SOC Analyst Lead - L3 Incident Response

KPMG R.G. Manabat & Co.

Manila

On-site

PHP 250,000 - 450,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

HMO with 2 Free Dependents
Communication Allowance
Rice Allowance
Clothing Allowance
Christmas/Holiday Gift (Christmas Cash
Group Personal Accident Insurance
Life Insurance
Optical, Medicine, and Dental Allow an
Bereavement Assistance

Job summary

KPMG R.G. Manabat & Co. is hiring for a senior security leadership role to define the strategic direction of Managed Detection & Response as a managed service in a 24/7 environment.

You will lead a team to orchestrate incidents, analyze threat data, and coordinate with clients and channels. Ideal candidates have 7+ years in enterprise security operations, threat hunting, and cloud security, with relevant certifications and SaaS/IaaS product experience.

Qualifications

  • 7+ years experience leading Enterprise Security Operations Centers or MDR/IR teams.
  • Experience in L3 SOC analyst, threat hunting, pen testing, forensics, IR, vulnerabilities and attacks.
  • Experience with on-prem, hybrid and cloud security concepts and protocols.
  • Demonstrated understanding of modern product discovery and delivery for SaaS/IaaS offerings.
  • Familiarity with 24/7 high-availability managed services.

Responsibilities

  • Formulate and define strategic direction for Managed Detection & Response as a managed service.
  • Grow pipeline by working with internal and external channels.
  • Identify pull-through opportunities for other managed services and consulting services.
  • Perform investigation and orchestration for complex/high severity security alerts, threats or incidents.
  • Provide people, process and technology background to ensure timely detection and alerting of attacks/intrusions.
  • Isolate, triage and eradicate malicious behaviors.
  • Lead incident response orchestration with clients.
  • Direct product managers in developing new or modified MDR solutions.
  • Create and develop SOC processes and Use Case Catalog.

Skills

Leadership
Enterprise security operations
Threat hunting
Incident response
Product discovery knowledge

Tools

CEH
GIAC
OSCP
CREST
GCIH
CCIA
GPEN
Microsoft
Splunk
Sentinel

Job description

About the role

Formulate and define the strategic direction for Managed Detection & Response as a managed service. Grow pipeline of the solution by working closely with internal and external channels. Identify and create pull through opportunity for other managed services and consulting services. Keep abreast of industrial, technology and business trends. Perform investigation and orchestration for complex/high severity security alerts, threats or incidents. Serve as the lead point of contact facilitating incident response orchestration with client. Lead research, analysis and correlation efforts across a variety of all source data sets/collectors, log collectors and threat feeds to inform and guide the strategic direction of the offering. Monitor competitive landscape in pricing, capabilities and offerings to analyze and report system security posture trends. As a leader of a team, ensure that the right things are being worked on at the right time, and ensure quality throughout.

Key responsibilities
  • Formulate and define the strategic direction for Managed Detection & Response as a managed service

  • Grow pipeline of the solution by working closely with internal and external channels

  • Identify and create pull through opportunity for other managed services and consulting services

  • Perform investigation and orchestration for complex/high severity security alerts, threats or incidents

  • Provide the people, process and technology background to ensure timely detection, identification and alerting of possible attacks/intrusions, anomalous activities, intrusion attempts/compromises, malicious behavior, insider risk, and misuse activities

  • Isolate, triage and eradicate malicious behaviors

  • Serve as the lead point of contact facilitating incident response orchestration with client

  • Lead research, analysis and correlation efforts across a variety of all source data sets/collectors, log collectors and threat feeds

  • Direct technical product managers in developing new or modified solutions for Managed Detection and Response

  • Create and develop SOC processes and procedures, lead strategy development, methodology and execution of Use Case Catalog

About you
  • At least 7+ years of experience leading Enterprise Security Operations Centers or Managed Detection and Response analyst or incident response teams

  • Experience in lead security operations center analyst (L3), threat hunting, penetration testing, digital forensics, incident response, recognizing and categorizing organizational vulnerabilities and attacks, on-prem, hybrid and cloud security concepts and protocols

  • Certifications: CEH, GIAC, OSCP, CREST, GCIH, CCIA, GPEN, Platform Certifications (Microsoft, Splunk, Sentinel, etc.)

  • Experience with one or more of the following: Cyber-Security solutions, Security Operation Center, Threat Intelligence Management, Vulnerability Research, Digital Forensics, Incident Response, Endpoint Management, Network Security

  • Product Management experience with Software as a Service (SaaS) or Infrastructure as a Service (IaaS) offerings for enterprises

  • Experience in the enterprise software market and with services / product companies

  • Demonstrated understanding of the techniques and methods of modern product discovery and product delivery

  • Knowledge of a global, 24/7, high availability and high trust operation aspects of managed services

  • Familiarity with engineering work of a security operation center

  • 3+ years Level 3 SOC Analyst experience

Benefits
  • HMO with 2 Free Dependents

  • Communication Allowance

  • Rice Allowance

  • Clothing Allowance

  • Christmas/Holiday Gift (Christmas Cash Gift)

  • Group Personal Accident Insurance

  • Life Insurance

  • Optical, Medicine, and Dental Allowance

  • Bereavement Assistance

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

Microgenesis Business Systems • Mandaluyong

On-site
PHP 279,000 - 390,600
Health insurance
Life insurance
Additional leave
+2
Cyber Defence - Global Security Operations Centre (GSOC) Level 2 Analyst
Cyber Defence - Global Security Operations Centre (GSOC) Level 2 Analyst

WTW • Taguig

On-site
PHP 1,200,000 - 1,600,000
SOC Analyst
SOC Analyst

Offshore Business Processing Inc. • Hinoba-an

On-site
PHP 446,000 - 558,000
HMO on Day 1
Perks and rewards
Travel opportunities
+1
Security Operations Center Analyst
Security Operations Center Analyst

Centrics Networks • Cebu City

On-site
PHP 400,000 - 640,000
Cyber Defence - Global Security Operations Centre (GSOC) Level 2 Analyst
Cyber Defence - Global Security Operations Centre (GSOC) Level 2 Analyst

Willis Towers Watson • Pateros

On-site
PHP 600,000 - 900,000
SOC Analyst
SOC Analyst

OFFSHORE BUSINESS PROCESSING INC. • Philippines

On-site
PHP 446,000 - 558,000
HMO on Day 1
Receive promising perks and rewards
Experience travel opportunities
+3
SOC Lead
SOC Lead

OFFSHORE BUSINESS PROCESSING INC. • Philippines

On-site
PHP 558,000 - 614,000
HMO day 1
Perks & rewards
Travel opportunities
+3
SOC Analyst
SOC Analyst

Continent 8 Technologies • Makati

On-site
PHP 900,000 - 1,300,000
SOC Lead
SOC Lead

OFFSHORE BUSINESS PROCESSING INC. • Metro Manila

On-site
PHP 558,000 - 614,000
HMO on Day 1
Travel opportunities
Performance rewards
+3
SOC Analyst
SOC Analyst

Continent 8 Technologies • Manila, Hinoba-an

On-site
PHP 600,000 - 850,000