2 дня назад
SOC Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
SOC Analyst (Splunk): Performing advanced SOC monitoring, threat hunting, and incident investigations across customer environments with an accent on Splunk Enterprise Security, SPL, and NIST-aligned incident response. Focus on tuning detections, coordinating containment and recovery, preparing evidence-based reports, and mentoring junior analysts.
Location: Taguig City, Philippines; in-person collaboration is prioritized
Company
is a Fortune 500 global IT services company delivering mission-critical technology services across more than 70 countries.
What you will do
- Monitor, triage, and investigate complex security alerts and incidents across customer environments.
- Use Splunk Enterprise Security and SPL for investigations, threat hunting, detection validation, correlation searches, and detection tuning.
- Execute incident response activities, including escalation, containment coordination, recovery validation, root cause analysis, and post-incident reviews.
- Communicate security findings, risks, recommendations, and incident status to technical teams, customers, and business stakeholders.
- Prepare incident reports, executive summaries, case documentation, and improvement recommendations.
- Identify detection gaps, false positives, alert noise, and recurring patterns; contribute to SOC playbooks and mentor junior analysts.
Requirements
- 5+ years of experience in cybersecurity or SOC operations with Tier 2.5 or Tier 3-level capabilities.
- Strong hands-on experience with Splunk Enterprise Security and SPL, including building, modifying, interpreting, and troubleshooting queries.
- Hands-on experience with cybersecurity incident response and investigations using endpoint, network, identity, cloud, email, application, and SIEM telemetry.
- Knowledge of NIST-aligned incident response practices.
- Strong written and verbal communication skills, including customer-facing communication.
- Experience preparing technical incident reports, RCA/PIR documentation, and executive summaries.
Nice to have
- Experience with MITRE ATT&CK, threat intelligence, IOC/TTP analysis, threat hunting, SIEM rule tuning, and SOC playbooks.
- Knowledge of Splunk notable events, correlation searches, dashboards, risk-based alerting, security domains, data models, lookups, macros, field extraction, and CIM.
- Experience identifying detection gaps, alert noise, normalization issues, and data-quality problems.
- Experience mentoring junior SOC analysts and improving SOC processes.
- Splunk, GCIH, GCED, GCFA, CySA+, CISSP, SC-200, or SC-100 certification.
Culture & Benefits
- Flexible working arrangements with an emphasis on in-person collaboration.
- Health insurance for employees and dependents upon hiring, plus life insurance from the first day.
- 15–20 vacation days and 15 sick-leave days.
- Company-sponsored training, upskilling, and certification opportunities.
- Retirement program, employee assistance program, performance recognition, and supplemental standby or shift pay.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
19 часов назад
SOC Analyst (Cybersecurity)
1 день назад
Junior Information Security Analyst (For Internship Program) (Cybersecurity)
3 дня назад
IT Security Operations Specialist (Cybersecurity)
1 день назад
Penetration Testing Analyst (Cybersecurity)
5 дней назад
Global Head of Security Detection and Response (Cybersecurity)
23 часа назад