SOC Team Lead (L2) / Security Information & Event Management (SIEM) Platform Operation | Hybrid in Cubao | ATCP-1335560-S423658
Job Description
Key Skills
15 candidate(s) have already applied for this Job. Apply now
SOC L2 – Security Operations / Cyber Defense
Location: Manila – Hybrid in Cubao
Work Setup: Hybrid
Work Shift: Shifting
Employment Type: Full-Time
Lead Incident Response. Strengthen Cyber Defense.
We are looking for an experienced SOC L2 professional to support advanced security monitoring, incident investigation, threat detection, and incident response activities across enterprise environments.
This role is ideal for experienced SOC and Cyber Defense professionals who can investigate complex security incidents, guide junior analysts, coordinate high-priority incident response, and continuously improve security operations.
Key Responsibilities
Lead the investigation and resolution of complex security incidents escalated by L1 analysts.
Perform root cause analysis, threat validation, and incident triage across enterprise environments.
Act as a key responder during high-severity security incidents.
Coordinate with CSIRT, engineering teams, and relevant stakeholders during incident response activities.
Conduct threat hunting using Indicators of Compromise (IoCs) and threat intelligence.
Mentor and guide SOC analysts through coaching, quality reviews, and incident-handling best practices.
Collaborate with detection engineering teams to improve security use cases, alert quality, and SOC processes.
Analyze security logs, network traffic, and security events across enterprise environments.
Maintain incident documentation, reports, playbooks, and operational procedures.
Contribute to continuous improvement of security monitoring and incident response processes.
Required Experience & Skills
3–5+ years of experience in a SOC, Incident Response, or Cyber Defense environment.
Previous experience leading, mentoring, or supervising SOC analysts is highly preferred.
Strong hands-on experience investigating security incidents using SIEM and security monitoring tools.
Strong knowledge of network security, threat detection, malware analysis, incident response, and threat hunting.
Experience analyzing logs, network traffic, and security events across enterprise environments.
Ability to work effectively during high-priority security incidents.
Strong communication and cross-functional coordination skills.
Preferred Qualifications
Experience with CrowdStrike Falcon is highly preferred.
Hands-on experience with SIEM platforms such as:
Splunk
Microsoft Sentinel
IBM QRadar
Google SecOps
Other comparable SIEM platforms
Scripting experience using Python or PowerShell for automation and investigations.
Security certifications such as Security+, CEH, GCIH, GCIA, or equivalent.
Exposure to cloud security monitoring across AWS, Azure, or GCP.
Work Setup
Hybrid work arrangement.
Office location: Cubao, Manila.
Must be amenable to a shifting schedule.
Applicants must currently be based in the Philippines.
Applicants must already have the legal right to live and work in the Philippines.
Recruitment Process
Screening with CV Reviewer
Endorsement for validation and further CV screening through Workday, including the HRI toolkit, FCV, and CV
Client review
Pre-Screening Questions
How many years of experience do you have in a SOC, Incident Response, or Cyber Defense environment?
Have you led, mentored, supervised, or guided SOC analysts? Please provide details.
What is your level of hands-on experience with SIEM platforms? Please mention the platforms you have worked with.
Do you have hands-on experience with CrowdStrike Falcon or other EDR/XDR tools?
What is your experience with incident response, threat hunting, and security incident investigation?
What is your last drawn salary?
What is your expected salary?
Are you willing to work in a hybrid setup in Cubao with a shifting schedule?
What is your current notice period?
Important: Please ensure that the latest version of the candidate's CV is uploaded in PDF format, along with screening notes based on the requirements of the JD.
Role
Security
Timings
Rotational Shifts (Permanent)
Industry
IT-Software / Software Services
Work Mode
Hybrid
Process
Non-Voice
Functional Area
IT Software/Hardware
Note: Myglit doesn't charge any money from candidates. If you have been asked to pay money to get this job then report to us immediately at support@myglit.com.
Interview Tips
- Giving the VNA round?
- What are the most important skills you acquired as a Soft Skills/VNA trainer?
- How would you handle an irate customer?
Similar Jobs
Senior CIS Functional Support Analyst
Gratitude Inc4 - 7 Year(s)
Confidential
Manila, Philippines
Senior System Analyst - eProc
Gratitude Inc5 - 10 Year(s)
Confidential
Manila, Philippines
Manager, pre-sales & solutions - service desk
Gratitude Inc5 - 10 Year(s)
Confidential
Manila, Philippines
HR ServiceNow Application Developer
Gratitude Inc5 - 8 Year(s)
Confidential
Manila, Philippines
3 - 5 Year(s)
Confidential
Manila, Philippines
Workday Payroll | Hybrid Quezon City -URGENTLY HIRING
Gratitude Inc2 - 5 Year(s)
Confidential
Manila, Philippines
5 - 10 Year(s)
Confidential
Manila, Philippines
Trainer II | Training- Helpdesk Customer Support
Gratitude Inc2 - 4 Year(s)
Confidential
Manila, Philippines
Site Realibility Engineer
Gratitude Inc3 - 6 Year(s)
₱ 85 - ₱ 90K p.m
Manila, Philippines

