
Cyber Security Analyst
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in Philippines.
• Conduct investigations into security alerts escalated by SOC Level 1 analysts.
• Execute in-depth analyses of suspicious activities across SIEM, EDR, network, identity, cloud, and email security platforms.
• Assess whether security events are false positives, exhibit suspicious behavior, breach policies, or are confirmed cybersecurity incidents.
• Correlate events from various log sources to uncover attack patterns, affected assets, compromised accounts, lateral movements, malware activities, or unauthorized access.
• Evaluate the scope, severity, business impact, and urgency of security incidents.
• Suggest containment, eradication, and remediation strategies to relevant technical teams.
• Develop and uphold comprehensive incident timelines, investigation notes, evidence documentation, and escalation summaries.
• Assist in phishing investigations, endpoint compromise evaluations, suspicious login assessments, malware alerts, brute-force attack analyses, data exfiltration indicators, and cloud security incidents.
• Review and enhance SOC playbooks, investigation methodologies, and escalation criteria.
• Offer technical direction, coaching, and feedback to SOC Level 1 analysts.
• Identify recurring false positives and suggest tuning enhancements for SIEM, EDR, and other detection systems.
• Engage in post-incident evaluations and provide recommendations for improving detection, response, and prevention strategies.
• Facilitate shift transitions by documenting ongoing incidents, outstanding actions, and key operational contexts.
• 2 to 4 years of experience in SOC operations, cybersecurity monitoring, incident response, security operations, network security, endpoint security, or infrastructure security.
• Prior experience as a SOC Analyst L1 or in a similar role.
• Experience in investigating actual security alerts and recording incident findings.
• Practical knowledge of SIEM, EDR, identity logs, firewall logs, email security alerts, and endpoint events.
• Experience in escalating incidents and recommending remediation measures.
• Preferred Certifications: CompTIA CySA+, Blue Team Level 1 / BTL1, Blue Team Level 2 / BTL2, Microsoft AZ-500, CompTIA Security+, CompTIA Network+, Cisco CCNA, Fortinet FCP / NSE, Microsoft AZ-500, and eCIR as advantageous for cloud/security environments.
• Language proficiency: English C1 is mandatory.
• Competitive salary and performance-based bonuses.
• Opportunities for professional development and certification reimbursements.
• Flexible work schedule and remote work options.
• Comprehensive health benefits and wellness programs.
Finance of America
True Zero Technologies, LLC
Metro Vein Centers
Get handpicked remote jobs straight to your inbox weekly.