Job Openings SOC/MDR Security Analyst

About the job SOC/MDR Security Analyst

We're Hiring: SOC/MDR Security Analyst

Join our team and help protect organizations against evolving cyber threats. We are seeking a proactive and detail-oriented SOC / MDR Security Analyst who is passionate about cybersecurity, threat detection, and incident response. This role is ideal for someone with hands-on experience in Security Operations (SOC) or Managed Detection and Response (MDR) who enjoys investigating security events and contributing to a strong security posture.

Key Responsibilities:

  • Continuously monitor and analyze security alerts from SIEM, EDR, NDR, SOAR, and other security platforms
  • Perform triage, investigation, and classification of security events and incidents based on severity, impact, and context
  • Identify attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK
  • Support incident containment and response efforts in collaboration with Incident Response teams
  • Conduct log analysis, endpoint telemetry review, and behavioral detection to identify advanced threats
  • Integrate threat intelligence to enrich investigations and provide context to security alerts
  • Document incident workflows, indicators of compromise (IOCs), and lessons learned
  • Recommend improvements to detection rules, alert tuning, and security automation playbooks
  • Participate in threat hunting, purple team exercises, and continuous detection engineering initiatives

Requirements:

  • Fluent in English
  • 1–2 years of experience in a SOC, MDR, Blue Team, or similar cybersecurity operations role
  • Experience with security tools such as Elastic, Splunk, CrowdStrike, SentinelOne, Suricata, Zeek, and Wireshark
  • Strong understanding of Windows and Linux operating systems, Active Directory, and common attack techniques
  • Familiarity with threat hunting methodologies, IOC analysis, and alert enrichment
  • Ability to communicate investigation findings clearly to both technical and non-technical stakeholders
  • Experience using cybersecurity frameworks such as MITRE ATT&CK, Cyber Kill Chain, and the Diamond Model
  • Experience with Python, PowerShell, or regular expressions is a plus

Preferred Qualifications:

  • GIAC certifications (GCIA, GCIH, GDAT)
  • CompTIA Security+ or CySA+
  • OSCP or CEH certification
  • Vendor certifications such as SentinelOne Ranger, CrowdStrike Certified Falcon Responder, or Splunk Core Certified

Work Setup:

  • 100% Work From Home
  • Full-Time Position
  • Working hours are on an early morning shift (Philippine time) or as required by the client

Salary:

  • USD 9 per hour