SOC L1 Security Operations Analyst (24/7 Shift)

Zohorecruit

Parañaque

On-site

PHP 335,000 - 614,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Zohorecruit seeks a Security Operations Center professional to monitor SIEM dashboards and security events across network, endpoint, cloud, and applications on a 24/7 shift rotation. You will perform initial triage, classify alerts, and escalate complex incidents with thorough documentation.

Responsibilities include recording investigations in the ticketing system, conducting health checks, triaging phishing reports, and executing containment steps as directed.

Qualifications

  • Bachelor’s degree in computer science, information technology, or a related field, or equivalent practical experience.
  • 0–2 years in security operations, IT support, or network/system administration; willing to work on a 24/7 shift rotation.
  • Foundational knowledge of networking (TCP/IP, DNS, HTTP), Windows and Linux operating systems, and common attack techniques (MITRE ATT&CK).
  • Certifications (good to have): CompTIA Security+, CompTIA CySA+, or Microsoft SC-200 preferred.

Responsibilities

  • Monitor SIEM dashboards, alerts, and security events across network, endpoint, cloud, and application log sources on a 24/7 shift rotation.
  • Perform initial triage, classification, and prioritization of security alerts following documented playbooks and runbooks.
  • Escalate validated or complex incidents to SOC L2 with complete and accurate documentation of findings and actions taken.
  • Record all alerts, investigations, and response actions in the case management/ticketing system.
  • Perform routine health checks on security monitoring tools and report gaps in log sources or detection coverage.
  • Triage phishing reports and user-reported security concerns, executing first-response steps per playbook.
  • Execute containment actions as directed by SOC L2 or the incident lead during active incidents.
  • Contribute tuning recommendations to reduce false positives and improve alert quality.
  • Maintain complete shift-handover logs to ensure continuity of monitoring between shifts.

Education

Bachelor’s degree in computer science, information technology, or a related field

Tools

Splunk
Microsoft Sentinel
QRadar
Ticketing tools

Job description

Zohorecruit seeks a Security Operations Center professional to monitor SIEM dashboards and security events across network, endpoint, cloud, and applications on a 24/7 shift rotation. You will perform initial triage, classify alerts, and escalate complex incidents with thorough documentation.

Responsibilities include recording investigations in the ticketing system, conducting health checks, triaging phishing reports, and executing containment steps as directed.

Get your free, confidential resume review.

or drag and drop your file here.