Cyber Security Analyst
Job Description
Cyber Security Analyst
Department: Optimization Engineering & Analytics
Reports To: Director, Global Cyber Operations
Employment Type: Full-Time, Exempt (40+ hours/week)
Work Setup: Remote (until further notice)
Schedule: 11pm - 8am MNL
We are seeking a Cyber Security Analyst to join a global Security Operations team supporting 24x7 managed security services.
In this role, you will monitor, analyze, escalate, and support the remediation of security incidents across enterprise client environments. You will work closely with cross-functional security teams to ensure threats are identified, validated, and resolved in a timely and effective manner.
This position requires strong foundational experience in network security and systems administration, along with hands-on exposure to endpoint security tools, SIEM platforms, incident response processes, and security automation.
- Provide 24x7 SOC support, following established operational frameworks and shift processes
- Monitor, analyze, and triage security alerts from SIEM, endpoint, network, and threat intelligence sources
- Investigate, escalate, and support remediation of security incidents
- Assist in incident response activities and provide technical guidance during active security events
- Support onboarding and integration of endpoint security and attack surface management solutions
- Develop and maintain automation playbooks to improve detection, triage, and response efficiency
- Assist in SIEM tuning, including detection rule creation, optimization, and false-positive reduction
- Collaborate with engineering teams to enhance SOC tooling, automation, and platform integrations
- Perform health checks and optimization of security tools and monitored environments
- Maintain clear and well-documented procedures, runbooks, scripts, and technical documentation
- Identify opportunities for continuous improvement to reduce MTTR and improve SOC efficiency
- Stay current with emerging threats, malware trends, and cybersecurity technologies
Qualifications:
- 4+ years of IT experience
- 3+ years of cybersecurity experience
- Strong knowledge of Windows, Linux, or macOS (at least two operating systems)
- Solid understanding of network protocols (TCP/IP, DNS, HTTP/HTTPS, FTP, SSH, SSL/TLS)
- Experience in security monitoring, incident response, and malware analysis
- Foundational scripting skills (PowerShell, Python, or Bash preferred)
- Ability to analyze logs and security event data from multiple sources
- Strong troubleshooting and analytical skills in security or network environments
- Ability to work independently with minimal supervision
- Strong interest in cybersecurity threats, tools, and emerging attack techniques
- Experience with endpoint security tools (CrowdStrike, Microsoft Defender, SentinelOne, Trellix ePO/ENS/EDR, or similar)
- Experience operating SIEM platforms (Splunk, Microsoft Sentinel, Elastic SIEM, Devo, or similar)
- Experience with SIEM detection engineering and rule tuning
- Exposure to patch management or vulnerability management tools (SCCM, Automox, SolarWinds, GFI LanGuard, etc.)
- Familiarity with MITRE ATT&CK, Cyber Kill Chain, or Diamond Model frameworks
- Industry certifications such as CEH, CISSP, GCIH, GMON, CISA, or similar
- Bachelor’s degree in Computer Science, Engineering, Mathematics, or related field (preferred)
Core Accountabilities:
- Real-Time Threat Monitoring & Triage: Ensure timely detection, validation, and escalation of security alerts
- Incident Response Support: Assist in investigation and remediation of security incidents with structured guidance
- Detection Engineering & Optimization: Improve SIEM rules and reduce noise through tuning and refinement
- SOC Process Excellence: Maintain consistent operational procedures and documentation across shifts
- Continuous Improvement: Drive efficiency gains by reducing MTTR and improving automation coverage
Performance Metrics
- Mean Time to Respond / Resolve (MTTR)
- Percentage of alerts covered by automated playbooks
- False positive rate reduction
- SLA compliance for alert triage and response