SOC Analyst - L1 and L2 (For Talent Pooling)

Hammerjack Pty Ltd

Philippines

On-site

PHP 600,000 - 1,000,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Hammerjack Pty Ltd is seeking a Security Analyst to perform detailed, repeatable security operations. The role focuses on monitoring SIEM environments, closing or escalating events, and maintaining incident documentation.

You will support the MDR team in detection, containment, and remediation activities. The candidate should have a Bachelor's degree in a related field and at least 1 year of MDR/SOC experience, with strong analytical and communication skills, and familiarity with SIEM tools such

Qualifications

  • Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field.
  • Minimum 12 months MDR/SOC/Incident response experience.
  • Demonstrated knowledge of network security concepts and incident handling.
  • Experience with SIEM tools and incident response processes.

Responsibilities

  • Execute operational tasks per documented processes and procedures.
  • Monitor SIEM tools for security events and close or escalate as needed.
  • Maintain group email, distribution lists, shift logs, and tickets.
  • Assist MDR Analyst during incident workflows and detection/remediation.
  • Document event analysis and write incident investigation reports.
  • Improve security-related operational processes and procedures.
  • Update knowledgebase and ingest daily intelligence reports.

Skills

Incident response
Threat hunting
Documentation
Analytical thinking
Communication

Education

Bachelor's degree in Computer Science or related field

Tools

Sentinel
Splunk
LogRhythm
Azure Sentinel
Confluence

Job description

Roles and responsibilities:

The primary role of a Security Analyst is the detailed and repeatable execution of all operational tasks as documented in processes and subordinate procedures. Specifically, these analysts will be responsible for monitoring the SIEM tools for security events and closing or escalating those events as necessary. Security Analysts maintain the group email address and distribution lists, answer the main phone lines, and update all relevant documentation such as shift logs and tickets. Additionally, assist the MDR Analyst in an incident workflow and assist the MDR team in incident detection, remediation and communicate with external teams in proper incident resolution.

Specifically, Security Analysts will:

Rapidly identify, categorize, prioritize and investigate events as the initial cyber event detection group for the enterprise using all available security logs and intelligence sources to include but not limited to:

  • Firewalls.
  • Systems and Network Devices.
  • Web Proxies.
  • Intrusion Detection/Prevention Systems.
  • Data Loss Prevention.
  • EDR / Antivirus Systems.
  • Knowledgebase Framework (Confluence).

Continuously monitor SIEM and logging environments for security events and alerts to threats, intrusions, and/or compromises, including:

  • SIEM alert queue.
  • Security email inbox.
  • Intel feeds via email and other sources (e.g. NH-ISAC).
  • Incident Ticketing queue (IT Security group).

Validate alerts as they come in to eliminate false positives and use other internal and external data sources to enrich alerts with additional context.

Perform triage of service requests from customers and internal teams.

Use playbook procedures to carry out standard plays for routine event types and escalated alerts to Level 2 Analysts for further triage and remediation.

Assist with containment of threats and remediation of environment during or after an incident.

Act as a participant during Threat Hunting activities at the direction of one or more Incident Response Handlers.

Document event analysis and write comprehensive reports of incident investigations.

Proactively improve security-related operational processes and procedures.

Use available security tools for historical analysis purposes as necessary for detected events; for example, historical searches using SIEM tools.

Maintain operational shift logs with relevant activity from the Analyst's shift. Document investigation results, ensuring relevant details are passed to Level 2 or MDR Analysts for final event analysis.

Update/reference knowledgebase tool (e.g., Confluence) as necessary for changes to processes and procedures and ingest of daily intelligence reports and previous shift logs.

Conduct research and document events of interest within the scope of IT Security.

Required Technical skills:
  • Experience with SIEM tools (Sentinel, Splunk, Logrhythm, etc.).
  • Experience in Azure Sentinel.
  • Familiarity with common IDS/IPS and Firewalls (Snort, Cisco, Fortigate, Sourcefire) .
  • Familiarity with incident response process and activities.
  • Familiarity with TCP/IP protocol, OSI Seven Layer Model.
  • Knowledge of Windows, Unix-based systems, architectures, and network security devices.
  • Intermediate level of knowledge of LAN and WAN technologies.
  • Must have a solid understanding of information technology, information security domains.
  • Knowledge of security best practices and concepts.
  • Desired certifications: Security+, C|EH, Network+, Certified Information Systems Security Professional (CISSP), GIAC Certified Intrusion Analyst, GIAC Certified Incident Handler, or GIAC Reverse Engineering Malware.
  • Familiarity with ticketing tool / ITSM tool.
  • Personal drive, positive work ethic to deliver results within tight deadlines and in demanding situations.
Qualifications:
  • Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field.
  • Minimum of 12 months of prior MDR/SOC/Incident response experience.
  • Demonstrated technical knowledge of current network security, network hardware, protocols, and standards required.
  • Shall have demonstrated professional experience in incident detection and response, malware analysis, or cyber forensics.
  • Act as a workstream participant to support tier-1, tier-2, or tier-3 SOC environments.
  • Demonstrated strong oral and written communication and client facing skills.
  • Demonstrated strong analytical and communications skills.
  • Flexibility to adapt to different types of engagement, working hours, work environments, and locations.
  • Proven ability to work creatively, analytically in a problem-solving environment.
  • Ability to work nights, weekends, and/or holidays in the event of an incident response emergency.
  • Be comfortable working against deadlines in a fast-paced environment.
  • Identify issues, opportunities for improvement, and communicate them to an appropriate senior member.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Analyst (Online Gaming)
SOC Analyst (Online Gaming)

Sureste Properties Inc. • Parañaque

On-site
PHP 420,000 - 640,000
IT Security Analyst
IT Security Analyst

Ibex Limited • Davao del Sur

On-site
PHP 480,000 - 840,000
IT Security Analyst
IT Security Analyst

IBEX Global Solutions (Philippines) Inc. • Davao del Sur

On-site
PHP 420,000 - 560,000
Security Operations Center (SOC) - Head
Security Operations Center (SOC) - Head

SMITS, Inc. - IT Company of San Miguel Corporation • Mandaluyong

On-site
PHP 900,000 - 1,600,000
Cyber Defence - Global Security Operations Centre (GSOC) Level 2 Analyst
Cyber Defence - Global Security Operations Centre (GSOC) Level 2 Analyst

WTW • Taguig

On-site
PHP 1,200,000 - 1,600,000
SOC Analyst/Incident Response Analyst
SOC Analyst/Incident Response Analyst

PM Consulting • Metro Manila

On-site
PHP 320,000 - 520,000
Security Analyst / Network Security Analyst
Security Analyst / Network Security Analyst

RippedBoxStation • Philippines

On-site
PHP 260,000 - 420,000
Associate Security Analyst
Associate Security Analyst

itm8 Danmark • Lapu-Lapu

On-site
PHP 480,000 - 640,000
IT Security Specialist
IT Security Specialist

Ibex Limited • Manila

On-site
PHP 600,000 - 900,000
Security Analyst – SOC
Security Analyst – SOC

Moder Solutions Inc. • Cebu City

On-site
PHP 420,000 - 720,000