
SOC Analyst
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Philippines.
• Oversee security alerts generated by SIEM, EDR, and cloud services.
• Conduct initial assessments and categorize alerts as legitimate or false positives.
• Examine suspicious behaviors across endpoints, identities, and cloud settings.
• Forward verified incidents to Tier 2 / Incident Response teams with appropriate context.
• Review logs from CloudTrail, Azure Activity Logs, OS logs, and other pertinent security data sources.
• Clearly document findings in tickets and investigation reports.
• Adhere to existing playbooks and participate in enhancing detection logic over time.
• Engage with internal teams and clients concerning alerts, discoveries, and escalations.
• At least 1 year of experience in SOC / Security Operations.
• Practical experience with EDR tools like CrowdStrike, SentinelOne, or Microsoft Defender for Endpoint.
• Familiarity with SIEM solutions such as Splunk, Microsoft Sentinel, QRadar, or similar platforms.
• Basic understanding of networking fundamentals, including IP, DNS, HTTP/S, ports, and related concepts.
• Basic knowledge of Linux and Windows operating systems.
• Capability to analyze logs and detect suspicious activities.
• Proficiency in English, both written and spoken — a must.
• Strong verbal communication skills, particularly in client-facing scenarios.
• Experience with cloud platforms such as AWS, Azure, or GCP.
• Knowledge of GCP / Google Cloud Platform — a notable advantage.
• Ability to investigate cloud activities, including IAM, API calls, and resource modifications.
• Understanding of identity-based threats, such as token abuse and privilege escalation.
• Experience with scripting in Python or Bash.
• Full-time employment.
• Remote work option available.
Sicredi
Sicredi
NBCUniversal
DecisionPoint Corporation
Get handpicked remote jobs straight to your inbox weekly.