Sr. SecOps Platform Engineer | SIEM & SOAR

NCS Philippines

Taguig

Hybrid

PHP 600,000 - 1,200,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

NCS Philippines is seeking a Senior SOC Platform Engineer to design, implement, and optimize SIEM, SOAR, and log management platforms in a security operations environment. The role emphasizes platform development and integration over routine SOC analyst tasks.

You will onboard diverse log sources, configure ingestion and enrichment, and translate security requirements into effective detections and automated responses.

Qualifications

  • Bachelor’s degree in CS/IT/Cybersecurity or related field.
  • 5+ years in SecOps/SOC platform engineering.
  • Hands-on with SIEM and/or SOAR platforms.

Responsibilities

  • Engineer, integrate, optimize and maintain SOC platforms (SIEM, SOAR, log management).
  • Onboard and integrate log sources into the SOC platform and ensure data quality.
  • Develop and tune detection rules and monitoring use cases.
  • Configure and optimise SOAR playbooks and automation workflows.
  • Perform platform maintenance, patching, upgrades and configuration changes.
  • Provide technical support and root-cause analysis for issues; monitor platform health.
  • Collaborate with customers and SOC teams to capture monitoring requirements and document configurations.

Skills

Analytical skills
Troubleshooting
Security platform engineering
Documentation
Stakeholder management

Education

Bachelor's degree in Computer Science / IT / Cybersecurity

Tools

SIEM
SOAR
Log management

Job description

GENERAL RESPONSIBILITIES:

The role is responsible for the engineering, integration, optimisation, and maintenance of SOC platforms, particularly SIEM, SOAR, and log management technologies. The role focuses on building and improving the security platform rather than performing day-to-day SOC analyst activities.

DUTIES AND RESPONSIBILITIES:
  1. SOC Platform Engineering
    • Configure, maintain, and fine-tune SIEM, SOAR, and other SOC platforms.
    • Optimise platform performance, reliability, and detection capabilities.
    • Troubleshoot platform and integration issues.
  2. Log Source Integration
    • Onboard and integrate security and technology log sources into the SOC platform.
    • Configure ingestion, parsing, normalisation, and enrichment.
    • Validate data quality and troubleshoot ingestion issues.
  3. Detection Engineering
    • Develop, configure, and fine-tune detection rules and correlation use cases.
    • Translate customer security requirements into actionable detections.
    • Take onboarded log sources through to customer-specific detection capabilities.
  4. SOAR and Automation
    • Configure and optimise SOAR playbooks, workflows, and integrations.
    • Support security automation and automated enrichment/response capabilities.
  5. Platform Maintenance and Uplift
    • Perform platform patching, upgrades, configuration changes, and maintenance.
    • Support continuous improvement and uplift of SOC platform capabilities.
  6. Operations and Troubleshooting
    • Provide technical support for platform, ingestion, integration, and detection issues.
    • Conduct root-cause analysis and implement corrective actions.
    • Monitor platform health and performance.
  7. Customer and Stakeholder Support
    • Work with customers and SOC teams to understand monitoring and detection requirements.
    • Provide technical guidance on log onboarding, integrations, detections, and automation.
    • Maintain technical documentation and support knowledge transfer.
LEADERSHIP COMPETENCIES:

N/A

FUNCTIONAL/TECHNICAL COMPETENCIES:

Information Security, Release and Deployment, Configuration Management, Incident Management, Systems Installation and Removal, Methods and Tools,

CORE COMPETENCIES:

Teamwork & Collaboration, Accountability, Customer Focus, Communication, Innovation, Quality

JOB SPECIFICATIONS:
  • Education- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Security, Engineering, or related discipline. Relevant cybersecurity or vendor certifications are an advantage.
  • Related Work Experience - Minimum 5 years of relevant experience in SecOps/SOC platform engineering.
    • Hands-on experience with SIEM and/or SOAR platforms.
    • Experience onboarding and integrating multiple log sources.
    • Experience developing and fine-tuning security detections and monitoring use cases.
    • Experience with SOC platform maintenance, patching, upgrades, and troubleshooting.
    • Experience in an enterprise SOC, MSSP, managed security services, or cybersecurity operations environment.
  • Knowledge
    • Security Operations (SOC) platforms, technologies, and operating concepts
    • SIEM, SOAR, and security log management technologies
    • Security event collection, log source onboarding, ingestion, and data pipelines
    • Log parsing, normalization, enrichment, and data quality concepts
    • Detection engineering, correlation rules, and security monitoring use cases
    • Security automation, orchestration, and SOAR playbook concepts
    • Security platform integrations, including APIs, Syslog, and related integration methods
    • SOC platform administration, configuration, performance monitoring, and troubleshooting
    • Platform lifecycle management, including patching, upgrades, and configuration changes
Skills
  • Strong analytical, problem-solving, and technical troubleshooting skills
  • Ability to engineer, configure, integrate, and optimize security platforms
  • Ability to develop, tune, and improve security detections and related use cases
  • Ability to translate customer and operational requirements into practical technical solutions
  • Strong technical documentation and communication skills
  • Ability to collaborate effectively with SOC analysts, security engineers, technical teams, and customers
  • Strong technical ownership, accountability, and attention to quality
  • Continuous improvement mindset with the ability to identify and implement platform enhancements
  • Effective stakeholder management and customer orientation
  • Ability to share technical knowledge and provide guidance to relevant teams
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Operations Center (SOC) - Head
Security Operations Center (SOC) - Head

SMITS, Inc. - IT Company of San Miguel Corporation • Mandaluyong

On-site
PHP 900,000 - 1,600,000
Security Engineer
Security Engineer

JetSon Manpower Agency • Manila

On-site
PHP 669,600 - 892,800
Cyber Security Engineer (SIEM/SOAR)
Cyber Security Engineer (SIEM/SOAR)

Create Synergies Inc. • Mandaluyong

On-site
PHP 1,200,000 - 1,800,000
Security Engineer (SIEM & SOAR)
Security Engineer (SIEM & SOAR)

Metacom Careers • Quezon City

On-site
PHP 600,000 - 900,000
Security Operations and Incident Manager
Security Operations and Incident Manager

Private Advertiser • Mandaluyong

On-site
PHP 3,000,000 - 5,000,000
Security Operations Analyst II
Security Operations Analyst II

Vertiv Co • Mandaluyong

On-site
PHP 480,000 - 720,000
Security Analyst / Network Security Analyst
Security Analyst / Network Security Analyst

RippedBoxStation • Philippines

On-site
PHP 260,000 - 420,000
Lead Security Engineer
Lead Security Engineer

Vaco by Highspring • Philippines

On-site
PHP 800,000 - 1,200,000
SOC - 3rd shift
SOC - 3rd shift

Ayannah • Pasig

On-site
PHP 900,000 - 1,300,000
Senior SIEM Engineer for Cybersecurity Detection
Senior SIEM Engineer for Cybersecurity Detection

Boehringer Ingelheim Business Services Philippines, Inc. • Muntinlupa

On-site
PHP 1,000,000 - 1,500,000