SOC Analyst | Hybrid

Cloudstaff Philippines Inc.

Philippines

On-site

PHP 400,000 - 600,000

Full time

7 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Comprehensive health insurance
Flexible leave credits
Company-provided PC/Laptop

Job summary

Cloudstaff Philippines Inc. is seeking a Security Operations Centre (SOC) Analyst to monitor and triage security alerts across the SIEM platform and cloud services. You will work with Microsoft 365, Azure and AWS, triaging alerts, escalating incidents and tracking endpoint signals.

The role emphasizes accurate incident documentation, shift handovers and participation in exercises. Strong English written communication and experience with SIEM tools are essential.

Qualifications

  • Demonstrated experience monitoring and triaging alerts in a SIEM platform.
  • Ability to classify alert severity and manage incident workflows.
  • Experience with AWS and Azure cloud environments.
  • Experience with Microsoft 365 Entra ID sign-in and audit signals.
  • Knowledge of EDR and vulnerability management concepts.
  • Strong written English and incident record-keeping.

Responsibilities

  • Triage alerts in SIEM and escalate incidents per the matrix.
  • Monitor Microsoft Entra ID, 365, AWS CloudTrail and GuardDuty.
  • Classify alert severity, run incident workflows.
  • Triage EDR alerts and track endpoint coverage gaps.
  • Track vulnerabilities and patches across Azure and AWS.
  • Maintain triage notes, incident records and shift handover.

Skills

SIEM monitoring
Alert triage
AWS & Azure
Entra ID signals
EDR concepts
Vulnerability management
English communication

Tools

Rapid7
Microsoft Defender for Endpoint
CrowdStrike
Netskope
Cloudflare
LastPass

Job description

Job Description
Role Purpose

The Security Operations Centre (SOC) Analyst runs the day-to-day security monitoring and alert triage function, working across the Security Information and Event Management (SIEM) platform and the wider technology stack. The role watches the environment spanning Microsoft 365, Microsoft Azure and Amazon Web Services (AWS), triaging alerts, escalating incidents and tracking endpoint and vulnerability signals.

Key Responsibilities
  • Monitor the Rapid7 Security Information and Event Management (SIEM) platform and triage alerts from Microsoft Entra ID, Microsoft 365, AWS CloudTrail and AWS GuardDuty.
  • Classify alert severity, run the incident workflow and elevate confirmed incidents through the escalation matrix.
  • Triage Endpoint Detection and Response (EDR) alerts and track endpoint coverage gaps for follow‑up.
  • Track vulnerability and patch signals from scanning across Azure and AWS, and follow items through to remediation.
  • Maintain accurate triage notes, incident records and shift handover documentation, and take part in tabletop and incident response simulation exercises.
Parallel and Cross-Functional Responsibilities
  • Support the Security Operations Engineer on SIEM alert tuning and refining detection metrics.
  • Feed EDR and endpoint health findings to the M365 Engineer for hardening and coverage fixes.
  • Provide monitoring input to the vCISO for the monthly cybersecurity reporting and dashboard.
Technical Environment
  • Rapid7 as the primary Security Information and Event Management (SIEM) and vulnerability tracking platform across the environment.
  • Microsoft 365 E3 with Microsoft Defender, Microsoft Intune and Microsoft Entra ID as native telemetry sources.
  • CrowdStrike or Microsoft Defender for Endpoint Detection and Response (EDR), the Netskope suite for secure web gateway and Data Loss Prevention (DLP), Cloudflare for Web Application Firewall (WAF) protection and LastPass for password management.
  • Amazon Web Services (AWS) and Microsoft Azure
Qualifications and Requirements
Required Skills and Experience
  • Demonstrated experience monitoring and triaging alerts in a Security Information and Event Management (SIEM) platform.
  • Sound understanding of alert severity classification, incident workflow and escalation practice.
  • Practical monitoring experience across Amazon Web Services (AWS) and Microsoft Azure cloud environments.
  • Confident working with Microsoft 365 E3 and Microsoft Entra ID sign-in and audit signals, plus knowledge of Endpoint Detection and Response (EDR) and vulnerability management concepts.
  • Strong written English and clear communication for incident notes, handovers and cross-team collaboration.
Highly Desirable
  • Hands‑on experience with Rapid7 or Microsoft Sentinel and the wider security tooling stack for monitoring and triage.
  • Familiarity with Rapid7 or Microsoft Sentinel and Microsoft Defender or CrowdStrike detection and hunting workflows.
  • Exposure to the Netskope suite and Cloudflare protection services, and understanding of the Essential Eight and Centre for Internet Security (CIS) benchmarks.
  • A security certification such as Microsoft Certified: Security Operations Analyst Associate or CompTIA Security+.
Perks and Benefits
  • Comprehensive health and life insurance on your 16th day of employment, covering 1 free dependent on the 16th day of employment
  • Up to 24 leave credits per year
  • Flexible leave credits which may be used for vacation, emergency and sick leaves
  • Superb and exciting Mid-Year Parties – with items to give away and cash prizes!
  • Endless opportunities for career advancement
  • Exclusive ATM inside the office for employee's convenience
  • Annual Performance Review with Salary Increase
  • We set you up for success with a company-provided PC/Laptop and fiber internet connection
  • Look forward to weekly office perks for work from office staff – Free Coffee, Meals and Beer Fridays!
  • Top notch workplace with first class VIP lounge and game rooms
  • Child friendly spaces to cater to the needs of employees with children, enhancing work-life balance
  • Participate and join our CS Social Clubs and Special Interest Groups to connect with colleagues
  • International career growth and connections
  • Unlimited cash incentives for hired referrals
  • Mental Wellness Employee Assistance program through Lifeworks
  • In-house psychiatrist available to support employees' well-being
  • Become part of the Employee Share Units program
  • Cloudstaff Dream Points - To be used for bidding useful items like appliances, kitchenettes etc.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Engineer | Hybrid
Security Operations Engineer | Hybrid

Cloudstaff Philippines Inc. • Philippines

On-site
PHP 800,000 - 1,000,000
Comprehensive health and life ins.
Leave credits
Hybrid/Office perks
+5
DevSecOps Engineer | Hybrid
DevSecOps Engineer | Hybrid

Cloudstaff Philippines Inc. • Philippines

On-site
PHP 1,000,000 - 2,000,000
Comprehensive health and life保险 on 16+
Leave credits and flexible time off
Company-provided PC and fiber internet
Security Operations Engineer | Hybrid | Morning Shift
Security Operations Engineer | Hybrid | Morning Shift

Cloudstaff Philippines Inc. • Metro Manila

Hybrid
PHP 700,000 - 1,100,000
Comprehensive health and lifeinsurance
Up to 24 leave credits per year
Flexible leave credits for vacation/sx
+4
Senior Consultant I - Security & Privacy
Senior Consultant I - Security & Privacy

Cloudstaff • Angeles

Hybrid
Comprehensive health and life insurance
Flexible leave credits
Quarterly perks boxes
+3
SOC L3 Analyst Lead
SOC L3 Analyst Lead

KPMG R.G. Manabat & Co. • Philippines

On-site
PHP 1,800,000 - 3,400,000
HMO with 2 Free Dependents
Communication Allowance
Rice Allowance
+10
Senior Consultant I - Security & Privacy
Senior Consultant I - Security & Privacy

Cloudstaff • Pampanga

Hybrid
PHP 900,000 - 1,300,000
Health and life insurance
PC/Laptop provided
Fiber internet
+3
SOC Analyst Lead - L3 Incident Response
SOC Analyst Lead - L3 Incident Response

KPMG R.G. Manabat & Co. • Manila

On-site
PHP 250,000 - 450,000
HMO with 2 Free Dependents
Communication Allowance
Rice Allowance
+6
M365 Engineer | Work from Office | Morning Shift
M365 Engineer | Work from Office | Morning Shift

Cloudstaff Philippines Inc. • Metro Manila

On-site
PHP 1,004,000 - 1,451,000
Comprehensive health and lifeinsurance
Up to 24 leave credits per year
PC/Laptop and fiber internet provided
+4
Security Analyst (Remote)
Security Analyst (Remote)

Prime System Solutions • Philippines

On-site
PHP 1,200,000 - 1,600,000
HMO coverage
Paid time off
Career development and certification
+2
Customer Support Team Lead - ORT
Customer Support Team Lead - ORT

Cloudstaff Philippines Inc. • Metro Manila

On-site
PHP 670,000 - 1,004,000
Health insurance
Leave credits
Career advancement
+7