Security Operations Center Analyst (Microsoft Sentinel/CrowdStrike/MS Defender)

Optum, a UnitedHealth Group Company

Metro Manila

On-site

PHP 350,000 - 600,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Market Pay
Hybrid work
Retirement Plan
Medical Plan (HMO) from Day 1
Dental/Optical reimbursements
Life and Disability Insurance
Paid Time-Off
Sick Leave Conversion
Tuition Reimbursement
EAP
Merit Increases
Employee Recognition
Training & Development
Referral Program
Volunteerism
Statutory Benefits

Job summary

Optum is seeking a Level 1 SOC Analyst to monitor security alerts, triage incidents, and support incident response within a 24×7 SOC environment. You will collect logs, perform basic investigations, and escalate to higher tiers as needed to protect the organization.

The role requires 2+ years in Security Operations, familiarity with SIEM and EDR tools, and strong documentation skills. Hybrid work setup and comprehensive benefits are offered.

Qualifications

  • Undergraduate degree or equivalent experience.
  • 2+ years of experience in Security Operations, SOC monitoring, IT security, or related technology roles.
  • Hands-on experience with SIEM-Sentinel & CrowdStrike, MS Defender (hands-on depth).
  • Basic understanding of information security concepts, including monitoring, incident detection, escalation processes.
  • Foundational knowledge of networking and application protocols (HTTP, HTTPS, DNS, FTP, TCP, UDP, ICMP).
  • Exposure to basic malware analysis concepts and threat intelligence lookups.
  • Basic understanding of Windows/Linux and common attack techniques.
  • Ability to communicate risks clearly to business stakeholders.
  • Awareness of Indicators of Compromise (IOCs).
  • Strong documentation and communication skills; autonomous and detail-oriented.

Responsibilities

  • Continuously monitor security alerts and events across endpoint, network, cloud, email, and identity security tools in a 24×7 SOC environment.
  • Perform initial triage and validation of security alerts to identify false positives and potential security incidents.
  • Conduct basic investigation and analysis using SIEM, EDR, firewall, proxy, and cloud logs to determine context and impact.
  • Collect and preserve initial forensic artifacts for escalation.
  • Perform basic malware analysis using hash lookups and sandbox verdicts.
  • Create and maintain clear incident tickets with thorough documentation.
  • Escalate confirmed or suspected incidents to SOC L2/L3 or Incident Response teams.
  • Assist senior analysts during incident response and containment activities.

Education

Undergraduate degree or equivalent experience

Tools

Sentinel SIEM
CrowdStrike
MS Defender

Job description

The Level 1 Security Operations Center (SOC) Analyst role supports the SecOps team by providing continuous monitoring, initial analysis, and triage of security alerts and events across the organization. This role serves as the first line of defense in detecting potential security incidents and ensuring timely escalation in accordance with defined incident response procedures.

The L1 SOC Analyst is responsible for Monitoring alerts from SIEM, EDR, email security, and other security monitoring tools to identify suspicious activity, validate true positives, and document findings. The analyst follows established playbooks and standard operating procedures to perform basic investigations, collect relevant logs and artifacts, and elevate incidents to higher-tier analysts when required.

This role also involves maintaining accurate incident records, supporting SOC workflows, and ensuring adherence to security policies, SLAs, and escalation criteria, while contributing to overall situational awareness and operational effectiveness of the SOC.

Job Responsibilities:
  • Continuously monitor security alerts and events across endpoint, network, cloud, email, and identity security tools in a 24×7 SOC environment

  • Perform initial triage and validation of security alerts to identify false positives, benign activity, and potential security incidents in accordance with defined playbooks and SOPs

  • Conduct basic investigation and analysis using SIEM- Sentinel & CrowdStrike, EDR, firewall, proxy, and cloud logs to determine event context, severity, and potential impact

  • Collect and preserve initial forensic artifacts (logs, hashes, timestamps, alerts, screenshots) as part of triage activities, ensuring proper documentation for escalation

  • Perform basic malware analysis tasks (e.g., hash lookups, reputation checks, sandbox AnyRun verdict reviews) using approved tools and threat intelligence sources

  • Create and maintain clear, accurate incident tickets and alert documentation, capturing the who, what, when, and how in plain business language

  • Escalate confirmed or suspected security incidents to SOC L2/L3 or Incident Response teams with well-documented findings and supporting evidence

  • Assist senior analysts during incident response, containment, and eradication activities by providing timely data, logs, and analysis

  • Support the creation and refinement of Indicators of Compromise (IOCs) and detection logic based on observed activity and investigation outcomes

  • Follow incident handling SLAs, escalation criteria, and communication protocols to ensure timely response and business impact reduction

  • Participate in security drills, tabletop exercises, and attack simulations to validate detection capabilities and SOC readiness

  • Contribute to post-incident reviews and lessons learned by providing investigation inputs and observations

  • Work closely with security control owners to support alert tuning, playbook updates, and continuous improvement of SOC processes

  • Demonstrate awareness of risk acceptance and risk exception concepts, escalating identified risks in line with organizational policies

  • Adhere to shift handover procedures, ensuring continuity of operations across 24×7 SOC shifts

  • Comply with the terms and conditions of the employment contract, company policies and procedures, and any and all directives (such as, but not limited to, transfer and/or re-assignment to different work locations, change in teams and/or work shifts, policies in regards to flexibility of work benefits and/or work environment, alternative work arrangements, and other decisions that may arise due to the changing business environment). The Company may adopt, vary or rescind these policies and directives in its absolute discretion and without any limitation (implied or otherwise) on its ability to do so

Job Qualifications:
  • Undergraduate degree or equivalent experience.

  • 2+ years of experience in Security Operations, SOC monitoring, IT security, or related technology roles.

  • Hands-on experience with SIEM-Sentinel & CrowdStrike, MS Defender (hands-on depth)

  • Basic understanding of information security concepts, including security monitoring, incident detection, alert triage, and escalation processes

  • Foundational knowledge of networking and application protocols such as HTTP, HTTPS, DNS, FTP, TCP, UDP, and ICMP, with the ability to interpret security alerts related to these protocols

  • Exposure to basic malware analysis concepts, such as hash analysis, reputation checks, sandbox verdict interpretation, and threat intelligence lookups

  • Basic understanding of operating systems (Windows/Linux) and common attack techniques such as phishing, malware delivery, and credential misuse

  • Understanding of the technology risks that are inherent to a business and an ability to effectively communicate those risks

  • Awareness of Indicators of Compromise (IOCs), including IPs, domains, URLs, file hashes, and how they are used in detection and investigations

  • Demonstrated solid documentation and communication skills, with the ability to clearly record investigation findings and elevate issues in plain, business-friendly language

  • Demonstrated ability to be creative and autonomous

  • Basic project management skills and detail orientation

  • Ability to perform initial log analysis using firewall, server, endpoint, and cloud logs to identify suspicious or anomalous activity

What We Offer:
  • Market Competitive Pay Levels

  • Hybrid Work Set-up

  • Retirement Plan

  • Medical Plan (HMO) from Day 1 of employment

  • Dental, Medical, and Optical Reimbursements

  • Life and Disability Insurance

  • Paid Time-Off Benefits

  • Sick Leave Conversion

  • Tuition Reimbursement

  • Employee Assistance Program (EAP)

  • Annual Performance Based Merit Increases

  • Employee Recognition

  • Training and Staff Development

  • Employee Referral Program

  • Employee Volunteerism Opportunity

  • All Mandatory Statutory Benefits

Who We Are:
  • Optum is the health care technology and innovation company of the UnitedHealth Group enterprise along with UnitedHealthcare.

  • UnitedHealth Group is a health care and well-being company with a mission to help people live healthier lives and help make the health system work better for everyone.

  • We’re a leading health solution and care delivery organization. Our work is complex, but our mission is simple: create a healthier world, with you at the center.

  • As part of a Fortune 5 enterprise, we are improving the health care experience of over 125 million people around the world.

  • Elevate your career with a leading health care company while improving lives.

Join us in evolving health care so everyone can have the opportunity to live their healthiest life. This is your opportunity to be part of a team that’s dedicated to Caring. Connecting. Growing together.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

Optum, a UnitedHealth Group Company • Metro Manila

Hybrid
PHP 420,000 - 650,000
Hybrid Work Set-up
Medical Plan (HMO) from Day 1
Dental, Medical, and Optical Reimburse
Information Security Engineer Analyst - SOC Analyst
Information Security Engineer Analyst - SOC Analyst

Optum Philippines • Muntinlupa

On-site
PHP 300,000 - 520,000
Cyber Threat Intelligence Analyst
Cyber Threat Intelligence Analyst

Optum, a UnitedHealth Group Company • Metro Manila

On-site
PHP 900,000 - 1,300,000
Market Competitive Pay Levels
Retirement Plan
Medical Plan (HMO) from Day 1 of work
+2
Information Security Engineer Analyst
Information Security Engineer Analyst

Optum Philippines • Muntinlupa

On-site
PHP 480,000 - 720,000
Sr Info Sec Engineer - Risk GRC, Vendor, Education Training & Awareness
Sr Info Sec Engineer - Risk GRC, Vendor, Education Training & Awareness

Optum • Metro Manila

Hybrid
PHP 900,000 - 1,300,000
Hybrid
Laptop Provided
Medical Plan
+11
Network Consultant | Data Center & Enterprise Network (SD-WAN)
Network Consultant | Data Center & Enterprise Network (SD-WAN)

Optum, a UnitedHealth Group Company • Metro Manila

On-site
PHP 1,200,000 - 2,100,000
Market Competitive Pay Levels
Retirement Plan
Medical Plan (HMO) from Day 1
+12
Workplace Services Engineer
Workplace Services Engineer

Optum, a UnitedHealth Group Company • Metro Manila

On-site
PHP 1,200,000 - 1,800,000
Market Competitive Pay Levels
Retirement Plan
Medical Plan (HMO) from Day 1
Cybersecurity Operations Analyst
Cybersecurity Operations Analyst

UL Solutions • Makati

On-site
PHP 600,000 - 900,000
InfoSec Engineer (GRC & Vendor Risk Management)
InfoSec Engineer (GRC & Vendor Risk Management)

Optum, a UnitedHealth Group Company • Metro Manila

Hybrid
PHP 1,000,000 - 1,400,000
Hybrid
Laptop provided by the company
Total rewards package
+13
Senior SQL Server Database Administrator
Senior SQL Server Database Administrator

Optum, a UnitedHealth Group Company • Metro Manila

Hybrid
PHP 1,339,000 - 2,009,000
Hybrid
Laptop Provided by Company
Medical Plan (HMO) from Day 1
+12