Security Operations Center (SOC) - Head

SMITS, Inc. - IT Company of San Miguel Corporation

Mandaluyong

On-site

PHP 900,000 - 1,600,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

SMITS, Inc. - IT Company of San Miguel Corporation is seeking an experienced SOC Lead to supervise daily operations, mentor analysts, and coordinate incident response. You will ensure timely escalation, triage, and closure of tickets while improving detection rules and playbooks.

The role requires strong knowledge of SIEM/EDR, incident handling, and effective communication with technical and non-technical stakeholders. Experience with QRadar, Splunk, or similar is a plus.

Qualifications

  • Experience in security operations, incident response, or threat monitoring.
  • Strong knowledge of SIEM, EDR, ticketing systems, and security monitoring tools.
  • Familiarity with MITRE ATT&CK framework and detection methodologies.
  • Ability to lead analysts, manage priorities, and communicate under pressure.
  • Ability to document, report, and improve SOC processes.

Responsibilities

  • Oversee daily SOC operations: alert monitoring, triage, escalation, and incident tracking.
  • Lead and mentor SOC analysts with investigations, threat analysis, and responses.
  • Ensure incidents align with SLAs and established security procedures.
  • Review incident tickets, case notes, and closure details for accuracy.
  • Coordinate with internal teams and external vendors during incidents.
  • Monitor security platforms for suspicious activity and anomalies.
  • Improve SOC processes, playbooks, and reporting for efficiency.
  • Prepare and present operational metrics and incident trends to management.
  • Support containment, investigation, remediation, and post-incident review.
  • Ensure knowledge transfer and cross-skilling within the SOC team.

Skills

SOC operations
Incident response
Threat monitoring
SIEM
EDR/XDR
SOAR platforms
Communication
Decision making

Education

Computer Science
ECE
Computer Engineering
IT related course

Tools

SIEM/SOAR platforms
EDR/XDR tools
Vulnerability scanners
Threat intelligence platforms
Wireshark
ServiceNow
Sysinternals/Autoruns/Process Explorer
Malware analysis tools

Job description

  • Oversee daily SOC operations, including alert monitoring, triage, escalation, and incident tracking.
  • Lead and mentor SOC analysts, providing guidance on investigations, threat analysis, and response actions.
  • Ensure incidents are handled in accordance with SLAs, escalation matrices, and established security procedures.
  • Review and validate incident tickets, case notes, and closure details for completeness and accuracy.
  • Coordinate with internal teams and external vendors during security incidents and major outages.
  • Monitor SOC tools, firewall, email security, and other security platforms for suspicious activity.
  • Improve SOC processes, detection rules, playbooks, and reporting to increase efficiency and response quality.
  • Prepare and present operational metrics, incident trends, and security reports to management.
  • Support incident response activities, including containment, investigation, remediation, and post-incident review.
  • Ensure knowledge transfer, training, and cross-skilling within the SOC team.

Educational Background: Computer Science, ECE, Computer Engineering or any IT related course

Certifications Required: Preferably CEH, CCNA or other certificate related to Network and Security

Relevant Skills: Should have an extensive knowledge of Information Technology systems and a deep understanding of the security risks associated with these technologies.

  • Experience in security operations, incident response, or threat monitoring.
  • Strong understanding of SIEM, EDR, ticketing systems, and security monitoring tools.
  • Knowledge of common attack techniques, malware behavior, and detection methodologies.
  • Proven ability to lead analysts, manage priorities, and communicate clearly under pressure.
  • Familiarity with reporting, documentation, and process improvement in a SOC environment.
  • Strong communication skills for working with technical and non-technical stakeholders.
  • Ability to make sound decisions quickly during active security events.

Technology Exposure: Should have experience with any of the following;

  • SIEM and SOAR platforms
  • EDR/XDR tools, such as SentinelOne, CrowdStrike Falcon, and Microsoft Defender for Endpoint.
  • Vulnerability scanners, such as Tenable, Qualys, and Rapid7.
  • Threat intelligence platforms
  • Network analysis tools, such as Wireshark.
  • Log management tools.
  • Incident response and case management tools, such as ServiceNow
  • Endpoint investigation tools, such as Sysinternals, Autoruns, and Process Explorer.
  • Malware analysis and sandbox tools.
  • Email security platforms.

Related Work Experience: The candidate should have relevant experience in the following;

  • Experience with QRadar, SentinelOne, Splunk, Microsoft Defender, or similar platforms.
  • Familiarity with MITRE ATT&CK, incident lifecycle management, and threat hunting.• Strong understanding of and ability to operationalize the MITRE ATT&CK framework to develop detection rules for SIEM, EDR, and other security controls.
  • Advanced threat hunting across endpoint, identity, network, email, and cloud environments.
  • Strong working experience gathering threat intelligence from different sources, and strong understanding of attacker campaigns.
  • Deep understanding of attacker TTPs such as advanced persistence, defense evasion, privilege escalation, lateral movement, and data exfiltration.
  • Deep understanding of malware behavior, and common forensic artifacts from different operating systems such as Windows, Unix/Linux, and MacOS.
  • Strong working experience conducting root cause analysis and incident analysis report.
  • Strong experience working in all incident response stages (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Analyst
IT Security Analyst

IBEX Global Solutions (Philippines) Inc. • Davao del Sur

On-site
PHP 420,000 - 560,000
IT Security Analyst
IT Security Analyst

Ibex Limited • Davao del Sur

On-site
PHP 480,000 - 840,000
Security Analyst / Network Security Analyst
Security Analyst / Network Security Analyst

RippedBoxStation • Philippines

On-site
PHP 260,000 - 420,000
Junior SOC Analyst
Junior SOC Analyst

Kinettix Inc. • Manila

On-site
IT Security Specialist
IT Security Specialist

Ibex Limited • Manila

On-site
PHP 600,000 - 900,000
IT Security Specialist
IT Security Specialist

ibex • Mandaluyong

On-site
PHP 420,000 - 640,000
Senior Security Engineer – SOC
Senior Security Engineer – SOC

42 Gears Mobility Systems • Hinoba-an

On-site
PHP 995,000 - 1,592,000
Senior Analyst, Cyber Security Operations
Senior Analyst, Cyber Security Operations

Melco Resorts & Entertainment • Manila

On-site
PHP 1,004,000 - 1,674,000
SOC Analyst
SOC Analyst

Paynamics • Philippines

On-site
PHP 600,000 - 900,000
SOC Analyst/Incident Response Analyst
SOC Analyst/Incident Response Analyst

PM Consulting • Metro Manila

On-site
PHP 320,000 - 520,000