Security Operations III - Cyber Security Analyst

Posted Yesterday
Be an Early Applicant
Taguig City, Metro Manila, National Capital Region, PHL
In-Office
Mid level
Information Technology
The Role
Investigate and respond to complex cybersecurity incidents, including MDR alerts, malware, phishing, CASB, and SOC escalations. Conduct threat hunting, analyze logs, improve detection processes, automate security workflows, and manage investigations through remediation. Produce detailed incident reports and recommendations while applying knowledge of MITRE ATT&CK, network security, endpoint protection, SIEM/SOAR, cloud security, and scripting.
Summary Generated by Built In

About the Role

We are seeking a dedicated Cyber Security Analyst to join one of our client's teams of cybersecurity professionals. In this role, you will work closely with senior security team members to master existing security processes, procedures, and protocols. We are committed to the ongoing professional development of our team, providing the resources and collaborative environment needed to further elevate your technical expertise.


Scope of Work

  • Incident Response & Triage: Conduct in-depth investigations and incident response for complex security events, including Managed Detection and Response (MDR) alerts, malware/phishing campaigns, and CASB/SOC escalations.
  • Threat Hunting & Analysis: Analyze anomalous log data and collaborate during brainstorming sessions to proactively detect and eradicate threat actors across client networks.
  • Process Improvement & Automation: Analyze security incidents to enhance the alert catalog and continuously improve processes. Leverage automation to streamline detection sets and build a more efficient security posture.
  • Reporting & Remediation: Manage escalated investigations handed off from the Service Desk from start to finish. Provide comprehensive reports detailing the investigation's outcome, recommended remediation actions, and strategies to prevent future occurrences.

Required Qualifications & Skills

  • Bachelor's degree and 4+ years of prior relevant cybersecurity experience; or an equivalent combination of education and hands-on work experience.
  • Minimum of 3 years of experience in a dedicated Cyber Security support, incident response, or similar role.
  • Strong ability to conduct incident investigations and provide comprehensive triage support with minimal supervision.
  • Demonstrated understanding of network threat lifecycles, attack vectors, and exploitation methods, including strong familiarity with the MITRE ATT&CK framework and TTPs.
  • Solid foundational knowledge of TCP/IP, common networking ports/protocols, traffic flow, the OSI model, system administration, and defense-in-depth strategies.
  • Proficiency with modern enterprise security technologies, including Endpoint and Extended Detection and Response (EDR/XDR), Network Detection and Response (NDR), Next-Generation Firewalls (NGFW), and SIEM/SOAR platforms.
  • Familiarity with Zero Trust architecture, Intelligence-Driven Defense, and/or the Cyber Kill Chain methodology.
  • Introductory understanding of securing cloud services, containers, multi-tier web applications, data lakes, alongside solid SQL query skills.
  • Experience utilizing ServiceNow or similar enterprise ticketing systems.
  • Proficiency with Microsoft Excel and PowerPoint.
  • Proven track record of managing multiple concurrent tasks and meeting strict deadlines.
  • Must be willing to work USA Central time zone business hours.

Preferred Qualifications & "Plus" Factors

  • Specialized Security Platforms: Hands-on experience with ThreatLocker for zero-trust endpoint security and application control is a strong plus. Experience with CyberArk for privileged access management (PAM) and identity security is also highly desirable.
  • MDR & Incident Response: Advanced experience driving incident response specifically for Managed Detection and Response (MDR) security events.
  • Network & Access Security: Experience implementing and managing Cisco Secure Access or modern Security Service Edge (SSE) environments is a plus.
  • Web & Mobile Security: Proven experience managing website blacklisting and whitelisting, as well as administering Mobile Device Management (MDM) security tools and policies.
  • Automation & Scripting: Strong scripting and programming experience (especially PowerShell) to drive process automation.
  • OS Expertise: Intermediate knowledge of Windows 10, 11, and Windows Server administration, including OS hardening techniques. Familiarity with using and navigating Linux endpoints.
  • Tooling: Hands-on experience utilizing various open-source incident response tools and utilities.
  • Certifications: Advanced industry certifications (e.g., CISSP, SANS GIAC/GCIA/GCIH) or SIEM-specific training/certifications are highly preferred.
  • Continuous Improvement: A demonstrated commitment to self-study, training, and maintaining ongoing proficiency across emerging technical cybersecurity domains.

Skills Required

  • Bachelor's degree and 4+ years of relevant cybersecurity experience, or equivalent education and hands-on experience
  • At least 3 years of experience in cybersecurity support, incident response, or a similar role
  • Ability to independently conduct incident investigations and provide triage support
  • Understanding of network threat lifecycles, attack vectors, exploitation methods, MITRE ATT&CK, and TTPs
  • Knowledge of TCP/IP, networking ports and protocols, traffic flow, OSI model, system administration, and defense-in-depth
  • Proficiency with EDR/XDR, NDR, NGFW, and SIEM/SOAR platforms
  • Familiarity with Zero Trust, Intelligence-Driven Defense, or Cyber Kill Chain methodologies
  • Introductory cloud, container, web application, and data lake security knowledge, plus solid SQL skills
  • Experience with ServiceNow or a similar enterprise ticketing system
  • Proficiency with Microsoft Excel and PowerPoint
  • Willingness to work USA Central time zone business hours
  • Experience with ThreatLocker
  • Experience with CyberArk privileged access management and identity security
  • Advanced MDR incident response experience
  • Cisco Secure Access or Security Service Edge experience
  • Website blacklisting and whitelisting and Mobile Device Management security experience
  • PowerShell or other scripting and programming experience
  • Windows 10, Windows 11, Windows Server administration and hardening experience
  • Linux endpoint familiarity
  • Experience with open-source incident response tools
  • CISSP, SANS GIAC, GCIA, GCIH, or SIEM-specific certifications or training

Astreya Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Astreya and has not been reviewed or approved by Astreya.

  • Healthcare Strength — Health coverage includes multiple medical plan options plus dental and vision, complemented by FSAs, an EAP, disability and life insurance, and wellness programs. Feedback suggests these offerings provide solid core protection across many roles.
  • Wellbeing & Lifestyle Benefits — Client-site amenities at some large tech campuses can add non-cash value such as meals or on-site perks that enhance the day-to-day experience. Wellness Days and access to learning resources and tuition reimbursement further support overall wellbeing.
  • Flexible Benefits — Choice among medical plan types and tax-advantaged accounts enables some customization to individual needs. Some roles also offer remote or flexible work, adding practical flexibility to the total package.

Astreya Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Jose, California
1,958 Employees
Year Founded: 2001

What We Do

Astreya is the leading IT solutions provider for some of the world's most recognizable and innovative organizations. Our journey started in 2001 in the heart of Silicon Valley and reaches thirty-three countries with over 2200+ IT professionals. We enable businesses to make better decisions, achieve operational efficiency and gain a competitive edge. The Astreya advantage is centered around focus and clear- vision, world-class talent, and innovative technology: Creativity is in our DNA. Our dedicated Software and Service Innovation teams bring best-in-class technology and tools to bear for our clients.

Similar Jobs

Capital One Logo Capital One

Data Annotator

Fintech • Machine Learning • Payments • Software • Financial Services
Remote or Hybrid
Metro Manila, PHL
55000 Employees

Capital One Logo Capital One

Sr. Associate, Associate Relations

Fintech • Machine Learning • Payments • Software • Financial Services
Remote or Hybrid
Metro Manila, PHL
55000 Employees

Capital One Logo Capital One

Sr. Analyst, Data Analysis

Fintech • Machine Learning • Payments • Software • Financial Services
Remote or Hybrid
Metro Manila, PHL
55000 Employees

Optum Logo Optum

Technical Support

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Makati City, Metro Manila, National Capital Region, PHL
160000 Employees

Similar Companies Hiring

Axle Health Thumbnail
Artificial Intelligence • Healthtech • Information Technology • Logistics
Santa Monica, CA
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account