SOC Analyst L2 - Incident Response & Detection

Staff4Me

Philippines

On-site

PHP 600,000 - 840,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Staff4me is seeking a SOC Analyst L2 in the Philippines to lead deeper investigations of escalated cases, confirm incidents, determine scope and impact, and drive containment actions with internal teams. You will produce high-quality technical communications and post-incident outputs, and contribute to detection improvements through playbooks updates.

The role requires 2-5 years in SOC/IR, strong networking fundamentals, EDR experience, and proficiency in English for clear stakeholder updates.

Qualifications

  • 2-5 years in SOC/IR/Blue Team or equivalent incident handling experience.
  • Solid fundamentals in networking: TCP/IP, DNS, HTTP/S, VPN, NAT.
  • EDR investigations (process trees, persistence, LOLBins) and containment workflows.
  • Windows/AD triage (authentication patterns, suspicious logon) and Linux triage.
  • Network analysis and security controls (firewall/IDS/proxy/DNS).
  • Proven ability to produce defensible scoping and timelines based on evidence.
  • High documentation standards and ability to perform under pressure.
  • Threat hunting experience and MITRE ATT&CK mapping.
  • Detection engineering exposure (Sigma/YARA) and SIEM correlation strategy.
  • Basic forensics concepts (acquisition, triage artifacts).
  • Certifications aligned to Blue Team / IR (e.g., GCIH/GCIA, SC-200).
  • Strong English (B2-High/C1) for technical calls and incident notes.

Responsibilities

  • Take escalations from L1 and perform in-depth investigations: hypothesis-driven analysis, evidence validation, scoping, impact assessment, and timeline building.
  • Correlate telemetry across endpoint (EDR), Windows/Linux, AD, firewall/proxy/DNS/IDS, and cloud logs.
  • Recommend and coordinate containment actions following change control and governance.
  • Determine severity and communicate clearly in English to technical stakeholders; provide concise executive updates.
  • Identify detection gaps and drive improvements: reduce false positives and close false negatives.
  • Ensure evidence integrity and proper documentation; coordinate handoffs with IR, IT Ops, Network, and Cloud teams.
  • Produce post-incident deliverables: probable root cause, lessons learned, and preventive actions.

Skills

SOC/IR Experience
Threat Hunting
MITRE ATT&CK
English Communication
Detection Engineering
EDR Investigations
Forensics Basics

Tools

EDR
Windows/AD
Linux Triage
Firewall/IDS/Proxy
Sigma/YARA
SIEM

Job description

Staff4me is seeking a SOC Analyst L2 in the Philippines to lead deeper investigations of escalated cases, confirm incidents, determine scope and impact, and drive containment actions with internal teams. You will produce high-quality technical communications and post-incident outputs, and contribute to detection improvements through playbooks updates.

The role requires 2-5 years in SOC/IR, strong networking fundamentals, EDR experience, and proficiency in English for clear stakeholder updates.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Soc Analyst L2
Soc Analyst L2

Staff4Me • Philippines

On-site
PHP 600,000 - 840,000
IT Security Analyst: Incident Response & Threat Hunting
IT Security Analyst: Incident Response & Threat Hunting

PFCC Group • Manila

On-site
PHP 900,000 - 1,700,000
Senior SOC Analyst: Threat Detection & IR
Senior SOC Analyst: Threat Detection & IR

N-able • Taguig

On-site
PHP 800,000 - 1,000,000
Medical and dental insurance
Generous PTO and holidays
Employee Stock Purchase Program
+2
Hybrid SOC L2 Team Lead: Incident Response & Mentoring
Hybrid SOC L2 Team Lead: Incident Response & Mentoring

Gratitude Philippines • Quezon City

Hybrid
PHP 725,000 - 2,232,000
SOC Analyst I: Monitoring & Triage Specialist
SOC Analyst I: Monitoring & Triage Specialist

MVP Asia Pacific Inc. • Mabalacat

On-site
PHP 420,000 - 650,000
SOC Lead: Incident Response & Threat Hunting Leader
SOC Lead: Incident Response & Threat Hunting Leader

OFFSHORE BUSINESS PROCESSING INC. • Metro Manila

On-site
PHP 558,000 - 614,000
HMO on Day 1
Travel opportunities
Performance rewards
+3
SOC L2 Cyber Defense Lead - Incident Response
SOC L2 Cyber Defense Lead - Incident Response

WTW • Taguig

On-site
PHP 1,200,000 - 1,600,000
SOC Analyst — Fast-Track Cyber Defense & Growth
SOC Analyst — Fast-Track Cyber Defense & Growth

OFFSHORE BUSINESS PROCESSING INC. • Philippines

On-site
PHP 446,000 - 558,000
HMO on Day 1
Receive promising perks and rewards
Experience travel opportunities
+3
Junior SOC Analyst: Incident Response & Monitoring
Junior SOC Analyst: Incident Response & Monitoring

Dsv Inc • Philippines

On-site
PHP 240,000 - 320,000
Remote Senior SOC Analyst (L3) – Threat Intel & IR Lead
Remote Senior SOC Analyst (L3) – Threat Intel & IR Lead

Permworks • Philippines

Remote
PHP 2,405,000 - 3,608,000
Health Benefits (HMO Provided)
Work from home flexibility