Job Openings
SOC/MDR Security Analyst
About the job SOC/MDR Security Analyst
We're Hiring: SOC/MDR Security Analyst
Join our team and help protect organizations against evolving cyber threats. We are seeking a proactive and detail-oriented SOC / MDR Security Analyst who is passionate about cybersecurity, threat detection, and incident response. This role is ideal for someone with hands-on experience in Security Operations (SOC) or Managed Detection and Response (MDR) who enjoys investigating security events and contributing to a strong security posture.
Key Responsibilities:
- Continuously monitor and analyze security alerts from SIEM, EDR, NDR, SOAR, and other security platforms
- Perform triage, investigation, and classification of security events and incidents based on severity, impact, and context
- Identify attacker tactics, techniques, and procedures (TTPs) using frameworks such as MITRE ATT&CK
- Support incident containment and response efforts in collaboration with Incident Response teams
- Conduct log analysis, endpoint telemetry review, and behavioral detection to identify advanced threats
- Integrate threat intelligence to enrich investigations and provide context to security alerts
- Document incident workflows, indicators of compromise (IOCs), and lessons learned
- Recommend improvements to detection rules, alert tuning, and security automation playbooks
- Participate in threat hunting, purple team exercises, and continuous detection engineering initiatives
Requirements:
- Fluent in English
- 1–2 years of experience in a SOC, MDR, Blue Team, or similar cybersecurity operations role
- Experience with security tools such as Elastic, Splunk, CrowdStrike, SentinelOne, Suricata, Zeek, and Wireshark
- Strong understanding of Windows and Linux operating systems, Active Directory, and common attack techniques
- Familiarity with threat hunting methodologies, IOC analysis, and alert enrichment
- Ability to communicate investigation findings clearly to both technical and non-technical stakeholders
- Experience using cybersecurity frameworks such as MITRE ATT&CK, Cyber Kill Chain, and the Diamond Model
- Experience with Python, PowerShell, or regular expressions is a plus
Preferred Qualifications:
- GIAC certifications (GCIA, GCIH, GDAT)
- CompTIA Security+ or CySA+
- OSCP or CEH certification
- Vendor certifications such as SentinelOne Ranger, CrowdStrike Certified Falcon Responder, or Splunk Core Certified
Work Setup:
- 100% Work From Home
- Full-Time Position
- Working hours are on an early morning shift (Philippine time) or as required by the client
Salary:
- USD 9 per hour