Senior Cybersecurity Analyst
Posted 2 days ago
Posted 2 days ago
This is a fully remote position, open to applicants in Philippines.
• Oversee daily security operations, which include monitoring, triaging, and investigating security alerts across production, corporate, and SaaS environments.
• Manage and enhance the SIEM continuously by onboarding log sources, parsing, normalizing data, developing and tuning detection rules, and optimizing cost and coverage.
• Oversee the MDR partnership, which encompasses escalation workflows, SLAs, feedback loops for detection, and ensuring quality of response.
• Lead security incidents from start to finish, including triage, scoping, containment, eradication, recovery, and conducting blameless post-incident reviews.
• Create SOAR playbooks, detection-as-code pipelines, enrichment integrations, and response scripts to minimize manual tasks and response times.
• Perform proactive threat hunting guided by threat intelligence and insights into Thumbtack’s environment.
• Define, monitor, and report on operational metrics such as MTTD, MTTR, alert fidelity, and ATT&CK coverage.
• Utilize AI tools to enhance security operations and adapt detections, processes, and tools to meet evolving threats.
• Collaborate with Security Engineering, Platform, IT, and Compliance teams to address detection gaps and bolster security posture.
• Assist with GRC, collection of audit evidence, control monitoring, endpoint security, network security, third-party risk assessments, and vulnerability management.
• A minimum of 6 years of experience in security operations, detection and response, or a related security engineering field.
• Extensive hands-on experience in operating and tuning a SIEM, including detection engineering and managing log pipelines.
• Experience in managing or closely collaborating with an MDR/MSSP partner, including escalation design and ensuring vendors meet quality standards and SLAs.
• Strong incident response capabilities in cloud-native environments (AWS and/or GCP), SaaS applications, endpoints, and identity systems.
• Proficiency with AI tools in daily security tasks and an ability to adapt to new and emerging threats, including AI-related risks.
• Scripting and automation skills (e.g., Python), with experience in creating SOAR playbooks, detection-as-code, or similar automation techniques.
• Analytical thinking and risk-based judgment to prioritize coverage, fidelity, and effort trade-offs.
• Familiarity with GRC and compliance frameworks such as SOC 2 and PCI DSS, as well as third-party risk assessments and vulnerability management.
• Outstanding written and verbal communication skills.
• Ability to work effectively with a distributed team, primarily based in the US.
• Must currently reside in the Philippines.
• Authorized to work in the Philippines.
• Willing to work a graveyard shift aligned with US Central Time hours, observing Philippine holidays.
• Competitive salary and performance-based incentives.
• Comprehensive health and wellness benefits.
• Opportunities for professional development and career advancement.
• Flexible work arrangements and supportive work culture.
Rimini Street
Rimini Street
Get handpicked remote jobs straight to your inbox weekly.