A complete application in a minute — tailored resume and cover letter, ready to send.
Gratitude Philippines is hiring a SOC L2 Team Lead in a hybrid Cubao office for complex incident response and cyber defense. The role emphasizes leading analysts, driving incident response efforts, and improving security operations across enterprise environments.
The ideal candidate will have 3–5+ years in a SOC/IR role, hands-on SIEM experience, and strong knowledge of network security, malware analysis, and threat hunting.
JOB TITLE: SOC L2 WORK SETUP: Hybrid in Cubao WORK SHIFT: Shifting Salary budget: 65K - 200K
Work Mode: Hybrid
Sub-city: Cubao
City: Quezon City
Desired Shift: Shifting / Flexible
Job Type: Full-time
Role: SOC L2 Team Lead
Industry: BPO / IT Services
Function: Cybersecurity / Information security
Lead Incident Response. Strengthen Cyber Defense. Join Accenture's Cybersecurity team as a SOC Team Lead (L2) and play a key role in detecting, investigating, and responding to advanced security threats. This role is ideal for experienced SOC professionals who enjoy leading analysts, driving incident response efforts, and continuously improving security operations.
Lead the investigation and resolution of complex security incidents escalated by L1 analysts.
Perform root cause analysis, threat validation, and incident triage across enterprise environments. Act as a key responder during high-severity incidents, coordinating with CSIRT, engineering teams, and stakeholders. Conduct threat hunting activities using indicators of compromise (IoCs) and threat intelligence.
Mentor and guide SOC analysts through coaching, quality reviews, and incident handling best practices. Collaborate with detection engineering teams to improve use cases, alert quality, and SOC processes. Maintain incident documentation, reports, playbooks, and operational procedures.
3–5+ years of experience in a SOC, Incident Response, or Cyber Defense environment.
Previous experience leading, mentoring, or supervising SOC analysts is highly preferred. Strong hands‑on experience investigating security incidents using SIEM and security monitoring tools. Knowledge of network security, threat detection, malware analysis, incident response, and threat hunting.
Experience analyzing logs, network traffic, and security events across enterprise environments. Ability to work effectively during high-priority security incidents and coordinate cross‑functional response efforts.
Experience with CrowdStrike Falcon (highly preferred). Hands‑on experience with SIEM platforms such as Splunk, Sentinel, QRadar, Google SecOps, or similar. Scripting experience using Python or PowerShell for automation and investigations. Certifications such as Security+, CEH, GCIH, GCIA, or similar. Exposure to cloud security monitoring across AWS, Azure, or GCP.
Hybrid work arrangement Cubao office location Amenable to possible shifting schedules Additional details: Open for those applicants who are currently in Philippines and already have the right to live and work in this country are eligible for this role