SOC Security Analyst L3

BlueVoyant

Philippines

A distancia

PHP 600.000 - 900.000

Jornada completa

Hace 9 días
Generador de candidaturas

Una candidatura hecha a medida para este puesto de trabajo — un currículum y una carta de presentación adaptados que responden directamente a la oferta.

Supera los filtros ATS

Descripción de la vacante

BlueVoyant is seeking a SOC Security Analyst L3 to join the Security Operations Center. You will act as a senior technical expert, handle intrusions, mentor junior analysts, and communicate clearly with clients on investigations and remediation.

The role requires strong SIEM/EDR expertise, collaboration across a global team, and adherence to client and internal security controls while supporting ongoing security enhancements.

Formación

  • Bachelor's degree in Information Security, CS, or related field or equivalent experience.
  • 5+ years in SOC/TOC/NOC with incident handling experience preferred.
  • Strong communication and client-facing skills, ability to mentor teammates.

Responsabilidades

  • Monitor security events from SIEM, EDR, and logs across sources.
  • Act as escalation point for active intrusions and junior analysts.
  • Lead investigations, perform live response analysis, and declare incidents.
  • Document findings and remediation actions for clients.
  • Coordinate with Incident Response teams and advise on improvements.

Conocimientos

Advanced communication
Team collaboration
Client interaction
Mentoring junior analysts
Incident response
Analytical thinking

Educación

Bachelor's in Information Security

Herramientas

Microsoft Sentinel
Splunk
Microsoft Defender
CrowdStrike Falcon
SentinelOne
EDR
SIEM

Descripción del empleo

Position: SOC Security Analyst L3
Reports To: SOC Team Lead / SOC Manager
Department: Security Operations Center (SOC)
Location: Remote, Philippines
Shift Schedule: Sunday-Wednesday or Wednesday-Saturday, 7:00am-5:00pm
Work Authorization: Philippine Citizenship Required
BlueVoyant is seeking a SOC Security Analyst L3 to join our Security Operations Center, defending our global customers against constant and evolving adversary activity. As the senior technical expert and escalation point for your team, you will handle active intrusions, lead complex investigations, and ensure attacks against our clients are handled with urgency, accuracy, and clear communication. You will mentor junior analysts, act as a trusted voice for clients, and contribute directly to technology strategy and process improvement. This role reports into BlueVoyant SOC leadership and operates under BlueVoyant processes, tooling, and supervision at all times, including when working within client environments.

What You’ll Do:
  • Monitor and analyze security events and alerts from multiple sources, including SIEM logs, endpoint logs, and EDR telemetry.
  • Act as the technical escalation point for active intrusions and escalations from junior analysts.
  • Execute complex investigations, handle incident declaration, and perform live response analysis of compromised endpoints.
  • Research indicators and activities to determine reputation and suspicious attributes.
  • Perform analysis of malware, attacker network infrastructure, and forensic artifacts.
  • Hunt for suspicious activity based on anomalous behavior and curated threat intelligence.
  • Ensure events are properly identified, analyzed, and escalated to incidents.
  • Participate in the response, investigation, and resolution of security incidents, and engage BlueVoyant Incident Response teams for active intrusions.
  • Deliver clear incident investigation, handling, and response documentation that leaves clients with defined remediation actions.
  • Communicate regularly with clients to inform them of incidents and support remediation.
  • Identify and tune false-positive or benign detections.
  • Perform peer review and QA of junior analyst investigations, and mentor lower-level analysts.
  • Assist in the advancement of security policies, procedures, and automation.
  • Support the Customer Success team with client engagements when required.
  • Operate across BlueVoyant-managed systems and client-provided environments in accordance with client-approved access controls, logging, and BlueVoyant operating procedures, maintaining strict separation and adherence to security policies.
What You’ll Bring
  • Ability to handle high-pressure situations in a productive and professional manner.
  • Advanced written and verbal communication skills, with the ability to present complex technical topics in clear, easy-to-understand language.
  • Strong teamwork and interpersonal skills, including working effectively within a globally distributed team.
  • Ability to work directly with clients to understand requirements and gather feedback on security services.
  • Knowledge and experience with SIEM solutions, Cloud App Security tools, and EDR.
  • Experience with SIEM/EDR detection creation.
  • Expertise in endpoint, web, and authentication log analysis.
  • Advanced knowledge of network protocols, network telemetry, and commonly abused protocols.
  • Experience responding to modern authentication attacks against Active Directory, Entra ID, OAuth, and SSO.
  • Expert knowledge of common attack paths, including LOLBin use, common adversary tools, business email compromise (BEC), and AiTM attacks, including identification and response.
  • Strong knowledge of:
    • SIEM workflows (preferably Microsoft Sentinel and Splunk)
    • Malware detection, including dynamic and light static analysis, and Windows PE and maldoc analysis
    • Network monitoring metadata (web logs, firewall logs, WAF/IDS)
    • Email security and common BEC attacks
    • Windows and Unix forensic artifacts (e.g. registry analysis, wtmp/btmp)
    • Remote access solutions (both legitimate and inherently malicious)
    • Lateral movement methodologies and tools for Windows and Unix-based operating systems
    • Microsoft 365 attack paths and common attacker methodologies
    • Credential harvesting tools and methodologies
Nice to Have:
  • Background in intrusion analysis, incident response, digital forensics, penetration testing, or related areas.
  • 5+ years of hands-on SOC/TOC/NOC experience.
  • Experience countering ransomware threat actors and operations.
  • Familiarity with Microsoft Sentinel, Splunk, Microsoft Defender suite, CrowdStrike Falcon, and SentinelOne.
  • Familiarity with GPO, LANDesk, or other IT infrastructure tools.
  • Understanding of one or more programming languages such as Python, JavaScript, Lua, Ruby, GoLang, or Rust.
  • Relevant certifications such as: GIAC certification(s) (strongly preferred), CISSP, Security+, Network+, CEH, RHCA, RHCE, MCSA, MCP, MCSE
Education:
  • Bachelor’s degree in Information Security, Computer Science, or another IT-related field, or equivalent professional experience.
Why BlueVoyant?
  • Serve as the senior technical authority in a global SOC, leading investigations into real-world intrusions and making the calls that stop adversaries in their tracks.
  • Shape the growth of the team through mentoring and peer review while influencing detection, process, and technology strategy across a diverse client base.
  • Join a global, mission-driven cybersecurity company defending organizations worldwide with cutting-edge data, technology, and expertise.
  • Competitive compensation and a comprehensive benefits package, with support for wellbeing, development, and career growth.
About BlueVoyant

BlueVoyant is an AI-driven cybersecurity company dedicated to standing between our customers and cyber threats. By combining human, artificial, and proprietary intelligence, we deliver a unified solution that protects every organization’s network, identities, vendors, and digital footprints as a single attack surface. The company’s award-winning Microsoft Security expertise helps organizations maximize their security investments while reducing risk and ensuring compliance.

Led by CEO, John Hernandez, BlueVoyant’s highly skilled team includes former government cyber officials with extensive frontline experience in responding to advanced cyber threats on behalf of the National Security Agency, Federal Bureau of Investigation, Unit 8200, and GCHQ, together with private sector experts. BlueVoyant services utilize large real-time datasets with industry leading analytics and technologies.

Founded in 2017 by Fortune 500 executives, including Chairman of the Board, Jim Rosenthal, Vice Chairman, Tom Glocer, and former Government cyber officials, BlueVoyant is headquartered in New York City and has offices in Maryland, Tel Aviv, London, Budapest, and Latin America and is committed to building a workplace where talented people are empowered to do their best work in the fight against global cyber threats.

All employees must be legally authorized to work in the Philippines. BlueVoyant provides equal employment opportunities to all employees and applicants for employment without regard to age, sex, gender, sexual orientation, religion, ethnicity, disability, or any other characteristic protected under Philippine law, and complies with all applicable national and local laws governing non-discrimination in employment, including the Labor Code of the Philippines and Republic Act No. 10911 (Anti-Age Discrimination in Employment Act). Personal data submitted as part of your application will be processed in accordance with the Data Privacy Act of 2012 (Republic Act No. 10173) and our Candidate Privacy Notice.

Disclaimer: Pursuant to contractual requirements and applicable law, Philippine citizenship is required for this position in order to perform work on certain client engagements. Accordingly, an employee’s ability to perform this role is contingent upon the company’s verification of the employee’s citizenship status

Important Information for Applicants: BlueVoyant uses AI-assisted tools within our applicant tracking system to help identify candidates whose experience and skills best match the requirements of a role. This technology provides hiring teams with added insights to support fair and efficient hiring decisions. All applications are reviewed by a member of our hiring team, and final hiring decisions are made by humans, not AI. By submitting your application, you acknowledge that AI tools may assist in the evaluation of your resume as part of the recruitment process.

Interview Expectations: As part of our interview process, we assess your experience through real-time discussion, so we expect responses to be your own. While we embrace the use of AI within our business and recruitment process, we do not permit its use during interviews. Any suspected use of AI during an interview will be challenged, and this may include the use of detection tools.

BlueVoyant Candidate Privacy Notice: To understand how we secure and manage your personal data upon submitting a job application, please see our Candidate Privacy Notice, which can be found here - Candidate Privacy Notice

Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

SOC Security Analyst L2
SOC Security Analyst L2

BlueVoyant • Manila

Híbrido
PHP 670.000 - 1.004.000
SOC Analyst
SOC Analyst

Continent 8 Technologies • Makati

Presencial
PHP 900.000 - 1.300.000
SOC Analyst
SOC Analyst

Continent 8 Technologies • Manila, Hinoba-an

Presencial
PHP 600.000 - 850.000
Senior SOC Security Analyst L3 (Remote, Philippines)
Senior SOC Security Analyst L3 (Remote, Philippines)

BlueVoyant • Filipinas

A distancia
PHP 600.000 - 900.000
Security Operations Center Analyst (Las Pinas)
Security Operations Center Analyst (Las Pinas)

TaskUs • Las Piñas

Presencial
PHP 360.000 - 720.000
Benefits package
Professional development
Internal mobility
Cybersecurity Proposal and Solution Analyst
Cybersecurity Proposal and Solution Analyst

LevelBlue • Filipinas

Híbrido
PHP 600.000 - 900.000
Cybersecurity Proposal and Solution Analyst
Cybersecurity Proposal and Solution Analyst

Trustwave • Filipinas

Presencial
PHP 600.000 - 850.000
Security Analyst
Security Analyst

Zohorecruit • Cebu City

Presencial
PHP 480.000 - 780.000
Security Engineer (SIEM & SOAR) – Associate Manager
Security Engineer (SIEM & SOAR) – Associate Manager

Gratitude Philippines • Cebu City

Presencial
PHP 1.200.000 - 2.000.000
Hybrid work arrangement
Cybersecurity Operations Lead
Cybersecurity Operations Lead

PLDT Global, Inc. • Makati

Presencial
PHP 1.200.000 - 2.000.000