Soc Analyst L2

Staff4Me

Philippines

On-site

PHP 600,000 - 840,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Staff4me is seeking a SOC Analyst L2 in the Philippines to lead deeper investigations of escalated cases, confirm incidents, determine scope and impact, and drive containment actions with internal teams. You will produce high-quality technical communications and post-incident outputs, and contribute to detection improvements through playbooks updates.

The role requires 2-5 years in SOC/IR, strong networking fundamentals, EDR experience, and proficiency in English for clear stakeholder updates.

Qualifications

  • 2-5 years in SOC/IR/Blue Team or equivalent incident handling experience.
  • Solid fundamentals in networking: TCP/IP, DNS, HTTP/S, VPN, NAT.
  • EDR investigations (process trees, persistence, LOLBins) and containment workflows.
  • Windows/AD triage (authentication patterns, suspicious logon) and Linux triage.
  • Network analysis and security controls (firewall/IDS/proxy/DNS).
  • Proven ability to produce defensible scoping and timelines based on evidence.
  • High documentation standards and ability to perform under pressure.
  • Threat hunting experience and MITRE ATT&CK mapping.
  • Detection engineering exposure (Sigma/YARA) and SIEM correlation strategy.
  • Basic forensics concepts (acquisition, triage artifacts).
  • Certifications aligned to Blue Team / IR (e.g., GCIH/GCIA, SC-200).
  • Strong English (B2-High/C1) for technical calls and incident notes.

Responsibilities

  • Take escalations from L1 and perform in-depth investigations: hypothesis-driven analysis, evidence validation, scoping, impact assessment, and timeline building.
  • Correlate telemetry across endpoint (EDR), Windows/Linux, AD, firewall/proxy/DNS/IDS, and cloud logs.
  • Recommend and coordinate containment actions following change control and governance.
  • Determine severity and communicate clearly in English to technical stakeholders; provide concise executive updates.
  • Identify detection gaps and drive improvements: reduce false positives and close false negatives.
  • Ensure evidence integrity and proper documentation; coordinate handoffs with IR, IT Ops, Network, and Cloud teams.
  • Produce post-incident deliverables: probable root cause, lessons learned, and preventive actions.

Skills

SOC/IR Experience
Threat Hunting
MITRE ATT&CK
English Communication
Detection Engineering
EDR Investigations
Forensics Basics

Tools

EDR
Windows/AD
Linux Triage
Firewall/IDS/Proxy
Sigma/YARA
SIEM

Job description

SOC Analyst L2

Company : Staff4me Job Type : Full Time Philippines

Job Description - SOC Analyst L2
Description

As a SOC Analyst L2, you will lead deeper investigations of escalated cases, confirm incidents, determine scope and impact, drive containment actions with internal teams, and produce high-quality technical communications and post-incident outputs. You will also contribute to detection improvement (tuning, new detections, playbook updates).

Responsibilities
  • Take escalations from L1 and perform in-depth investigations: hypothesis-driven analysis, evidence validation, scoping, impact assessment, and timeline building.
  • Correlate telemetry across endpoint (EDR), Windows/Linux, AD, firewall/proxy/DNS/IDS, and (when applicable) cloud logs.
  • Recommend and/or coordinate containment actions (host isolation, credential resets, IOC blocks, temporary control changes) following change control and governance.
  • Determine severity and communicate clearly in English to technical stakeholders; provide concise executive-style updates when required.
  • Identify detection gaps and drive improvements: reduce false positives, close false negatives, propose new rules/use cases.
  • Ensure evidence integrity and proper documentation, coordinate handoffs with IR, IT Ops, Network, and Cloud teams.
  • Produce post-incident deliverables: probable root cause, lessons learned, and preventive actions.
Requirements
  • 2-5 years in SOC/IR/Blue Team (or equivalent demonstrated incident-handling experience). Solid fundamentals in networking: TCP/IP, DNS, HTTP/S, VPN, NAT.
  • EDR investigations (process trees, persistence, LOLBins behavior, containment workflows).
  • Windows/AD triage (authentication patterns, suspicious logon behavior, account activity) and Linux triage.
  • Network analysis and security controls (firewall/IDS/proxy/DNS), recognizing anomalous patterns.
  • Proven ability to produce defensible scoping and timelines based on evidence.
  • High documentation standards and the ability to perform under pressure.
  • Threat hunting experience and MITRE ATT&CK mapping.
  • Detection engineering exposure (Sigma/YARA at a basic/intermediate level), use-case design, and SIEM correlation strategy.
  • Basic forensics capabilities (acquisition concepts, triage artifacts, memory/disk fundamentals).
  • Certifications aligned to Blue Team / IR (e.g., GCIH/GCIA, BTL2, SC-200, etc.).
  • Strong spoken and written English (B2-High/C1 preferred) - able to lead technical calls, write incident summaries, and investigation notes.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Analyst L2 - Incident Response & Detection
SOC Analyst L2 - Incident Response & Detection

Staff4Me • Philippines

On-site
PHP 600,000 - 840,000
SOC Analyst - L1 and L2 (For Talent Pooling)
SOC Analyst - L1 and L2 (For Talent Pooling)

Hammerjack Pty Ltd • Philippines

On-site
PHP 600,000 - 1,000,000
SOC Lead
SOC Lead

OFFSHORE BUSINESS PROCESSING INC. • Metro Manila

On-site
PHP 558,000 - 614,000
HMO on Day 1
Travel opportunities
Performance rewards
+3
SOC Lead
SOC Lead

OFFSHORE BUSINESS PROCESSING INC. • Philippines

On-site
PHP 558,000 - 614,000
HMO day 1
Perks & rewards
Travel opportunities
+3
SOC L2 Team Lead
SOC L2 Team Lead

Gratitude Philippines • Quezon City

Hybrid
PHP 725,000 - 2,232,000
Senior SOC Analyst (L3)
Senior SOC Analyst (L3)

Permworks • Philippines

Remote
PHP 2,405,000 - 3,608,000
Health Benefits (HMO Provided)
Work from home flexibility
SOC Analyst
SOC Analyst

OFFSHORE BUSINESS PROCESSING INC. • Philippines

On-site
PHP 446,000 - 558,000
HMO on Day 1
Receive promising perks and rewards
Experience travel opportunities
+3
SOC Analyst (Online Gaming)
SOC Analyst (Online Gaming)

Sureste Properties Inc. • Parañaque

On-site
PHP 420,000 - 640,000
Cyber Defence - Global Security Operations Centre (GSOC) Level 2 Analyst
Cyber Defence - Global Security Operations Centre (GSOC) Level 2 Analyst

Willis Towers Watson • Pateros

On-site
PHP 600,000 - 900,000
SOC Analyst
SOC Analyst

Commit • Metro Manila

On-site
PHP 350,000 - 550,000