Security Incident Response Analyst

Philtech Inc.

Taguig

On-site

PHP 360,000 - 720,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Albertsons Companies is seeking a Security Operations Center Analyst to join a 24/7 team focused on security operations and incident response. You will analyze logs, respond to events, and document procedures to support continuous improvement.

You will work with SIEM/EDR/SOAR tools, coordinate with internal teams and MSSP partners, and help ensure SLAs are met while protecting critical assets.

Qualifications

  • Expert level knowledge of information technology systems and processes.
  • Proven analytical, problem solving and troubleshooting skills.
  • Ability to quickly learn and apply new concepts.
  • Experience with security operations technologies (SIEM/EDR/SOAR).

Responsibilities

  • Perform log analysis and correlate datasets to identify anomalies.
  • Respond to security events, drive issues to closure with stakeholders.
  • Document security processes and procedures.
  • Support intake of service requests and communicate promptly with requestors.
  • Enforce security policies, standards and procedures.
  • Stay updated on security technologies, trends, and best practices.
  • Participate in Incident Response activities and investigations.
  • Detect, analyze, and respond to cybersecurity threats.
  • Coordinate with MSSP and internal/external teams during events.
  • Ensure SLAs, KRIs, and KPIs are met for service delivery.
  • Interface with CTI for detection development and threat updates.
  • Work on Data Loss Prevention initiatives.
  • Other duties as assigned; may include shift work in a 24/7 SOC.

Skills

IT systems knowledge
Cybersecurity fundamentals
Incident response

Tools

SIEM
EDR
SOAR
Firewall

Job description

What You Will Be Doing

In this role, you will use your knowledge of industry best practices, good judgement, and problem-solving skills to execute security operations and incident response. You will be on the front lines of cyber defense for one of the largest retail organizations in the US. You should be adept at making good decisions under pressure and be able to quickly adapt to any security challenge. You will have a keen attention to detail and be disciplined in documenting process and procedures. You will also be in a support role for requests coming into the team making sure departmental SLAs are met. The Security Operations / Incident Response team goal is operational excellence, continual process improvement and customer service.

What You Will Be Doing

In this role, you will use your knowledge of industry best practices, good judgement, and problem-solving skills to execute security operations and incident response. You will be on the front lines of cyber defense for one of the largest retail organizations in the US. You should be adept at making good decisions under pressure and be able to quickly adapt to any security challenge. You will have a keen attention to detail and be disciplined in documenting process and procedures. You will also be in a support role for requests coming into the team making sure departmental SLAs are met. The Security Operations / Incident Response team goal is operational excellence, continual process improvement and customer service.

Main Responsibilities
  • Perform log analysis and correlate disparate datasets to identify abnormal behavior.
  • Respond to security events, driving issues to closure, and engaging all appropriate resources.
  • Document Security process and procedures.
  • Support service request in-take process and communicate back to requestors promptly.
  • Provide enforcement of security policies, standards, and procedures.
  • Knowing the latest on security technologies, trends, standards, and best practices.
  • Participate Incident Response activities.
  • Detecting, and analyzing cybersecurity threats.
  • Working with our MSSP, responding to internal and external cyber security events.
  • Ensure quality service delivery to internal customers across current and future capabilities including SIEM, Triage/Investigate/Response, Phishing Email Analysis and Response, Threat Detection Development.
  • Ensure service incidents are closed within SLA.
  • Ensure service metrics (SLAs/KRIs/KPIs) are met.
  • Interface with our Cyber Threat Intelligence (CTI) team on detection development and new / upcoming threats.
  • Will be working on Data Loss Protection.
  • Other duties and responsibilities as assigned.
  • This position will be a part of Albertsons Companies 24/7 Security Operations Center and may involve shift work including day, evening, and weekend roles.
What We Are Searching For
  • Expert level knowledge and understanding of information technology systems and process.
  • Experience with IT Service Management. Especially around the delivery of security services.
  • Demonstrated and proven analytical, problem solving and troubleshooting skills.
  • The ability to learn, understand and apply new concepts quickly.
  • Experience writing detection rules, firewall rules, or any other similar detection capability.
  • Comfortable with working with other internal or external organizations regarding security policy and standards violations, security controls failure and incident response situations.
  • Ability to balance and prioritize work.
  • Knowledge of information security principles and practice.
  • A sound understanding of the OSI networking model.
  • Advanced knowledge of networking protocols including DNS, TCP/IP, UDP.
  • Experience with Windows Server/Workstation and Mac OS is required.
  • Advanced level knowledge and experience with EDR, antivirus, anti-malware and proxy solutions.
  • Must be trustworthy in keeping sensitive data confidential.
  • Thorough understanding of current attack tools, tactics, procedures, and how to detect and/or mitigate them.
  • Experienced and in-depth knowledge in Data Loss Protection.
We believe the successful candidate has these qualifications and experience:
  • Experience working within Enterprise SOC operations.
  • Experience with security operations technologies including SIEM, EDR, Cyber Threat Intelligence, Adversary Hunting, and Security Orchestration (SOAR) or other applicable experience.
  • Comfortable participating in Incident Response Investigations, Incident Response Plan execution.
  • Performing appropriate forensic procedures to capture and preserve evidence for future use and analysis in a manner that allows for appropriate chain of custody.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Specialist InfoSec Analyst
Specialist InfoSec Analyst

Philtech Inc. • Taguig

On-site
PHP 350,000 - 600,000
IT Security Specialist
IT Security Specialist

ibex • Mandaluyong

On-site
PHP 420,000 - 640,000
IT Security Specialist
IT Security Specialist

Ibex Limited • Manila

On-site
PHP 600,000 - 900,000
Cyber Incident Response Specialist
Cyber Incident Response Specialist

Philtech Inc. • Taguig

On-site
PHP 360,000 - 720,000
Incident Response Analyst
Incident Response Analyst

PM Consulting • Philippines

On-site
PHP 400,000 - 600,000
IT Security Analyst
IT Security Analyst

Ibex Limited • Davao del Sur

On-site
PHP 480,000 - 840,000
IT Security Analyst
IT Security Analyst

IBEX Global Solutions (Philippines) Inc. • Davao del Sur

On-site
PHP 420,000 - 560,000
Security Operations Analyst
Security Operations Analyst

THOMSON REUTERS CORP PTE LTD - PHILIPPINE BRANCH • Taguig

Hybrid
PHP 600,000 - 900,000
Security Operations and Incident Manager
Security Operations and Incident Manager

Private Advertiser • Mandaluyong

On-site
PHP 3,000,000 - 5,000,000
Security Analyst / Network Security Analyst
Security Analyst / Network Security Analyst

RippedBoxStation • Philippines

On-site
PHP 260,000 - 420,000