SOC Analyst

Scrubbed, Accounting that Matters

San Fernando

On-site

PHP 600,000 - 900,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Scrubbed, Accounting that Matters seeks a SOC Analyst to join its Technology team. This role involves monitoring and responding to security incidents within ARI's environments, utilizing tools like Microsoft Sentinel. Applicants should have 1-3 years of relevant experience and a Bachelor’s degree in Cybersecurity or related field, or equivalent experience.

The position is hybrid, with flexibility for remote work, but some office attendance is required. Responsibilities include managing security alerts, documenting incidents, and participating in post-incident reviews.

Qualifications

  • 1-3 years in SOC, IT security operations, or IT support with security responsibilities.
  • Familiar with Microsoft 365 security stack: Sentinel, Defender XDR, Entra ID.
  • Foundational knowledge of common attack patterns: phishing, ransomware, etc.

Responsibilities

  • Monitor security alerts during U.S. business hours.
  • Triage alerts and maintain incident tickets.
  • Participate in tabletop exercises and post-incident reviews.

Skills

Monitoring security alerts
Triage alerts
Incident ticket management
Network fundamentals
Documentation skills
Communication skills

Education

Bachelor’s degree in Cybersecurity or related discipline

Tools

Microsoft 365 security stack (Sentinel, Defender XDR)
Jira Service Management

Job description

SOC Analyst

Hybrid

Professional Firms Support Services and Specialized Teams, 1 Open position

This position works in our Technology team and serves as a Tier 1 security operations analyst, monitoring and triaging security alerts across ARI’s enterprise IT and OT environments. The role executes documented playbooks, escalates higher‑severity incidents to senior security staff, and contributes to the maturation of ARI’s detection and response capability. The SOC Analyst I is the first line of detection and response for ARI’s IT estate and works in coordination with the OT Security Engineer, who owns the OT side, and with ARI’s external MSSP. This position will report to Head of Remote Workforce Strategy and the Director of Technology. This is a hybrid position, with most of the time spent working from home but with office attendance from time to time, as needed.

Responsibilities
  • Monitor security alerts and telemetry from Microsoft Sentinel, Defender XDR, Entra ID, and adjacent enterprise security tooling during U.S. business hours.
  • Triage alerts using documented playbooks: validate, classify, gather context, and either resolve, suppress with rationale, or elevate.
  • Open, maintain, and close incident tickets in ARI’s ITSM system (Jira Service Management) with audit‑quality documentation.
  • Triage phishing reports, including end‑user reports to the abuse mailbox and automated phish detections.
  • Contribute to detection tuning by flagging false‑positive patterns and recommending refinements.
  • Maintain SOC runbooks and playbook documentation; recommend updates based on observed alert patterns.
  • Support routine security operations tasks: account access reviews, certificate expiry tracking, vulnerability report triage.
  • Participate in tabletop exercises and post‑incident reviews; capture lessons learned.
  • Escalate to the OT Security Engineer on any indication of OT‑ or SCADA‑related security events.
  • Coordinate with ARI’s MSSP for incidents requiring deeper investigation or after‑hours coverage.
Qualifications
  • 1–3 years in a SOC, IT security operations, or IT support role with security responsibilities; strong entry‑level candidates with demonstrated learning velocity will also be considered.
  • Familiarity with the Microsoft 365 security stack: Sentinel, Defender XDR, Entra ID, Purview.
  • Foundational knowledge of common attack patterns: phishing, credential theft, MFA fatigue, business email compromise, ransomware delivery.
  • Working knowledge of networking fundamentals: TCP/IP, DNS, HTTP/S, VPN, basic packet flow.
  • Foundational knowledge of operating system concepts on Windows and macOS endpoints.
  • Strong documentation discipline; ability to write clear incident notes that survive audit review.
  • Clear written and verbal communication, including the ability to elevate concisely under time pressure.
  • Bachelor’s degree in Cybersecurity, Information Technology, or related discipline — or equivalent demonstrated experience.
  • Preferred certifications: CompTIA Security+, Microsoft SC‑200, or equivalent.
  • Comfortable working in a remote‑first environment with clear handoffs to senior staff and an external MSSP.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hybrid SOC Analyst – Tier 1 Security Ops
Hybrid SOC Analyst – Tier 1 Security Ops

Scrubbed, Accounting that Matters • San Fernando

Hybrid
PHP 600,000 - 900,000
NSOC Analyst Tier 1
NSOC Analyst Tier 1

Astute Cybersecurity • Cebu City

On-site
PHP 420,000 - 900,000
NSOC Analyst Tier 1
NSOC Analyst Tier 1

Centrics Networks • Cebu City

On-site
PHP 420,000 - 660,000
Junior SOC Analyst
Junior SOC Analyst

Kinettix Inc. • Manila

On-site
Senior SOC Analyst
Senior SOC Analyst

Hammerjack Pty Ltd • Manila

On-site
PHP 900,000 - 1,300,000
Security Operations Center (SOC) - Head
Security Operations Center (SOC) - Head

SMITS, Inc. - IT Company of San Miguel Corporation • Mandaluyong

On-site
PHP 900,000 - 1,600,000
Senior SOC Analyst: Advanced Incident Response
Senior SOC Analyst: Advanced Incident Response

Integrity360 • España

On-site
PHP 4,972,000 - 8,523,000
IT Security Analyst
IT Security Analyst

Ibex Limited • Davao del Sur

On-site
PHP 480,000 - 840,000
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

Microgenesis Business Systems • Mandaluyong

On-site
PHP 279,000 - 390,600
Health insurance
Life insurance
Additional leave
+2
IT Security Analyst
IT Security Analyst

ibex • Philippines

On-site
PHP 600,000 - 900,000