Security Operations Analyst II
Mandaluyong - Philippines
Job Summary
Job (Assignment) Title: SOC Analyst II
Function/Department: Security / Information Technology
Reports To: Manager Security Operations and Engineering
POSITION SUMMARY
- The SOC Analyst II is responsible for overseeing cybersecurity by monitoring detecting investigating and responding to security incidents within an organization. And act as an escalation from Tier 1 analyst. This role focuses on incident analysis threat validation containment actions and root cause identification while supporting continuous improvement of SOC detections playbooks and threat intelligence integration.
The Level II analyst acts as a technical escalation point mentoring junior analysts and collaborating closely with Incident Response Threat Intelligence and Security Engineering teams
RESPONSIBILITIES
- Monitor security events and alerts from SIEM (Security Information and Event Management) systems/ SOAR 7AI Dashboard and other security tools.
- Perform deep-dive analysis of security alerts escalated by Tier 1 to determine legitimacy scope and impact
- Conduct log correlation and forensic analysis across SIEM EDR network cloud and identity platforms
- Analyze and investigate security incidents to determine their impact and root cause.
- Respond to security incidents coordinate with stakeholders and escalate as necessary.
- Conduct risk analysis to identify security gaps.
- Develop and implement incident response procedures and playbooks.
- Collaborate with IT and security teams to improve security configurations and defenses.
- Document security incidents findings and recommendations for future mitigation.
- Stay updated on the latest cybersecurity threats trends and best practices.
- Identify Indicators of Compromise (IOCs) and attack patterns using threat intelligence and MITRE ATT&CK
- Execute containment and remediation actions (e.g. isolate hosts block indicators disable accounts)
- Work with our Security Engineering group for any security application and tools within SOC for enhancement or fine tuning.
- Assist in threat hunting and proactive security monitoring.
- Participate in security awareness training and initiatives.
QUALIFICATIONS
- Candidate must be a degree holder in Computer Science Computer Engineering Information Technology or equivalent qualifications
- 3-5 years of experience in cybersecurity SOC operations or a similar role.
- Security certifications such as CompTIA Security CEH GSEC or equivalent.
- Familiarity with SIEM tools IDS/IPS firewalls and endpoint protection solutions.
- Knowledge of cybersecurity frameworks such as NIST MITRE ATT&CK or ISO 27001.
- Understanding of networking protocols operating systems and security best practices.
- Strong analytical and problem-solving skills.
- Strong understanding of incident response lifecycle (NIST / SANS)
- Hands-on experience with log analysis endpoint telemetry and network traffic analysis
- Ability to analyze malware behavior lateral movement persistence and privilege escalation
- Excellent communication and documentation abilities.
- Experience with scripting languages (Python PowerShell etc.) for automation.
- Knowledge of cloud security (AWS Azure Google Cloud).
- Familiarity with forensic analysis and malware investigation techniques.
- Rotational shifts may be required to support 24/7 security monitoring.
- Ability to work in a fast-paced and high-pressure environment.
Required Experience:
IC
About Company
Work Authorization No calls or agencies please. Vertiv will only employ those who are legally authorized to work in the United States. This is not a position for which sponsorship will be provided. Individuals with temporary visas such as E, F-1, H-1, H-2, L, B, J, or TN or who need s ... View more