Назад
Company hidden
14 часов назад

Senior SOC Analyst for Black Team (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Philippines
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior SOC Analyst for Black Team (Cybersecurity): Monitoring and investigating security alerts for a 24x7 SOC operation with an accent on SIEM telemetry, incident triage, and cybersecurity threat analysis. Focus on analyzing logs across endpoints, networks, identity systems, cloud environments, and security devices while applying MITRE ATT&CK and forensic investigation techniques.

Location: Bonifacio Global City, Taguig City, Philippines; ability to commute or relocate as required.

Company

hirify.global provides an AI-powered cyber resilience platform that helps businesses manage, secure, and recover their environments.

What you will do

  • Monitor and triage alerts using Adlumin SIEM and other SOC tools.
  • Read and analyze network, IAM, endpoint, cloud, DNS, VPN, email, and EDR telemetry to identify suspicious behavior.
  • Conduct initial investigations, assess impact, and escalate validated incidents to Tier 2 according to SOPs and playbooks.
  • Analyze security-device logs for trends, anomalies, and potential threats.
  • Document investigation findings and maintain detailed case notes for reporting and knowledge sharing.
  • Collaborate with the team to support a 24x7 SOC and improve threat detection.

Requirements

  • 5+ years of experience as a Security Operations Analyst in a SOC environment.
  • Strong cybersecurity fundamentals covering threat vectors, risk management, and incident response.
  • Experience analyzing SIEM telemetry from Windows and Linux systems, network infrastructure, email, EDR, cloud environments, DNS, and VPNs.
  • Knowledge of living-off-the-land techniques, command encoding and decoding, and the MITRE ATT&CK framework.
  • Cybersecurity-related degree or equivalent certification, such as GCIH, GCFA, CompTIA Security+, or DoD 8570/8140 IAM/IAT Level 2.
  • Familiarity with KAPE, FTK, Velociraptor, Wireshark, NetworkMiner, Volatility3, MemProcFS, Ghidra, REMnux, and Any.Run.

Culture & Benefits

  • Medical and dental insurance.
  • Generous paid time off and observed holidays.
  • Two paid volunteer days per year.
  • Employee Stock Purchase Program and company-contributed pension.
  • Monthly onsite pantry, internet, and de minimis allowances.
  • Learning opportunities through N-ablite Learning and company giving initiatives.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →