
Security Operations Analyst
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Philippines.
• Oversee alerts in real time across EDR, firewall, IPS, WAF, and SIEM platforms.
• Assess alerts, prioritize their severity, and identify true positives under time constraints.
• Ensure ongoing 24/7 threat monitoring through rotating shifts, including nights, weekends, and holidays.
• Perform in-depth investigations of incidents across EDR, network, and cloud log sources.
• Identify the root cause, scope, and indicators of compromise for incidents.
• Offer analysis of incidents and recommendations for containment to client teams responsible for response execution.
• Adjust SIEM correlation rules and detection logic to minimize false positives and address security coverage gaps.
• Record investigation outcomes and timelines in case management systems.
• Revise SOC playbooks and standard operating procedures.
• Collaborate with GRC engineers and vCISOs to ensure threat detection aligns with client compliance requirements.
• Facilitate investigation handoffs during shift changes.
• Mentor junior analysts on investigative methodologies.
• Work directly with client stakeholders to ensure continuous detection coverage.
• A minimum of 3 years of practical experience in monitoring, triaging, and investigating security alerts within a fast-paced SOC environment.
• Expertise in correlating data across EDR, firewall, IPS, WAF, and SIEM tools to identify root causes under pressure.
• Capability to manage complex investigations from start to finish and make informed escalation decisions with little oversight.
• Proficient in documenting findings and communicating complex technical incidents in layman's terms to client stakeholders.
• Availability and readiness to work a rotating 24/7 shift schedule, including nights, weekends, and holidays.
• Possession of recognized industry security certifications such as CompTIA Security+, CySA+, GCIH, or similar credentials.
• Hands-on experience with EDR tools like CrowdStrike, SentinelOne, and Defender.
• Experience with SIEM solutions such as Splunk, Microsoft Sentinel, Sumo Logic, and Wazuh.
• Background in configuring, maintaining, and tuning security platforms beyond routine alert triage.
• Proficiency in writing Python or PowerShell scripts and creating SOAR playbooks.
• Previous experience in managed security service provider settings, supporting multiple client organizations simultaneously.
• Understanding of SOC 2, ISO 27001, and HIPAA standards as they relate to threat detection and incident response operations.
• Exceptional written and verbal communication skills in English.
• A reliable, high-speed internet connection and a professional home office environment suitable for confidential discussions and uninterrupted shift work.
• Willingness and ability to travel locally for occasional onsite meetings, team events, or business activities.
• Required to participate in live video interviews with the camera on and verify identity during recruitment and onboarding processes.
• Employment is contingent upon successful identity verification and background checks, where permitted by law.
• Opportunities for career development through mentorship and training programs.
• Reimbursement for approved training and certification courses relevant to the current position.
• Competitive base salary with regular performance evaluations tied to merit-based assessments.
• Potential for bonuses.
• Ample opportunities for career progression.
• Remote-first policy allowing work from any location while collaborating with a global team within the assigned shift.
Talan
Pragmatike
Supply Chimp
Pragmatike
Get handpicked remote jobs straight to your inbox weekly.