SOC Analyst – Splunk ES

Outsourcea Services Incorporated

Pasay

On-site

PHP 600,000 - 900,000

Full time

8 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Outsourcea Services Incorporated is seeking an experienced SOC Analyst to monitor security alerts, investigate incidents, and develop detections using Splunk Enterprise Security and Splunk Core. You will analyze endpoints and email security events and collaborate with clients to improve security postures.

The ideal candidate has 2+ years in a SOC, strong SPL skills, hands-on CrowdStrike Falcon and Proofpoint TAP/TRAP, and solid knowledge of SIEM, MITRE ATT&CK, and incident response processes.

Qualifications

  • 3–5 years in cybersecurity with at least 2 years in a SOC role.
  • Strong hands-on experience in security monitoring, incident response, alert triage, and threat detection.
  • Advanced Splunk ES and/or Splunk Core experience with SPL query development.
  • Hands-on CrowdStrike Falcon experience and familiarity with Proofpoint TAP/TRAP.
  • Good understanding of SIEM, endpoint security, threat detection and response processes.
  • Familiarity with MITRE ATT&CK and common cybersecurity frameworks.

Responsibilities

  • Monitor and investigate security alerts, events, and potential threats within the SOC.
  • Perform alert triage, incident investigation, containment, escalation, and follow-up.
  • Create and optimize advanced Splunk SPL queries for threat detection and investigation.
  • Develop and maintain correlation searches, dashboards, and other Splunk-based security content.
  • Review and tune detection rules to improve alert quality and minimize false positives.
  • Investigate security incidents involving endpoints and email using CrowdStrike Falcon and Proofpoint TAP/TRAP or comparable platforms.
  • Conduct security event analysis and identify indicators of compromise and potential threats.
  • Support threat hunting and proactive detection activities.
  • Maintain accurate documentation of incidents, investigations, findings, and remediation actions.
  • Work closely with Security Engineers, IT teams, and clients during investigations and response activities.

Skills

Splunk ES & SPL
Incident response
Threat detection
SOC monitoring
CrowdStrike Falcon
Proofpoint TAP/TRAP
SPL query writing
MITRE ATT&CK

Tools

Splunk Core
CrowdStrike Falcon
Proofpoint TAP/TRAP

Job description

About the role

We are seeking an experienced SOC Analyst to join our Cybersecurity team and support security monitoring, threat detection, and incident response activities. The ideal candidate has strong hands-on experience with Splunk Enterprise Security (ES) and advanced SPL query development, along with practical experience investigating security incidents across endpoint and email security platforms. You will play an important role in identifying and responding to potential threats, improving security detections, and helping maintain a strong security posture for our clients.

Key responsibilities
  • Monitor and investigate security alerts, events, and potential threats within the SOC.

  • Perform alert triage, incident investigation, containment, escalation, and follow-up.

  • Create and optimize advanced Splunk SPL queries for threat detection and investigation.

  • Develop and maintain correlation searches, dashboards, and other Splunk-based security content.

  • Review and tune detection rules to improve alert quality and minimize false positives.

  • Investigate security incidents involving endpoints and email using CrowdStrike Falcon and Proofpoint TAP/TRAP or comparable platforms.

  • Conduct security event analysis and identify indicators of compromise and potential threats.

  • Support threat hunting and proactive detection activities.

  • Maintain accurate documentation of incidents, investigations, findings, and remediation actions.

  • Work closely with Security Engineers, IT teams, and clients during investigations and response activities.

About you
  • 3–5 years of experience in cybersecurity, with at least 2 years of hands-on SOC experience.

  • Strong practical experience in security monitoring, incident response, alert triage, and threat detection.

  • Advanced experience using Splunk Enterprise Security (ES) and/or Splunk Core.

  • Strong ability to write and troubleshoot complex SPL queries.

  • Hands-on experience with CrowdStrike Falcon.

  • Experience with Proofpoint TAP/TRAP or similar email security solutions.

  • Good understanding of SIEM, endpoint security, threat detection, and incident response processes.

  • Familiarity with MITRE ATT&CK and common cybersecurity frameworks and practices.

  • Strong analytical and problem-solving skills.

  • Good written and verbal communication skills.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Analyst: Splunk ES & Threat Detection Expert
SOC Analyst: Splunk ES & Threat Detection Expert

Outsourcea Services Incorporated • Pasay

On-site
PHP 600,000 - 900,000
Security Engineer (SIEM & SOAR)
Security Engineer (SIEM & SOAR)

Metacom Careers • Quezon City

On-site
PHP 600,000 - 900,000
SOC Analyst
SOC Analyst

Commit • Metro Manila

On-site
PHP 350,000 - 550,000
Splunk Enterprise Security Engineer
Splunk Enterprise Security Engineer

Orbus International • Hinoba-an

On-site
PHP 900,000 - 1,300,000
IT Security Analyst
IT Security Analyst

IBEX Global Solutions (Philippines) Inc. • Davao del Sur

On-site
PHP 420,000 - 560,000
Senior SIEM Engineer for Cybersecurity Detection
Senior SIEM Engineer for Cybersecurity Detection

Boehringer Ingelheim GmbH • Hinoba-an

On-site
PHP 1,200,000 - 1,800,000
SOC Analyst/Incident Response Analyst
SOC Analyst/Incident Response Analyst

PM Consulting • Metro Manila

On-site
PHP 320,000 - 520,000
IT Security Analyst
IT Security Analyst

Ibex Limited • Davao del Sur

On-site
PHP 480,000 - 840,000
Senior Security Engineer – SOC
Senior Security Engineer – SOC

42 Gears Mobility Systems • Hinoba-an

On-site
PHP 995,000 - 1,592,000
Jr. SOC Analyst
Jr. SOC Analyst

Kinettix • Manila

On-site
PHP 350,000 - 550,000