A complete application in a minute — tailored resume and cover letter, ready to send.
Gratitude Philippines seeks an experienced Security Engineer (SIEM/SOC) to design, deploy, and optimize enterprise SIEM and SOAR solutions in Manila. You will integrate diverse data sources, develop detection logic, and automate responses while collaborating with SOC teams to improve detection and incident handling.
The ideal candidate has 5+ years in cybersecurity with strong SIEM engineering background and SOC exposure, and is prepared to work onsite in Manila with a shifting schedule.
Security Engineer – SIEM / SOC (Cybersecurity)
Work Setup: Onsite – Manila (Cyberpark, Cubao)
Work Schedule: Shifting Schedule
We are seeking experienced Security Engineers (SIEM/SOC) who are passionate about cybersecurity, security monitoring, detection engineering, and security automation. In this role, you will design, implement, and optimize enterprise SIEM and SOAR solutions that improve threat detection, accelerate incident response, and strengthen overall security operations.
You will work closely with SOC Analysts, Threat Hunters, Incident Responders, and IT Infrastructure teams to enhance security visibility across enterprise environments.
Design, deploy, administer, and optimize enterprise SIEM platforms.
Build and maintain correlation rules, detection logic, dashboards, alerts, and security reports.
Integrate log sources from endpoints, servers, network devices, cloud platforms, applications, and security appliances.
Improve data ingestion, parsing, normalization, and enrichment for higher-quality detections and reduced false positives.
Continuously enhance detection coverage based on emerging threats and attack techniques.
Implement and administer enterprise SOAR platforms.
Develop automated incident response playbooks and workflows.
Automate alert triage, enrichment, threat intelligence correlation, and remediation tasks.
Integrate SIEM, ticketing systems, EDR/XDR, threat intelligence feeds, and other security technologies.
Collaborate with SOC teams to improve response efficiency and reduce manual effort.
Support Security Operations Center (SOC) teams during incident investigations.
Develop engineering solutions that address recurring threats and operational gaps.
Perform root cause analysis and recommend long-term security improvements.
Maintain documentation, standard operating procedures, and knowledge articles.
Provide technical guidance and enablement to SOC analysts and IT teams.
Support security control implementation aligned with industry best practices.
Partner with internal stakeholders to ensure compliance with organizational and regulatory security requirements.
Contribute to continuous improvement initiatives across cybersecurity operations.
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related discipline.
At least 5 years of hands-on cybersecurity experience.
Strong experience in SIEM engineering within enterprise environments.
Previous experience working in a Security Operations Center (SOC) is highly preferred.
Hands-on experience with one or more SIEM technologies, including:
Splunk Enterprise Security
Microsoft Sentinel
IBM QRadar
ArcSight
Google SecOps
Elastic SIEM
Experience with one or more SOAR platforms such as:
Cortex XSOAR
Splunk SOAR
IBM Resilient
Additional technical expertise:
Python, PowerShell, or Bash scripting
Security automation and orchestration
MITRE ATT&CK Framework
NIST Cybersecurity Framework
CIS Controls
EDR/XDR technologies
Firewalls
IDS/IPS
Cloud security (AWS, Microsoft Azure, or Google Cloud Platform)
Candidates with one or more of the following will have an advantage:
SIEM content development
Detection engineering
Threat hunting
Incident response automation
Log management
Security analytics
Threat intelligence integration
Cloud security monitoring
DevSecOps exposure
Security engineering certifications (Splunk, Microsoft, IBM, CompTIA Security+, GIAC, Microsoft Security, AWS Security, etc.)
Willing to work onsite in Manila (Cyberpark, Cubao).
Amenable to a shifting schedule.
Able to work effectively in a fast-paced enterprise cybersecurity environment.
We're looking for professionals who have experience in roles such as:
Security Engineer
SIEM Engineer
SOC Engineer
Detection Engineer
Cybersecurity Engineer
Security Operations Engineer
Security Automation Engineer
Blue Team Engineer
Incident Response Engineer
Security Platform Engineer
Initial profile validation
Recruiter screening
Client CV review
Interview process
How many years of hands-on cybersecurity experience do you have?
How many years of SIEM engineering experience do you have?
Which SIEM platforms have you worked with? (Splunk, Microsoft Sentinel, QRadar, ArcSight, Google SecOps, Elastic, etc.)
Have you designed, implemented, or optimized enterprise SIEM environments? Please describe your experience.
Which SOAR platforms have you used (Cortex XSOAR, Splunk SOAR, IBM Resilient, etc.)?
What scripting languages do you use for automation (Python, PowerShell, Bash)?
Do you have experience working in a Security Operations Center (SOC)?
Are you willing to work onsite in Manila on a shifting schedule?