- Location
- Taguig, NCR,PH, PH · Cebu City, Central Visayas,PH, PH
- Type
- Full-time
- Department
- Engineering
- Seniority
- Senior
- Experience
- 2+ years
- Education
- PhD
- Source
- Eightfold
Description
Meet the team:
The Enterprise Cyber Defense team is a competitive group of individuals who work on these cybersecurity pillars: Cybersecurity Operations Center (SOC), Attack Surface Management, DLP, Email Security, SIEM Management, Detection Engineering and Security Operations Automation. As a Staff Cybersecurity Engineer, you will be involved in the end-to-end cycle of incident management as well as lead or support Security Operations projects. (including discovery, threat analysis and correlation, response and remediation, and continuous monitoring).
Where you come in:
- You will serve as a Tier 4 Security Operations Center (SOC) Engineer, leading the monitoring, investigation, and response to security events across SIEM, XDR/EDR, email security, IDS/IPS, DLP, firewalls, cloud, and other security platforms.
- You will lead or support advanced Digital Forensics and Incident Response (DFIR) activities, including threat hunting, malware investigations, endpoint and network forensics, root cause analysis, containment, eradication, recovery, and post-incident reviews.
- You will design, develop, optimize, and maintain detection content, correlation rules, analytics, and use cases based on threat intelligence, adversary TTPs, and the MITRE ATT&CK framework.
- You will leverage AI and machine learning capabilities within security platforms to enhance detection engineering, threat hunting, alert triage, investigation efficiency, and security operations effectiveness.
- You will act as a shift lead or point of escalation
- You will lead or support projects and initiatives of the Cyber Defense Team
- You may lead, support or perform other allied security services (on-demand) including, but not limited to: penetration testing, purple-team exercises, adversary emulation, security control validation and audit related activities.
- You will mentor and provide technical guidance to analysts and engineers across incident response, forensic investigations, threat detection, and security operations best practices.
What makes you successful:
- You possess strong expertise in Security Operations, Detection Engineering, Threat Hunting, Incident Response, and DFIR methodologies.
- Your hands-on experience with SIEM, XDR/EDR, IDS/IPS, DLP, vulnerability management, firewall, email security, and cloud security technologies.
- You have demonstrated experience designing, implementing, tuning, and maintaining security detections, analytics, and monitoring use cases.
- Your proficiency in utilizing AI-assisted security technologies, automation, machine learning analytics, or generative AI capabilities to improve detection and response outcomes.
- Your solid experience investigating and responding to complex security incidents involving malware, ransomware, phishing, insider threats, credential compromise, cloud attacks, or advanced persistent threats.
- You possess practical experience conducting endpoint and network forensics, evidence collection, malware analysis, timeline reconstruction, and root-cause investigations.
- Your experience leading security projects, technical implementations, operational improvements, and cross-functional initiatives.
- You have experience securing and administering Windows, Linux, macOS, cloud, and hybrid enterprise environments.
- You possess strong analytical, investigative, communication, and stakeholder engagement skills.
- Your flexibility to support US, EMEA, or APAC operations through a sustainable rotational schedule and participate in on-call activities as required.
Nice to have Qualifications:
- You possess experience with SOAR platforms, security automation, and AI-powered security operations tools.
- You possess hands on experience with scripting and automation using Python, PowerShell, KQL, XQL, SPL, Sigma, YARA, Regex, or similar technologies.
- Your hands-on experience in DFIR, reverse engineering, malware analysis, penetration testing, purple teaming, adversary emulation, or advanced threat hunting.
- You hold industry-recognized certifications such as CISSP, CISM, GCIH, GCFA, GCFE, GCIA, GMON, CEH, OSCP, or other Industry certifications (Preferred but not required)
What you’ll get:
- A front row seat to life changing CGM technology. Learn about our brave #dexcomwarriors community.
- A full and comprehensive benefits program.
- Growth opportunities on a global scale.
- Access to career development through in-house learning programs and/or qualified tuition reimbursement.
- An exciting and innovative, industry-leading organization committed to our employees, customers, and the communities we serve.
Experience and Education Requirements:
- Typically requires a Bachelor’s degree in a technical discipline, and 8-12 years related experience or Master’s degree and 5-7 years equivalent industry experience or a PhD and 2-4 years of experience.
#LI-Hybrid
AI in Hiring Notice: We may use AI supported tools to help make our hiring process more efficient, consistent, and accessible for candidates around the world. All hiring decisions are made by people.