Security Operations Center (SOC) - Head

SMITS, Inc. - IT Company of San Miguel Corporation

Mandaluyong

On-site

PHP 900,000 - 1,600,000

Full time

4 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

SMITS, Inc. - IT Company of San Miguel Corporation is seeking a Senior SOC Manager to lead daily operations, mentor analysts, and coordinate incident response activities across security platforms.

The role emphasizes incident containment, threat hunting, and reporting toManagement, with strong focus on process improvement and cross-functional collaboration.

Qualifications

  • Bachelor degree in Computer Science, ECE, Computer Engineering or any IT related course.
  • CEH or CCNA or other network/security certification preferred.
  • Extensive knowledge of IT systems and security risks across technologies.

Responsibilities

  • Oversee daily SOC operations: alert monitoring, triage, escalation, and incident tracking.
  • Lead and mentor SOC analysts, guiding investigations, threat analysis, and response actions.
  • Ensure incidents meet SLAs and follow escalation matrices and procedures.
  • Review incident tickets, case notes, and closure details for completeness and accuracy.
  • Coordinate with internal teams and external vendors during security incidents and major outages.
  • Monitor security platforms (SIEM, EDR, email security) for suspicious activity.
  • Improve SOC processes, detection rules, playbooks, and reporting for efficiency.
  • Prepare and present operational metrics, incident trends, and security reports to management.
  • Support containment, investigation, remediation, and post-incident reviews.
  • Facilitate knowledge transfer and cross-skilling within the SOC team.

Skills

Security operations
Threat monitoring
Incident response
Team leadership
Clear communication

Education

Bachelor in IT-related field

Tools

SIEM
EDR
SOAR
ServiceNow
Splunk
QRadar

Job description

Responsibilities
  • Oversee daily SOC operations, including alert monitoring, triage, escalation, and incident tracking.
  • Lead and mentor SOC analysts, providing guidance on investigations, threat analysis, and response actions.
  • Ensure incidents are handled in accordance with SLAs, escalation matrices, and established security procedures.
  • Review and validate incident tickets, case notes, and closure details for completeness and accuracy.
  • Coordinate with internal teams and external vendors during security incidents and major outages.
  • Monitor SOC tools, firewall, email security, and other security platforms for suspicious activity.
  • Improve SOC processes, detection rules, playbooks, and reporting to increase efficiency and response quality.
  • Prepare and present operational metrics, incident trends, and security reports to management.
  • Support incident response activities, including containment, investigation, remediation, and post-incident review.
  • Ensure knowledge transfer, training, and cross-skilling within the SOC team.
Educational Background

Educational Background: Bachelor degree of Computer Science, ECE, Computer Engineering or any IT related course

Certifications Required

Certifications Required: Preferably CEH, CCNA or other certificate related to Network and Security

Relevant Skills

Relevant Skills: Should have an extensive knowledge of Information Technology systems and a deep understanding of the security risks associated with these technologies.

  • Experience in security operations, incident response, or threat monitoring.
  • Strong understanding of SIEM, EDR, ticketing systems, and security monitoring tools.
  • Knowledge of common attack techniques, malware behavior, and detection methodologies.
  • Proven ability to lead analysts, manage priorities, and communicate clearly under pressure.
  • Familiarity with reporting, documentation, and process improvement in a SOC environment.
  • Strong communication skills for working with technical and non-technical stakeholders.
  • Ability to make sound decisions quickly during active security events.
Technology Exposure

Technology Exposure: Should have experience with any of the following;

  • SIEM and SOAR platforms
  • EDR/XDR tools, such as SentinelOne, CrowdStrike Falcon, and Microsoft Defender for Endpoint.
  • Vulnerability scanners, such as Tenable, Qualys, and Rapid7.
  • Threat intelligence platforms
  • Network analysis tools, such as Wireshark.
  • Log management tools.
  • Incident response and case management tools, such as ServiceNow
  • Endpoint investigation tools, such as Sysinternals, Autoruns, and Process Explorer.
  • Malware analysis and sandbox tools.
  • Email security platforms.
Related Work Experience

Related Work Experience: The candidate should have relevant experience in the following;

  • Experience with QRadar, SentinelOne, Splunk, Microsoft Defender, or similar platforms.
  • Familiarity with MITRE ATT&CK, incident lifecycle management, and threat hunting.
  • Strong understanding of and ability to operationalize the MITRE ATT&CK framework to develop detection rules for SIEM, EDR, and other security controls.
  • Advanced threat hunting across endpoint, identity, network, email, and cloud environments.
  • Strong working experience gathering threat intelligence from different sources, and strong understanding of attacker campaigns.
  • Deep understanding of attacker TTPs such as advanced persistence, defense evasion, privilege escalation, lateral movement, and data exfiltration.
  • Deep understanding of malware behavior, and common forensic artifacts from different operating systems such as Windows, Unix/Linux, and MacOS.
  • Strong working experience conducting root cause analysis and incident analysis report.
  • Strong experience working in all incident response stages (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned).
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Security Specialist
IT Security Specialist

Ibex Limited • Manila

On-site
PHP 600,000 - 900,000
Security Analyst / Network Security Analyst
Security Analyst / Network Security Analyst

RippedBoxStation • Philippines

On-site
PHP 260,000 - 420,000
IT Security Specialist
IT Security Specialist

ibex • Mandaluyong

On-site
PHP 420,000 - 640,000
IT Security Analyst
IT Security Analyst

SGL Manila (Shared Service Center), Inc. • Muntinlupa

On-site
PHP 600,000 - 900,000
IT Security Analyst
IT Security Analyst

IBEX Global Solutions (Philippines) Inc. • Davao del Sur

On-site
PHP 420,000 - 560,000
IT Security Analyst
IT Security Analyst

Ibex Limited • Davao del Sur

On-site
PHP 480,000 - 840,000
Security Analyst – SOC
Security Analyst – SOC

Moder Solutions Inc. • Cebu City

On-site
PHP 420,000 - 720,000
Junior SOC Analyst
Junior SOC Analyst

Kinettix Inc. • Manila

On-site
Security Operations and Incident Manager
Security Operations and Incident Manager

Private Advertiser • Mandaluyong

On-site
PHP 3,000,000 - 5,000,000
SOC Analyst - L1 and L2 (For Talent Pooling)
SOC Analyst - L1 and L2 (For Talent Pooling)

Hammerjack Pty Ltd • Philippines

On-site
PHP 600,000 - 1,000,000