SOC Security Analyst L2

BlueVoyant

Philippines

Hybrid

PHP 600,000 - 900,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

BlueVoyant is seeking a SOC Security Analyst L2 in a hybrid Manila location. You will own a queue of security alerts, conduct thorough investigations, resolve cases fit for SLAs, and escalate to L3 with well-documented findings.

You will collaborate with senior analysts and clients to minimize dwell time and impact. You will work with SIEM, EDR, and Cloud App Security tools, analyze endpoint, web, and email logs, and contribute to runbooks while maintaining client-approved procedures and access

Qualifications

  • Ability to manage a high‑volume ticket queue in a fast‑paced environment with accuracy.
  • Clear written and verbal communication; document findings clearly.
  • Strong teamwork within a globally distributed team.
  • Ability to work with clients to provide updates and gather information.
  • Knowledge and experience with SIEM solutions, Cloud App Security tools, and EDR.
  • Experience in endpoint, web, email, and authentication log analysis.
  • Understanding of network protocols and network telemetry.
  • Knowledge of attack techniques including phishing, BEC, credential harvesting, LOLBin, and lateral movement.

Responsibilities

  • Monitor, triage, and investigate security alerts and tickets from multiple sources including SIEM logs and EDR telemetry.
  • Own assigned tickets through to resolution within defined SLAs and prioritization by severity and client impact.
  • Research indicators and activities to determine reputation and suspicious attributes.
  • Analyze suspicious files, emails, URLs, and attacker infrastructure to support investigations.
  • Determine malicious vs benign vs false positives and escalate as needed with evidence.
  • Document investigation steps, findings, and recommended actions in the ticketing system.
  • Take initial response actions per runbooks and client procedures (e.g., isolate endpoints).
  • Communicate ticket updates to clients and share remediation guidance.
  • Identify false positives and propose tuning improvements.
  • Contribute to runbooks, procedures, and automation improvements.
  • Support L1 analysts and incorporate feedback from L3 QA.
  • Operate across BlueVoyant systems and client environments with strict access controls.

Skills

Ticket queue management
Clear written communication
Team collaboration
Client communication
SIEM knowledge
Cloud App Security
EDR
Network telemetry understanding
Phishing awareness

Tools

SIEM
Cloud App Security
EDR

Job description

Position: SOC Security Analyst L2
Reports To: SOC Team Lead / SOC Manager
Department: Security Operations Center (SOC)
Location: Hybrid, Manilla (Philippines)
Shift Schedule: Sunday–Wednesday or Wednesday–Saturday, 7:00am–5:00pm
Work Authorization: Philippine Citizenship Required

BlueVoyant is seeking a SOC Security Analyst L2 to join our Security Operations Center, defending our global customers against constant and evolving adversary activity. In this role you will own and work through a queue of security alerts and tickets, carrying out thorough investigations, resolving cases accurately and efficiently, and escalating confirmed or complex incidents to L3 analysts with clear, well‑documented findings. You will work closely with senior analysts and clients to reduce the impact and dwell time of security incidents. This role reports into BlueVoyant SOC leadership and operates under BlueVoyant processes, tooling, and supervision at all times, including when working within client environments.

What You'll Do:
  • Monitor, triage, and investigate security alerts and tickets from multiple sources, including SIEM logs, endpoint logs, and EDR telemetry.
  • Own assigned tickets through to resolution, working within defined SLAs and prioritizing by severity and client impact.
  • Research indicators and activities to determine reputation and suspicious attributes.
  • Perform analysis of suspicious files, emails, URLs, and attacker infrastructure to support investigations.
  • Determine whether activity is malicious, benign, or a false positive, and upscale verified or complex incidents to L3 analysts with clear supporting evidence.
  • Document investigation steps, findings, and recommended actions accurately within the ticketing and case management system.
  • Take initial response actions in line with runbooks and client‑approved procedures, such as isolating endpoints or disabling compromised accounts.
  • Communicate with clients to provide ticket updates, request information, and share remediation guidance.
  • Identify false‑positive or benign detections and recommend tuning improvements.
  • Contribute to the improvement of runbooks, procedures, and automation.
  • Support and share knowledge with L1 analysts and incorporate feedback from L3 peer review and QA.
  • Operate across BlueVoyant‑managed systems and client‑provided environments in accordance with client‑approved access controls, logging, and BlueVoyant operating procedures, maintaining strict separation and adherence to security policies.
What You'll Bring
  • Ability to manage a high‑volume ticket queue in a fast‑paced environment while maintaining accuracy and attention to detail.
  • Strong written and verbal communication skills, with the ability to document findings clearly and explain technical issues in easy‑to‑understand language.
  • Strong teamwork and interpersonal skills, including working effectively within a globally distributed team.
  • Ability to work directly with clients to provide updates and gather information.
  • Knowledge and experience with SIEM solutions, Cloud App Security tools, and EDR.
  • Experience in endpoint, web, email, and authentication log analysis.
  • Solid understanding of network protocols and network telemetry.
  • Knowledge of common attack techniques, including phishing, business email compromise (BEC), credential harvesting, LOLBin use, and lateral movement.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Security Analyst L2
SOC Security Analyst L2

BlueVoyant • Manila

Hybrid
PHP 670,000 - 1,004,000
SOC Security Analyst II — Incident Triage & Response
SOC Security Analyst II — Incident Triage & Response

BlueVoyant • Philippines

Hybrid
PHP 600,000 - 900,000
Soc Analyst L2
Soc Analyst L2

Staff4Me • Philippines

On-site
PHP 600,000 - 840,000
Senior SOC Security Analyst L3 (Remote, Philippines)
Senior SOC Security Analyst L3 (Remote, Philippines)

BlueVoyant • Philippines

Remote
PHP 600,000 - 900,000
SOC Security Analyst L3
SOC Security Analyst L3

BlueVoyant • Philippines

Remote
PHP 600,000 - 900,000
SOC Security Analyst II: Triage & Incident Response
SOC Security Analyst II: Triage & Incident Response

BlueVoyant • Manila

Hybrid
PHP 670,000 - 1,004,000
Security Operations Analyst II
Security Operations Analyst II

Vertiv Group Corporation • Mandaluyong

On-site
PHP 600,000 - 900,000
Security Operations Analyst II
Security Operations Analyst II

Vertiv Co • Mandaluyong

On-site
PHP 480,000 - 720,000
Security Operations Center Analyst
Security Operations Center Analyst

LanceSoft, Inc. • Metro Manila

On-site
PHP 500,000 - 900,000
Senior SOC Analyst (L3)
Senior SOC Analyst (L3)

Permworks • Philippines

On-site
PHP 2,405,291 - 3,607,937
Health Benefits (HMO Provided)
Work from home flexibility