- Location
- Mandaluyong City, Metro Manila
- Type
- Full-time
- Education
- Bachelor
- Source
- RecruiterFlow
Description
Penbrothers is an HR & remote talent management partner and one of the fastest-growing companies in the Philippines. We provide talented Filipinos with global opportunities in high-growth startups and dynamic companies, from the comfort of their own homes.
About The Role
As SOC Analyst, Consultant you will create and maintain the safest operating environment for the client, employees and clients. You will defend network boundaries, keep computer systems and network devices hardened against attacks and provide security services to protect sensitive data (e.g., passwords and customer information). You will monitor our systems for attacks and intrusions and work to proactively identify flaws and
vulnerabilities.
What You Will Do
-
Lead Advanced Security Investigations: Conduct in-depth investigations of escalated security incidents using CrowdStrike Falcon and other relevant log sources to determine how an attack occurred, identify the initial access point, trace subsequent malicious activity, and establish the full scope of compromise across affected endpoints, systems, and user accounts.
-
Perform Advanced EDR Analysis: Investigate and analyze security detections beyond initial alert validation, leveraging endpoint telemetry, process execution data, and related indicators to reconstruct attacker activity, assess threats, and determine the nature and severity of incidents.
-
Execute Threat Hunting and Detection Analysis: Perform targeted threat hunting, analyze indicators of compromise (IoCs), and assess adversary tactics, techniques, and procedures (TTPs) to identify malicious activity, validate threats, and support improvements to detection and prevention capabilities.
-
Own Incidents Through Remediation Recommendations: Take ownership of escalated incidents from initial investigation through containment and remediation planning. Develop evidence-based assessments, determine root causes where possible, and provide clear, actionable recommendations to customers to support effective incident resolution.
-
Make Independent Containment Decisions: Assess incident severity, available evidence, potential business impact, and customer authorization boundaries to determine appropriate containment and response actions. Independently execute authorized actions, including endpoint isolation, blocking malicious indicators, and disabling compromised accounts when warranted.
-
Provide Actionable Remediation Guidance: Recommend appropriate eradication and recovery measures, including patching, system rebuilding, configuration changes, and other corrective actions for implementation by the customer or designated internal teams. Clearly communicate the urgency, rationale, and potential impact of recommended actions.
-
Manage Security Escalations: Independently assess, prioritize, and route incidents requiring customer review, urgent incident escalation, or assistance from management and specialized internal teams. Recognize active hands-on-keyboard activity and other high-risk scenarios that require immediate escalation, ensuring timely communication and appropriate ownership.
-
Communicate Findings to Customers and Stakeholders: Translate technical investigation findings into clear incident summaries, explain the attack path and scope of compromise, communicate containment decisions, and present prioritized recommendations to customers and relevant stakeholders.
-
Maintain Incident Documentation: Document investigation findings, supporting evidence, affected assets and accounts, containment actions, escalation decisions, incident timelines, and remediation recommendations in accordance with established operational procedures and customer requirements.
-
Leverage Security Tools and Threat Intelligence: Maintain strong working knowledge of EDR/XDR, SIEM, and relevant security monitoring platforms, using available telemetry and threat intelligence to support investigations, validate malicious activity, and improve incident handling effectiveness.
-
Improve MDR Operations and Detection Capabilities: Contribute to the continuous improvement of investigation playbooks, standard operating procedures, response workflows, and detection logic. Identify opportunities to improve alert quality, investigation efficiency, escalation practices, and the overall effectiveness of the MDR service.
-
Collaborate Across Security and Technical Teams: Work closely with customers, SOC colleagues, security engineering, IT, and other technical teams to coordinate incident handling, validate findings, facilitate remediation, and resolve complex security issues.
-
Participate in Rotational and After-Hours Coverage: Support after-hours and on-call incident escalation and response requirements, ensuring timely investigation, sound response decisions, and effective incident coordination.
Qualifications:
-
Bachelor degree in information technology, Computer Science, Cybersecurity, or a related discipline, or equivalent professional experience.
-
Expertise in investigating and mitigating security incidents across diverse environments, including on-premises, cloud, and hybrid infrastructures.
-
An experienced (Level 2 or 3) Analyst, looking to develop and grow a SOC service and team.
-
Strong understanding of threat intelligence integration, adversary TTPs, and the MITRE ATT&CK framework.
-
Desired Certifications: CompTIA Security+ and Cybersecurity Analyst (CySA+), ISC2 CC and SSCP, EC-Council Certified Incident Handler (ECIH), GIAC Certified Incident Handler (GCIH), and SIEM/EDR certifications (e.g., Splunk, Chronicle, CrowdStrike, SentinelOne) are a plus.
-
Advanced English (C1).
-
3–5 years of hands-on experience in SOC operations, preferably for a SOC or MDR service provider (e.g.,MSSP).
-
Proficiency with SOC technologies, including SIEM (e.g., Chronicle, Splunk, IBM QRadar), EDR/XDR (e.g.,Trellix, CrowdStrike, SentinelOne, BlackPoint), and SOAR platforms (e.g., Chronicle, FortiSOAR, Splunk SOAR).
-
Experience responding to alerts related to Microsoft Office 365, Identities (Entra ID, Active Directory),Cloud (AWS, Azure), Firewalls, Endpoint security, Email security, Web security (IP, DNS Filtering).
Our Hiring Process & AI Disclaimer: We use AI tools to streamline our application process—including an initial conversation with an AI Interviewer. All hiring decisions are made entirely by humans: our Talent Acquisition team guides your full candidate journey and makes all evaluation decisions.
You are welcome to use AI for CV refinement and research, but real-time AI assistance during interviews or skill assessments is strictly prohibited to ensure an authentic evaluation.
Read our full AI Disclaimer to learn more
What You’ll Get
At Penbrothers, we are obsessed with creating positive employee experiences. Here you’ll find an environment that nurtures learning and provides opportunities for growth. You’ll have the opportunity to make an impact on fast-growing startups and dynamic companies.
· Meaningful work & Growth: We take every opportunity to stretch ourselves and deliver an excellent client experience.
· Employee as our biggest asset: We are genuinely invested in our people’s career and welfare.
· Global reach & local impact: Get to work with high-growth startups and dynamic companies from the comfort of your own home.
· Powering global startups: We’ve created 1,400 Filipino jobs that empower global start-ups to focus on growth.