Security Operations Specialist

Globe Telecom, Inc.

Philippines

On-site

PHP 600,000 - 1,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Globe Telecom, Inc. in the Philippines seeks a Security Operations Specialist to monitor and respond to security alerts, perform investigations using MITRE ATT&CK, document cases, escalate when needed, and contribute to SOC improvements.

The role requires experience in security monitoring or SOC, familiarity with SIEM/EDR/IDS/DLP, ability to analyze logs, and a willingness to cover 24/7 shifts with a sustainable rotation in a fintech-backed environment.

Qualifications

  • Experience in security monitoring, incident response, or security operations center work.
  • Working knowledge of SIEM, EDR, email security, cloud security, and related security monitoring tools.
  • Ability to analyze logs, investigate suspicious activity, and form evidence-based conclusions.
  • Familiarity with MITRE ATT&CK, attacker behavior mapping, or comparable investigative frameworks.
  • Strong technical documentation and case-writing skills.
  • Ability to balance speed, accuracy, and sound judgment in a high-volume operational environment.

Responsibilities

  • Alert Monitoring and Triage: Monitor and respond to security alerts; triage per severity and evidence; determine true/benign/false positives and escalation needs.
  • Investigation and Analysis: Conduct threat analysis, correlation, and containment; apply cyber kill chain concepts.
  • Case Documentation and Escalation: Document investigations; produce escalation notes; ensure actionable artifacts for senior teams.
  • Containment and Response: Validate risk and coordinate with owners; support remediation and closure of findings.
  • Detection and Operational Improvement: Identify false positives and tune detections; contribute to SOC playbooks and dashboards.

Skills

Security monitoring
Incident response
SOC operations
MITRE ATT&CK
Technical writing
24/7 support
Team collaboration

Education

Bachelor's degree in computer science or IT

Tools

SIEM
EDR
IDS
DLP
Firewalls
Endpoint security
Email security

Job description

Key Responsibilities
  1. Alert Monitoring and Triage Monitor and respond to security alerts from SIEM or from various security tools or instrumentation such as endpoint security, secure email gateway, firewalls, IDS, DLP, etc. Acknowledge new alerts promptly and begin meaningful triage based on severity, context, and available evidence. Review alerts using established SOC triage playbooks and standard case disposition guidance. Determine whether activity is true positive, benign positive, false positive, or requires further investigation.

  2. Investigation and Analysis Perform advanced incident response activities including discovery, threat analysis and correlation, response, remediation, and containment, at times involving network and endpoint forensics. Apply investigative logic using frameworks such as the Cyber Kill Chain and MITRE ATT&CK to understand attacker behavior, scope incidents, and assess likely impact. Validate whether reported activity is benign, expected, suspicious, or malicious before closure, escalation, or containment recommendation. Correlate evidence from SIEM, EDR, cloud, email, and network sources where applicable.

  3. Case Documentation and Escalation Document investigations clearly and completely so that work can be reviewed, continued, or audited without repeating prior analysis. Produce escalation notes that include alert summary, affected assets, investigative steps performed, evidence gathered, and analyst hypothesis. Escalate cases when deeper response, stakeholder coordination, or containment approval is required. Ensure escalations are actionable and complete enough for immediate continuation by senior analysts, leads, or partner teams. Contribute to overall SOC processes, documentation, metrics, and reporting.

  4. Containment and Response Support Support containment and response actions by validating risk, recommending next steps, and coordinating with leads, system owners, and supporting teams as needed. Participate in the investigation lifecycle from alert handling through validation, communication, and closure. Contribute to timely incident scoping and prioritization to improve mean time to detect, respond, and contain. Support or drive the remediation or closure of control gaps, risks, and findings from audits and certification activities.

  5. Detection and Operational Improvement Identify recurring false positives, noise patterns, and weak detections, then recommend tuning opportunities to improve SOC efficiency. Contribute to SOC initiatives that enhance analyst productivity, detection quality, and operational maturity. Help translate observed attack patterns and investigative learnings into improved rules, playbooks, dashboards, and use cases.

Core Deliverables
  • Accurate and timely handling of security alerts and cases.
  • Well-documented investigations and escalation artifacts.
  • High-quality incident analysis aligned to SOC playbooks and threat frameworks.
  • Recommendations for detection tuning, false-positive reduction, and process improvement.
Minimum Qualifications
  • Experience in security monitoring, incident response, or security operations center work.
  • Working knowledge of SIEM, EDR, email security, cloud security, and related security monitoring tools.
  • Ability to analyze logs, investigate suspicious activity, and form evidence-based conclusions.
  • Familiarity with MITRE ATT&CK, attacker behavior mapping, or comparable investigative frameworks.
  • Strong technical documentation and case-writing skills.
  • Ability to balance speed, accuracy, and sound judgment in a high-volume operational environment.
Preferred Qualifications
  • At least 2 years of SOC or IR experience.
  • Bachelor’s degree in computer science, IT, or directly related field, or equivalent work experience.
  • Strong understanding of SIEM platforms and hands-on experience with security technologies such as SIEM, IDS, DLP, vulnerability scanning, firewalls, endpoint security, or email security systems.
  • Exposure to threat hunting, detection engineering feedback loops, or SOAR-oriented process design.
  • Experience coordinating with application owners, infrastructure teams, or supporting functions during incident review and response.
  • Willingness to cover 24/7 working hours following a sustainable rotation schedule and at times cover on-call duties.
  • Practical experience in reverse engineering, malware forensics, or penetration testing, particularly within finance and fintech operations, is highly advantageous.
  • Advanced security certifications (e.g., CC, GCIH, CDSA, CompTia Sec+, SANS/GIAC, CEH) are highly advantageous.
Competencies
  • Investigative reasoning
  • Threat analysis and contextual decision-making
  • Technical writing and case documentation
  • Tool fluency across SOC platforms
  • Pattern recognition and false-positive identification
  • Stakeholder coordination during investigations
  • Technical security project support and collaboration
  • Cross-functional team collaboration
  • Continuous improvement mindset
Success Measures

A successful Security Operations Specialist consistently demonstrates strong alert handling coverage, high triage quality, timely acknowledgement of alerts, complete escalation documentation, active identification of false positives, delivery of SOC improvement initiatives, and continuous development of technical capability.

What We Offer

Opportunity for career growth and development in the #1 FinTech company in the country. Working with a dynamic and highly collaborative team who want to change the game. A company that values their people with highly competitive and flexible compensation and benefits package is the #1 Finance App in the Philippines. Through the GCash App, 81M registered users can easily purchase prepaid airtime; purchase from over 6M partner merchants and social sellers; send and receive money anywhere in the Philippines, even to other bank accounts; pay bills at over 1,800 partner billers nationwide; and get access to savings, credit, loans, insurance and investments, and so much more, all at the convenience of their smartphones. GCash is a wholly-owned subsidiary of Mynt (Globe Fintech Innovations, Inc.) since 2015. Mynt, Inc. is the parent company of GCash, the Philippines’ #1 finance superapp, advancing financial inclusion through ‘Finance for All’. G-Xchange, Inc. (GXI) is the payments company for GCash. GXI is a BSP-licensed e-money issuer responsible for the digital payments and electronic money activities in the GCash app. Fuse Financing, Inc. is the financing company for GCash. Fuse provides eligible users with access to fair and digitally-enabled credit products and solutions. Ryse, Inc. broadens access to investments that are easy to use and understand, supporting wealth-building for Filipinos at different stages of their financial journey. BlockG Virtual Assets, Inc. supports responsible participation in digital assets, helping build trust and long-term confidence in the continuously evolving digital landscape.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Head of Strategy, Operations
Head of Strategy, Operations

Globe Telecom, Inc. • Caloocan

On-site
PHP 2,000,000 - 5,000,000
AVP, Head of EOSS
AVP, Head of EOSS

Globe Telecom, Inc. • Manila, Hinoba-an

On-site
PHP 4,500,000 - 7,500,000
Competitive compensation & benefits
AVP, Head of EOSS
AVP, Head of EOSS

Globe Telecom, Inc. • Philippines

On-site
PHP 2,000,000 - 4,000,000
Lead, Transformation L2 Application Support
Lead, Transformation L2 Application Support

Globe Telecom, Inc. • Metro Manila

On-site
PHP 1,200,000 - 1,800,000
Competitive compensation
Flexible benefits
Lead, Transformation L2 Application Support
Lead, Transformation L2 Application Support

Globe Telecom, Inc. • Philippines

On-site
PHP 1,800,000 - 3,000,000
Career growth opportunities
Dynamic collaborative team
Flexible compensation and benefits
Service Level Manager (Manager)
Service Level Manager (Manager)

Globe Telecom, Inc. • Manila

On-site
PHP 80,000 - 110,000
Competitive compensation
Flexible benefits
Service Level Manager (Manager)
Service Level Manager (Manager)

Globe Telecom, Inc. • Philippines

On-site
PHP 600,000 - 1,200,000
Technical Architect
Technical Architect

Globe Telecom, Inc. • Philippines

On-site
PHP 1,800,000 - 3,000,000
Regulatory Compliance Lead
Regulatory Compliance Lead

Globe Telecom, Inc. • Taguig

On-site
PHP 600,000 - 1,100,000
Head of Cloud Governance
Head of Cloud Governance

Globe Telecom, Inc. • Metro Manila

On-site
PHP 6,000,000 - 9,000,000