Security Operations Center (SOC) Analyst

Optum, a UnitedHealth Group Company

Metro Manila

On-site

PHP 420,000 - 650,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid Work Set-up
Medical Plan (HMO) from Day 1
Dental, Medical, and Optical Reimburse

Job summary

Optum, a UnitedHealth Group Company, is seeking a Level 1 SOC Analyst to monitor and triage security alerts across endpoint, network, cloud, email, and identity security tools in a 24×7 SOC environment.

You will perform initial analysis, collect logs, validate true positives, and escalate to L2/L3 when required, following playbooks and incident response procedures.

Qualifications

  • Undergraduate degree or equivalent experience.
  • 2+ years of experience in Security Operations or related roles.
  • Basic understanding of information security concepts and incident handling.
  • Familiarity with SIEM, EDR, firewall, and cloud security tools.

Responsibilities

  • Continuously monitor security alerts and events in a 24×7 SOC environment.
  • Perform initial triage and validation of alerts to identify false positives and incidents.
  • Conduct basic investigation using SIEM and logs to determine context, severity and impact.
  • Collect and preserve logs and artifacts for escalation.
  • Escalate confirmed or suspected incidents to higher tiers with documented evidence.
  • Assist senior analysts during incident response and remediation activities.
  • Support the creation and refinement of IOCs and detection logic.
  • Follow SLAs and incident handling procedures to minimize business impact.
  • Contribute to post-incident reviews and improve SOC processes.

Skills

SOC monitoring
SIEM
EDR
Incident escalation
Log analysis
Documentation
Basic malware analysis

Education

Undergraduate degree or equivalent experience

Tools

Sentinel
CrowdStrike
Firewall

Job description

The Level 1 Security Operations Center (SOC) Analyst role supports the SecOps team by providing continuous monitoring, initial analysis, and triage of security alerts and events across the organization. This role serves as the first line of defense in detecting potential security incidents and ensuring timely escalation in accordance with defined incident response procedures.

The L1 SOC Analyst is responsible for Monitoring alerts from SIEM, EDR, email security, and other security monitoring tools to identify suspicious activity, validate true positives, and document findings. The analyst follows established playbooks and standard operating procedures to perform basic investigations, collect relevant logs and artifacts, and elevate incidents to higher-tier analysts when required.

This role also involves maintaining accurate incident records, supporting SOC workflows, and ensuring adherence to security policies, SLAs, and escalation criteria, while contributing to overall situational awareness and operational effectiveness of the SOC.

Job Responsibilities:
  • Continuously monitor security alerts and events across endpoint, network, cloud, email, and identity security tools in a 24×7 SOC environment

  • Perform initial triage and validation of security alerts to identify false positives, benign activity, and potential security incidents in accordance with defined playbooks and SOPs

  • Conduct basic investigation and analysis using SIEM- Sentinel & CrowdStrike, EDR, firewall, proxy, and cloud logs to determine event context, severity, and potential impact

  • Collect and preserve initial forensic artifacts (logs, hashes, timestamps, alerts, screenshots) as part of triage activities, ensuring proper documentation for escalation

  • Perform basic malware analysis tasks (e.g., hash lookups, reputation checks, sandbox AnyRun verdict reviews) using approved tools and threat intelligence sources

  • Create and maintain clear, accurate incident tickets and alert documentation, capturing the who, what, when, and how in plain business language

  • Escalate confirmed or suspected security incidents to SOC L2/L3 or Incident Response teams with well-documented findings and supporting evidence

  • Assist senior analysts during incident response, containment, and eradication activities by providing timely data, logs, and analysis

  • Support the creation and refinement of Indicators of Compromise (IOCs) and detection logic based on observed activity and investigation outcomes

  • Follow incident handling SLAs, escalation criteria, and communication protocols to ensure timely response and business impact reduction

  • Participate in security drills, tabletop exercises, and attack simulations to validate detection capabilities and SOC readiness

  • Contribute to post-incident reviews and lessons learned by providing investigation inputs and observations

  • Work closely with security control owners to support alert tuning, playbook updates, and continuous improvement of SOC processes

  • Demonstrate awareness of risk acceptance and risk exception concepts, escalating identified risks in line with organizational policies

  • Adhere to shift handover procedures, ensuring continuity of operations across 24×7 SOC shifts

  • Comply with the terms and conditions of the employment contract, company policies and procedures, and any and all directives (such as, but not limited to, transfer and/or re-assignment to different work locations, change in teams and/or work shifts, policies in regards to flexibility of work benefits and/or work environment, alternative work arrangements, and other decisions that may arise due to the changing business environment). The Company may adopt, vary or rescind these policies and directives in its absolute discretion and without any limitation (implied or otherwise) on its ability to do so

Job Qualifications:
  • Undergraduate degree or equivalent experience.

  • 2+ years of experience in Security Operations, SOC monitoring, IT security, or related technology roles. (Internship, training, or lab-based experience is acceptable for entry-level candidates.)

  • Basic understanding of information security concepts, including security monitoring, incident detection, alert triage, and escalation processes

  • Foundational knowledge of networking and application protocols such as HTTP, HTTPS, DNS, FTP, TCP, UDP, and ICMP, with the ability to interpret security alerts related to these protocols

  • Familiarity with SIEM-Sentinel & CrowdStrike, EDR, firewall, email security, and cloud security tools for alert review and investigation (hands-on depth not required)

  • Exposure to basic malware analysis concepts, such as hash analysis, reputation checks, sandbox verdict interpretation, and threat intelligence lookups

  • Basic understanding of operating systems (Windows/Linux) and common attack techniques such as phishing, malware delivery, and credential misuse

  • Understanding of the technology risks that are inherent to a business and an ability to effectively communicate those risks

  • Awareness of Indicators of Compromise (IOCs), including IPs, domains, URLs, file hashes, and how they are used in detection and investigations

  • Demonstrated solid documentation and communication skills, with the ability to clearly record investigation findings and escalated issues in plain, business-friendly language

  • Demonstrated ability to be creative and autonomous

  • Basic project management skills and detail orientation

  • Ability to perform initial log analysis using firewall, server, endpoint, and cloud logs to identify suspicious or anomalous activity

  • Ability to work effectively in a 24×7 shift-based SOC environment, including following handover procedures and SLAs

What We Offer:
  • Market Competitive Pay Levels

  • Hybrid Work Set-up

  • Retirement Plan

  • Medical Plan (HMO) from Day 1 of employment

  • Dental, Medical, and Optical Reimbursements

  • Life and Disability Insurance

  • Paid Time-Off Benefits

  • Sick Leave Conversion

  • Tuition Reimbursement

  • Employee Assistance Program (EAP)

  • Annual Performance Based Merit Increases

  • Employee Recognition

  • Training and Staff Development

  • Employee Referral Program

  • Employee Volunteerism Opportunity

  • All Mandatory Statutory Benefits

Who We Are:
  • Optum is the health care technology and innovation company of the UnitedHealth Group enterprise along with UnitedHealthcare.

  • UnitedHealth Group is a health care and well-being company with a mission to help people live healthier lives and help make the health system work better for everyone.

  • We’re a leading health solution and care delivery organization. Our work is complex, but our mission is simple: create a healthier world, with you at the center.

  • As part of a Fortune 5 enterprise, we are improving the health care experience of over 125 million people around the world.

  • Elevate your career with a leading health care company while improving lives.

Join us in evolving health care so everyone can have the opportunity to live their healthiest life. This is your opportunity to be part of a team that’s dedicated to Caring. Connecting. Growing together.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Center Analyst (Microsoft Sentinel/CrowdStrike/MS Defender)
Security Operations Center Analyst (Microsoft Sentinel/CrowdStrike/MS Defender)

Optum, a UnitedHealth Group Company • Metro Manila

Hybrid
PHP 350,000 - 600,000
Market Pay
Hybrid work
Retirement Plan
+13
Cyber Threat Intelligence Analyst
Cyber Threat Intelligence Analyst

Optum, a UnitedHealth Group Company • Metro Manila

On-site
PHP 900,000 - 1,300,000
Market Competitive Pay Levels
Retirement Plan
Medical Plan (HMO) from Day 1 of work
+2
Information Security Engineer Analyst - SOC Analyst
Information Security Engineer Analyst - SOC Analyst

Optum Philippines • Muntinlupa

On-site
PHP 300,000 - 520,000
Information Security Engineer Analyst
Information Security Engineer Analyst

Optum Philippines • Muntinlupa

On-site
PHP 480,000 - 720,000
InfoSec Engineer (GRC & Vendor Risk Management)
InfoSec Engineer (GRC & Vendor Risk Management)

Optum, a UnitedHealth Group Company • Metro Manila

Hybrid
PHP 1,000,000 - 1,400,000
Hybrid
Laptop provided by the company
Total rewards package
+13
Sr Info Sec Engineer - Risk GRC, Vendor, Education Training & Awareness
Sr Info Sec Engineer - Risk GRC, Vendor, Education Training & Awareness

Optum • Metro Manila

Hybrid
PHP 900,000 - 1,300,000
Hybrid
Laptop Provided
Medical Plan
+11
Workplace Services Engineer
Workplace Services Engineer

Optum, a UnitedHealth Group Company • Metro Manila

On-site
PHP 1,200,000 - 1,800,000
Market Competitive Pay Levels
Retirement Plan
Medical Plan (HMO) from Day 1
Network Consultant | Data Center & Enterprise Network (SD-WAN)
Network Consultant | Data Center & Enterprise Network (SD-WAN)

Optum, a UnitedHealth Group Company • Metro Manila

On-site
PHP 1,200,000 - 2,100,000
Market Competitive Pay Levels
Retirement Plan
Medical Plan (HMO) from Day 1
+12
Senior Software Quality Engineer (Manual testing)
Senior Software Quality Engineer (Manual testing)

Optum, a UnitedHealth Group Company • Metro Manila

Hybrid
PHP 600,000 - 1,000,000
Hybrid work model
Laptop provided by the company
Medical plan
+1
Senior Systems Management Analyst
Senior Systems Management Analyst

Optum, a UnitedHealth Group Company • Makati

On-site
PHP 420,000 - 660,000
Drug-free workplace