications

Candidates with one or more of the following will have an advantage:

  • SIEM content development

  • Detection engineering

  • Threat hunting

  • Incident response automation

  • Log management

  • Security analytics

  • Threat intelligence integration

  • Cloud security monitoring

  • DevSecOps exposure

  • Security engineering certifications (Splunk, Microsoft, IBM, CompTIA Security+, GIAC, Microsoft Security, AWS Security, etc.)

Work Arrangement
  • Willing to work onsite in Manila (Cyberpark, Cubao).

  • Amenable to a shifting schedule.

  • Able to work effectively in a fast-paced enterprise cybersecurity environment.

Ideal Candidate

We're looking for professionals who have experience in roles such as:

  • Security Engineer

  • SIEM Engineer

  • SOC Engineer

  • Detection Engineer

  • Cybersecurity Engineer

  • Security Operations Engineer

  • Security Automation Engineer

  • Blue Team Engineer

  • Incident Response Engineer

  • Security Platform Engineer

Recruitment Process
  • Initial profile validation

  • Recruiter screening

  • Client CV review

  • Interview process

Pre-Screening Questions
  1. How many years of hands-on cybersecurity experience do you have?

  2. How many years of SIEM engineering experience do you have?

  3. Which SIEM platforms have you worked with? (Splunk, Microsoft Sentinel, QRadar, ArcSight, Google SecOps, Elastic, etc.)

  4. Have you designed, implemented, or optimized enterprise SIEM environments? Please describe your experience.

  5. Which SOAR platforms have you used (Cortex XSOAR, Splunk SOAR, IBM Resilient, etc.)?

  6. What scripting languages do you use for automation (Python, PowerShell, Bash)?

  7. Do you have experience working in a Security Operations Center (SOC)?

  8. Are you willing to work onsite in Manila on a shifting schedule?

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer – SIEM/SOC Specialist
Security Engineer – SIEM/SOC Specialist

Gratitude Philippines • Quezon City

On-site
PHP 900,000 - 1,300,000
Security Engineer
Security Engineer

JetSon Manpower Agency • Manila

Hybrid
Build the Future of Cybersecurity as a SIEM/SOC Security Engineer
Build the Future of Cybersecurity as a SIEM/SOC Security Engineer

Gratitude Philippines • Manila

On-site
PHP 1,000,000 - 1,800,000
Security Engineer (SIEM & SOAR) | Specialist / Team Lead
Security Engineer (SIEM & SOAR) | Specialist / Team Lead

Gratitude Philippines • Manila

Hybrid
PHP 900,000 - 1,300,000
Hybrid work setup
(ACTIVE) Security Engineer (SIEM & SOAR) | Onsite/ Hybrid in QC
(ACTIVE) Security Engineer (SIEM & SOAR) | Onsite/ Hybrid in QC

Gratitude Philippines • Manila

Hybrid
PHP 700,000 - 1,000,000
(ACTIVE) I SIEM Platform Engineer (SIEM & SOAR) I Hybrid in Cubao
(ACTIVE) I SIEM Platform Engineer (SIEM & SOAR) I Hybrid in Cubao

Gratitude Philippines • Manila

Hybrid
PHP 900,000 - 1,700,000
Day 1 HMO and Life Insurance coverage
13th Month Pay
Performance bonus
+4
Security Operations Engineer (SIEM / Cybersecurity)
Security Operations Engineer (SIEM / Cybersecurity)

Recruitify_HR • Taguig

On-site
PHP 600,000 - 900,000
Equity Incentive Plan
Performance Bonus
Health Insurance
+4
Security Operations Engineer (SIEM / Cybersecurity)
Security Operations Engineer (SIEM / Cybersecurity)

Recruitify_HR • Taguig

On-site
PHP 1,000,000 - 1,500,000
Security Engineer (SIEM & SOAR) | Associate Manager
Security Engineer (SIEM & SOAR) | Associate Manager

Gratitude Philippines • Manila

Hybrid
PHP 1,200,000 - 1,800,000
Security Engineer (SIEM & SOAR) | Specialist / Team Lead
Security Engineer (SIEM & SOAR) | Specialist / Team Lead

Gratitude Philippines • Philippines

Hybrid
PHP 1,800,000 - 2,400,000
Hybrid work arrangement
Cubao office location
Shifting schedules