SOC Analyst (Online Gaming)

Sureste Properties Inc.

Parañaque

On-site

PHP 420,000 - 640,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Sureste Properties Inc. is seeking a Security Operations Analyst to monitor SIEM dashboards, triage alerts, and coordinate with SOC L2 on complex incidents. You will document findings and actions, perform routine health checks, and support containment during active events.

Ideal candidates have a basic grounding in networking, Windows and Linux, familiarity with MITRE ATT&CK, and experience with SIEM and ticketing tools. A degree in CS or IT and 0–2 years in security operations are preferred.

Qualifications

  • Bachelor’s degree in computer science, information technology, or a related field, or equivalent practical experience.
  • 0–2 years in security operations, IT support, or network/system administration; prior SOC or managed security service experience preferred.
  • Foundational knowledge of networking (TCP/IP, DNS, HTTP), Windows and Linux operating systems, and common attack techniques (MITRE ATT&CK).
  • Familiarity with SIEM platforms (Splunk, Microsoft Sentinel, QRadar, or similar) and ticketing tools.
  • Certifications such as CompTIA Security+, CompTIA CySA+, or Microsoft SC-200 are a plus.

Responsibilities

  • Monitor SIEM dashboards, alerts, and security events across network, endpoint, cloud, and application log sources on a 24/7 shift rotation.
  • Perform initial triage, classification, and prioritization of security alerts following documented playbooks and runbooks.
  • Escalate validated or complex incidents to SOC L2 with complete and accurate documentation of findings and actions taken.
  • Record all alerts, investigations, and response actions in the case management/ticketing system.
  • Perform routine health checks on security monitoring tools and report gaps in log sources or detection coverage.
  • Triage phishing reports and user-reported security concerns, executing first-response steps per playbook.
  • Execute containment actions as directed by SOC L2 or the incident lead during active incidents.
  • Contribute tuning recommendations to reduce false positives and improve alert quality.
  • Maintain complete shift-handover logs to ensure continuity of monitoring between shifts.

Education

Bachelor’s degree in computer science or related field

Tools

Splunk
Microsoft Sentinel
QRadar

Job description

Duties and Responsibilities
  • Monitor SIEM dashboards, alerts, and security events across network, endpoint, cloud, and application log sources on a 24/7 shift rotation.
  • Perform initial triage, classification, and prioritization of security alerts following documented playbooks and runbooks.
  • Escalate validated or complex incidents to SOC L2 with complete and accurate documentation of findings and actions taken.
  • Record all alerts, investigations, and response actions in the case management/ticketing system.
  • Perform routine health checks on security monitoring tools and report gaps in log sources or detection coverage.
  • Triage phishing reports and user-reported security concerns, executing first-response steps per playbook.
  • Execute containment actions as directed by SOC L2 or the incident lead during active incidents.
  • Contribute tuning recommendations to reduce false positives and improve alert quality.
  • Maintain complete shift-handover logs to ensure continuity of monitoring between shifts.
Key Performance Indicators
  • Mean time to acknowledge (MTTA) alerts within defined SLAs.
  • Alert triage accuracy and quality of escalations to SOC L2.
  • Percentage of alerts and cases handled within SLA.
  • Completeness and quality of case documentation and shift handovers.
  • False-positive identification and tuning recommendations submitted.
Qualifications and Requirements
  • Education: Bachelor’s degree in computer science, information technology, or a related field, or equivalent practical experience.
  • Experience: 0–2 years in security operations, IT support, or network/system administration; prior SOC or managed security service experience preferred. Must be willing to work on a 24/7 shift rotation.
  • Skills & Knowledge: Foundational knowledge of networking (TCP/IP, DNS, HTTP), Windows and Linux operating systems, and common attack techniques (MITRE ATT&CK); familiarity with SIEM platforms (Splunk, Microsoft Sentinel, QRadar, or similar) and ticketing tools.
  • Certifications (good to have): CompTIA Security+, CompTIA CySA+, or Microsoft SC-200 preferred.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Analyst/Incident Response Analyst
SOC Analyst/Incident Response Analyst

PM Consulting • Metro Manila

On-site
PHP 320,000 - 520,000
SOC Analyst - L1 and L2 (For Talent Pooling)
SOC Analyst - L1 and L2 (For Talent Pooling)

Hammerjack Pty Ltd • Philippines

On-site
PHP 600,000 - 1,000,000
SOC Analyst
SOC Analyst

Paynamics • Philippines

On-site
PHP 600,000 - 900,000
Security Analyst – SOC
Security Analyst – SOC

Moder Solutions Inc. • Cebu City

On-site
PHP 420,000 - 720,000
Associate Security Analyst
Associate Security Analyst

itm8 Danmark • Lapu-Lapu

On-site
PHP 480,000 - 640,000
SOC Analyst
SOC Analyst

Commit • Metro Manila

On-site
PHP 350,000 - 550,000
Security Operations Center (SOC) - Head
Security Operations Center (SOC) - Head

SMITS, Inc. - IT Company of San Miguel Corporation • Mandaluyong

On-site
PHP 900,000 - 1,600,000
IT Security Analyst
IT Security Analyst

SGL Manila (Shared Service Center), Inc. • Muntinlupa

On-site
PHP 600,000 - 900,000
Cyber Defence - Global Security Operations Centre (GSOC) Level 2 Analyst
Cyber Defence - Global Security Operations Centre (GSOC) Level 2 Analyst

WTW • Taguig

On-site
PHP 1,200,000 - 1,600,000
Security Analyst / Network Security Analyst
Security Analyst / Network Security Analyst

RippedBoxStation • Philippines

On-site
PHP 260,000 - 420,000