Stand out for this role — generate a tailored resume and cover letter in about a minute.
solaireresort is seeking a Security Operations Analyst in the Philippines to monitor SIEM dashboards, alerts, and security events across network, endpoint, cloud, and applications on a 24/7 shift rotation. You will conduct initial triage, classify incidents, and prioritize findings following documented playbooks and runbooks.
You will escalate validated or complex incidents to SOC L2 with detailed documentation, perform routine health checks on monitoring tools, and maintain thorough shift
Monitor SIEM dashboards, alerts, and security events across network, endpoint, cloud, and application log sources on a 24/7 shift rotation. Perform initial triage, classification, and prioritization of security alerts following documented playbooks and runbooks. Escalate validated or complex incidents to SOC L2 with complete and accurate documentation of findings and actions taken. Record all alerts, investigations, and response actions in the case management/ticketing system. Perform routine health checks on security monitoring tools and report gaps in log sources or detection coverage. Triage phishing reports and user-reported security concerns, executing first-response steps per playbook. Execute containment actions as directed by SOC L2 or the incident lead during active incidents. Contribute tuning recommendations to reduce false positives and improve alert quality. Maintain complete shift-handover logs to ensure continuity of monitoring between shifts.
Mean time to acknowledge (MTTA) alerts within defined SLAs. Alert triage accuracy and quality of escalations to SOC L2. Percentage of alerts and cases handled within SLA. Completeness and quality of case documentation and shift handovers. False-positive identification and tuning recommendations submitted.
Education: Bachelor’s degree in computer science, information technology, or a related field, or equivalent practical experience. Experience: 0–2 years in security operations, IT support, or network/system administration; prior SOC or managed security service experience preferred. Must be willing to work on a 24/7 shift rotation.
Skills & Knowledge: Foundational knowledge of networking (TCP/IP, DNS, HTTP), Windows and Linux operating systems, and common attack techniques (MITRE ATT&CK); familiarity with SIEM platforms (Splunk, Microsoft Sentinel, QRadar, or similar) and ticketing tools.
Certifications (good to have): CompTIA Security+, CompTIA CySA+, or Microsoft SC-200 preferred.