SOC Analyst enhancing cybersecurity operations for a global security team based in Manila, Philippines. Responsible for incident response, threat analysis, and process improvement.
Responsibilities
Incident response activities, security incident investigations, and working with asset owners, stakeholders, other teams, and relevant teams to develop remediation plans.
Investigating, documenting, and reporting on external information security threats and emerging trends.
Overseeing of vulnerability and risk analysis for customer IT systems, enterprise applications and cloud infrastructure.
Building automated alerting and remediation workflows for security issues.
Development of operating procedures for teams to integrate into their daily workflows to deliver secure enterprise applications and & infrastructure at scale.
Consulting on technical design & engineering processes for system architectures to ensure that security is a design consideration and not a feature.
Recommending information assurance and security solutions to support product development and customer requirements.
Driving the ongoing improvement of security processes and procedures.
Requirements
3.5 + years in a Security Operations role with comprehensive experience in investigations and incident response.
Experience working within a Security Operations Centre.
Knowledge in using and configuring the Elastic stack (Elastic Search, Logstash, Kibana) to drive SOC operations (or equivalent SOC tech stack)
One or more of the following certifications are highly desired: CompTIA Security+, PentTest+, EC-Council (CEH, ECIH, CHFI, CND), Cisco CyberOps, GIAC (GCED, GCIA, GCIH), ISC2 (CISSP, CSSP) or similar security certifications.
Detailed understanding of threats, vulnerabilities, exploits, defences, security principles and policies.
Knowledge of techniques attackers use to identify vulnerabilities, gain unauthorized access, escalate privileges and access restricted information.
Experience analyzing event and system logs, performing packet and forensic analysis in support of intrusion analysis or enterprise-level information security operations.
Knowledge of security practices and essential security technologies (AV, EDR, FIM, HIPS, NIPS, SIEM, WAF/DAM, DLP, IDS/IPS).
Knowledge of information security protection/detection and authentication systems (firewalls, IDS, IPS, anti-virus, AD, AAD, RADIUS etc.).
Knowledge of Unix, Linux and Windows administration, patch deployment and system configuration and security controls.
Knowledge of communication protocols (HTTP, DNS, TCP/UDP) as well as the various techniques utilized by malware within an operating system for persistence and data collection.
Practical experience with scripting languages (e.g., Python, Perl, Bash, PowerShell).
Understanding of database systems, application system development and installation/implementation processes.
Practical experience performing vulnerability scans, risk assessments and security assessments.
Practical experience in the use of Tenable vulnerability assessment tool is highly desirable.
Understanding of virtualization technologies (e.g. VMware) and cloud environments (e.g. Azure, AWS)
Vice President of Security Operations Center managing a global cyber defense strategy at Saviynt. Leading cybersecurity initiatives, incident response, and threat detection efforts.
Vice President of Security Operations Center at Fidelity ensuring security across global operations. Leading cyber incident response and collaborating with internal teams to enhance network security.
Security Operations Manager overseeing client relations and service delivery across multiple Columbus sites. Ensuring operations meet client expectations while managing staffing and scheduling responsibilities.
Security Operations Manager overseeing client relations and service delivery across Columbus sites for Ohio Support Services. Ensuring client security expectations and company standards are met or exceeded.
SOC Analyst responsible for monitoring global threats and preventing cyber attacks for SHE. Collaborating with elite teams and documenting activities in Ludwigshafen.
Information Security Senior Director leading cybersecurity operations strategies at Mass General Brigham. Managing teams, budget, and cross - functional collaborations for security and compliance.
Senior Security Engineer on FINRA's Security Operations team implementing and maintaining security solutions. Collaborate with teams to enhance security and mentor junior staff.
Security Operations Engineer supporting federal cybersecurity initiatives across enterprise and cloud environments. Hands - on security engineering, operational monitoring, and compliance support.
Security Operations Lead at Aily Labs designing AI - native security operations solutions. Collaborating with engineers to build innovative security capabilities at scale.