SOC Security Analyst II — Incident Triage & Response

BlueVoyant

Philippines

Hybrid

PHP 600,000 - 900,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

BlueVoyant is seeking a SOC Security Analyst L2 in a hybrid Manila location. You will own a queue of security alerts, conduct thorough investigations, resolve cases fit for SLAs, and escalate to L3 with well-documented findings.

You will collaborate with senior analysts and clients to minimize dwell time and impact. You will work with SIEM, EDR, and Cloud App Security tools, analyze endpoint, web, and email logs, and contribute to runbooks while maintaining client-approved procedures and access

Qualifications

  • Ability to manage a high‑volume ticket queue in a fast‑paced environment with accuracy.
  • Clear written and verbal communication; document findings clearly.
  • Strong teamwork within a globally distributed team.
  • Ability to work with clients to provide updates and gather information.
  • Knowledge and experience with SIEM solutions, Cloud App Security tools, and EDR.
  • Experience in endpoint, web, email, and authentication log analysis.
  • Understanding of network protocols and network telemetry.
  • Knowledge of attack techniques including phishing, BEC, credential harvesting, LOLBin, and lateral movement.

Responsibilities

  • Monitor, triage, and investigate security alerts and tickets from multiple sources including SIEM logs and EDR telemetry.
  • Own assigned tickets through to resolution within defined SLAs and prioritization by severity and client impact.
  • Research indicators and activities to determine reputation and suspicious attributes.
  • Analyze suspicious files, emails, URLs, and attacker infrastructure to support investigations.
  • Determine malicious vs benign vs false positives and escalate as needed with evidence.
  • Document investigation steps, findings, and recommended actions in the ticketing system.
  • Take initial response actions per runbooks and client procedures (e.g., isolate endpoints).
  • Communicate ticket updates to clients and share remediation guidance.
  • Identify false positives and propose tuning improvements.
  • Contribute to runbooks, procedures, and automation improvements.
  • Support L1 analysts and incorporate feedback from L3 QA.
  • Operate across BlueVoyant systems and client environments with strict access controls.

Skills

Ticket queue management
Clear written communication
Team collaboration
Client communication
SIEM knowledge
Cloud App Security
EDR
Network telemetry understanding
Phishing awareness

Tools

SIEM
Cloud App Security
EDR

Job description

BlueVoyant is seeking a SOC Security Analyst L2 in a hybrid Manila location. You will own a queue of security alerts, conduct thorough investigations, resolve cases fit for SLAs, and escalate to L3 with well-documented findings.

You will collaborate with senior analysts and clients to minimize dwell time and impact. You will work with SIEM, EDR, and Cloud App Security tools, analyze endpoint, web, and email logs, and contribute to runbooks while maintaining client-approved procedures and access

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Security Analyst II: Triage & Incident Response
SOC Security Analyst II: Triage & Incident Response

BlueVoyant • Manila

Hybrid
PHP 670,000 - 1,004,000
SOC Security Analyst L2
SOC Security Analyst L2

BlueVoyant • Philippines

Hybrid
PHP 600,000 - 900,000
SOC Security Analyst L2
SOC Security Analyst L2

BlueVoyant • Manila

Hybrid
PHP 670,000 - 1,004,000
Senior SOC Security Analyst L3 (Remote, Philippines)
Senior SOC Security Analyst L3 (Remote, Philippines)

BlueVoyant • Philippines

Remote
PHP 600,000 - 900,000
SOC Analyst II: Incident Response & Threat Detection
SOC Analyst II: Incident Response & Threat Detection

Vertiv Co • Mandaluyong

On-site
PHP 480,000 - 720,000
SOC Analyst L2 - Incident Response & Detection
SOC Analyst L2 - Incident Response & Detection

Staff4Me • Philippines

On-site
PHP 600,000 - 840,000
SOC Analyst II: Incident Response & Threat Hunting
SOC Analyst II: Incident Response & Threat Hunting

Vertiv • Mandaluyong

On-site
PHP 700,000 - 1,000,000
Hybrid SOC L2 Team Lead: Incident Response & Mentoring
Hybrid SOC L2 Team Lead: Incident Response & Mentoring

Gratitude Philippines • Quezon City

Hybrid
PHP 725,000 - 2,232,000
Soc Analyst L2
Soc Analyst L2

Staff4Me • Philippines

On-site
PHP 600,000 - 840,000
Remote SOC Analyst II - Security Monitoring & Response
Remote SOC Analyst II - Security Monitoring & Response

Supply Chimp • Metro Manila

Remote
PHP 725,000 - 893,000
HMO on Day 1
Internet stipend
Rice allowance
+4