Hiring.Camp

SOC Analyst

Penbrothers

·

Yesterday

Location
Mandaluyong City, Metro Manila
Type
Full-time
Education
Bachelor
Source
RecruiterFlow

Description

 About Penbrothers 

Penbrothers is an HR & remote talent management partner and one of the fastest-growing companies in the Philippines. We provide talented Filipinos with global opportunities in high-growth startups and dynamic companies, from the comfort of their own homes.

About The Role

As SOC Analyst, Consultant you will create and maintain the safest operating environment for the client, employees and clients. You will defend network boundaries, keep computer systems and network devices hardened against attacks and provide security services to protect sensitive data (e.g., passwords and customer information). You will monitor our systems for attacks and intrusions and work to proactively identify flaws and
vulnerabilities.

What You Will Do

 

  • Lead Advanced Security Investigations: Conduct in-depth investigations of escalated security incidents using CrowdStrike Falcon and other relevant log sources to determine how an attack occurred, identify the initial access point, trace subsequent malicious activity, and establish the full scope of compromise across affected endpoints, systems, and user accounts.

  • Perform Advanced EDR Analysis: Investigate and analyze security detections beyond initial alert validation, leveraging endpoint telemetry, process execution data, and related indicators to reconstruct attacker activity, assess threats, and determine the nature and severity of incidents.

  • Execute Threat Hunting and Detection Analysis: Perform targeted threat hunting, analyze indicators of compromise (IoCs), and assess adversary tactics, techniques, and procedures (TTPs) to identify malicious activity, validate threats, and support improvements to detection and prevention capabilities.

  • Own Incidents Through Remediation Recommendations: Take ownership of escalated incidents from initial investigation through containment and remediation planning. Develop evidence-based assessments, determine root causes where possible, and provide clear, actionable recommendations to customers to support effective incident resolution.

  • Make Independent Containment Decisions: Assess incident severity, available evidence, potential business impact, and customer authorization boundaries to determine appropriate containment and response actions. Independently execute authorized actions, including endpoint isolation, blocking malicious indicators, and disabling compromised accounts when warranted.

  • Provide Actionable Remediation Guidance: Recommend appropriate eradication and recovery measures, including patching, system rebuilding, configuration changes, and other corrective actions for implementation by the customer or designated internal teams. Clearly communicate the urgency, rationale, and potential impact of recommended actions.

  • Manage Security Escalations: Independently assess, prioritize, and route incidents requiring customer review, urgent incident escalation, or assistance from management and specialized internal teams. Recognize active hands-on-keyboard activity and other high-risk scenarios that require immediate escalation, ensuring timely communication and appropriate ownership.

  • Communicate Findings to Customers and Stakeholders: Translate technical investigation findings into clear incident summaries, explain the attack path and scope of compromise, communicate containment decisions, and present prioritized recommendations to customers and relevant stakeholders.

  • Maintain Incident Documentation: Document investigation findings, supporting evidence, affected assets and accounts, containment actions, escalation decisions, incident timelines, and remediation recommendations in accordance with established operational procedures and customer requirements.

  • Leverage Security Tools and Threat Intelligence: Maintain strong working knowledge of EDR/XDR, SIEM, and relevant security monitoring platforms, using available telemetry and threat intelligence to support investigations, validate malicious activity, and improve incident handling effectiveness.

  • Improve MDR Operations and Detection Capabilities: Contribute to the continuous improvement of investigation playbooks, standard operating procedures, response workflows, and detection logic. Identify opportunities to improve alert quality, investigation efficiency, escalation practices, and the overall effectiveness of the MDR service.

  • Collaborate Across Security and Technical Teams: Work closely with customers, SOC colleagues, security engineering, IT, and other technical teams to coordinate incident handling, validate findings, facilitate remediation, and resolve complex security issues.

  • Participate in Rotational and After-Hours Coverage: Support after-hours and on-call incident escalation and response requirements, ensuring timely investigation, sound response decisions, and effective incident coordination.

 

Qualifications: 

  • Bachelor degree in information technology, Computer Science, Cybersecurity, or a related discipline, or equivalent professional experience.

  • Expertise in investigating and mitigating security incidents across diverse environments, including on-premises, cloud, and hybrid infrastructures.

  • An experienced (Level 2 or 3) Analyst, looking to develop and grow a SOC service and team.

  • Strong understanding of threat intelligence integration, adversary TTPs, and the MITRE ATT&CK  framework.

  • Desired Certifications: CompTIA Security+ and Cybersecurity Analyst (CySA+), ISC2 CC and SSCP, EC-Council Certified Incident Handler (ECIH), GIAC Certified Incident Handler (GCIH), and SIEM/EDR certifications (e.g., Splunk, Chronicle, CrowdStrike, SentinelOne) are a plus.

  • Advanced English (C1).

  • 3–5 years of hands-on experience in SOC operations, preferably for a SOC or MDR service provider (e.g.,MSSP).

  • Proficiency with SOC technologies, including SIEM (e.g., Chronicle, Splunk, IBM QRadar), EDR/XDR (e.g.,Trellix, CrowdStrike, SentinelOne, BlackPoint), and SOAR platforms (e.g., Chronicle, FortiSOAR, Splunk SOAR).

  • Experience responding to alerts related to Microsoft Office 365, Identities (Entra ID, Active Directory),Cloud (AWS, Azure), Firewalls, Endpoint security, Email security, Web security (IP, DNS Filtering).

 

 

 

 

Our Hiring Process & AI Disclaimer: We use AI tools to streamline our application process—including an initial conversation with an AI Interviewer. All hiring decisions are made entirely by humans: our Talent Acquisition team guides your full candidate journey and makes all evaluation decisions.

You are welcome to use AI for CV refinement and research, but real-time AI assistance during interviews or skill assessments is strictly prohibited to ensure an authentic evaluation. 

Read our full AI Disclaimer to learn more

 

What You’ll Get

At Penbrothers, we are obsessed with creating positive employee experiences. Here you’ll find an environment that nurtures learning and provides opportunities for growth. You’ll have the opportunity to make an impact on fast-growing startups and dynamic companies. 

·   Meaningful work & Growth: We take every opportunity to stretch ourselves and deliver an excellent client experience. 

·   Employee as our biggest asset: We are genuinely invested in our people’s career and welfare.

·   Global reach & local impact: Get to work with high-growth startups and dynamic companies from the comfort of your own home. 

·   Powering global startups: We’ve created 1,400 Filipino jobs that empower global start-ups to focus on growth.

Skills

AWSAzureCybersecuritySIEMSOCSplunkCompTIA

Similar Jobs

30

SOC Analyst

Derex Technologies·Washington, DC·Onsite

1d ago

SOC Analyst

ASRC Federal·Alexandria, VA

2d ago

SOC Analyst

Peraton·US·Remote

3d ago

SOC Analyst

Koniag Government Services·Baltimore, MD

4d ago

SOC Analyst

Taskus·PHL - Las Pinas City - Hiraya, Philippines

1w ago

SOC Analyst

Leidos·2113 The Mark Ctr Alexandria VA, US

1w ago

SOC Analyst

S-RM·Cape Town +1·Remote, Hybrid, Onsite

1w ago

SOC Analyst

Waystone·Mumbai, Maharashtra

1w ago

SOC Analyst

Motorway·London·Onsite

2w ago

SOC Analyst

Leidos·7169 Moore St Canberra ACT Australia

2w ago

SOC Analyst

Rushstreetinteractive·Bogotá

3w ago

SOC Analyst

Rushstreetinteractive·Canada

3w ago

SOC Analyst

Mark Anthony Group Inc.·Vancouver, BC

4w ago

SOC Analyst

DXC Technology·PZZ04 - DXC Manila IPC McKinley Hill, Philippines

1mo ago

SOC Analyst

Continent8·Makati, Manila

1mo ago

SOC Analyst

Pwc·Praha - Hvezdova 1734, 2c

1mo ago

SOC Analyst

MoonPay·Bengaluru, Karnataka·Onsite

1mo ago

SOC Analyst

DXC Technology·PZZ04 - DXC Manila IPC McKinley Hill, Philippines

1mo ago

SOC Analyst

Pinkerton·MX

1mo ago

SOC Analyst

Hatchit·Washington, DC·Onsite

1mo ago

SOC Analyst

Allegromicro·Paranaque City, National Capital Region

2mo ago

SOC Analyst

Thales·Contern_EXC, Luxembourg·Remote

2mo ago

SOC Analyst

Orange·Kuala Lumpur, MY·Hybrid

2mo ago

SOC Analyst

Skillfield·Melbourne, Victoria

2mo ago

SOC Analyst

Idme·McLean, Virginia·Remote, Onsite

2mo ago

SOC Analyst

Dminc·Crownsville, MD

2mo ago

SOC Analyst

Fortinet·Burnaby, BC·Hybrid

3mo ago

SOC Analyst

Welvaart·Lisbon

3mo ago

SOC Analyst

Wix.com·Kyiv, Ukraine·Hybrid

3mo ago

SOC Analyst

Ericsson·Plano, TX

4mo ago