JOB TITLE:Security Engineer – SIEM/SOC Specialist
WORK SETUP:Onsite, Metro Manila
WORK SHIFT:Shifting schedule
Role Overview
We're hiring Security Engineers to design, implement, and manage security monitoring and automated response capabilities for a leading global organization. You'll work closely with SOC teams, threat analysts, and IT stakeholders to strengthen detection coverage and speed up incident response through automation. This is a great opportunity for a cybersecurity professional looking to work on enterprise-scale SIEM/SOAR programs with a well-established company.
Key Responsibilities
SIEM Engineering & Management
- Design, implement, and optimize SIEM solutions (e.g., Splunk, Microsoft Sentinel, Google SecOps, QRadar, Elastic)
- Develop and maintain correlation rules, dashboards, and reports to identify threats and anomalies
- Integrate diverse data sources (network, endpoints, cloud, applications) into the SIEM platform
- Enhance data ingestion, parsing, and normalization to improve detection quality and reduce noise
SOAR & Automation
- Implement and manage SOAR platforms (e.g., Cortex XSOAR, Splunk SOAR, IBM Resilient)
- Develop automated playbooks for incident response, alert triage, and threat intelligence enrichment
- Collaborate with SOC analysts to streamline workflows and improve response efficiency
- Maintain integrations with ticketing systems, threat intel feeds, and security tools
Security Engineering & Operations Support
- Support incident response with actionable alerts and automation-driven insights
- Conduct root cause analysis of recurring threats and implement engineering solutions
- Partner with audit and compliance teams to align security controls with regulatory standards
- Provide training and documentation for SOC and IT teams on SIEM/SOAR platforms
Qualifications
Education & Experience
- Bachelor's degree in Cybersecurity, IT, Computer Science, or a related field
- Minimum 5 years of cybersecurity experience, with hands-on SIEM/SOAR engineering exposure
- SOC environment experience highly preferred
Core Technical Skills
- Proven experience with at least one SIEM platform (Splunk, Sentinel, QRadar, ArcSight, Google SecOps)
- Hands-on experience developing SOAR playbooks and automation workflows
- Scripting skills (Python, PowerShell, or Bash) for automation and integrations
- Working knowledge of frameworks such as MITRE ATT&CK, NIST, or CIS Controls
- Familiarity with EDR/XDR, firewalls, IDS/IPS, and cloud security (AWS, Azure, or GCP)
Work Setup
- Willing to work a shifting schedule
- Open to onsite work in Metro Manila
Pre-Screening Questions
- How many years of hands-on experience do you have in cybersecurity, specifically with SIEM and SOAR engineering?
- Which SIEM platforms have you worked with (e.g., Splunk, Microsoft Sentinel, QRadar, ArcSight, Google SecOps, Elastic)?
- Have you designed, implemented, or optimized SIEM solutions? Please describe briefly.
- Which SOAR platforms have you worked with (e.g., Cortex XSOAR, Splunk SOAR, IBM Resilient)?
- What is your current/last monthly salary?
- What is your salary expectation?
- Are you open to working onsite in Metro Manila on a shifting schedule?