SOC Security Analyst L3
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
By continuing, you agree to our Terms & Privacy Policy.
Position: SOC Security Analyst L3
Reports To: SOC Team Lead / SOC Manager
Department: Security Operations Center (SOC)
Location: Remote, Philippines
Shift Schedule: Sunday-Wednesday or Wednesday-Saturday, 7:00am-5:00pm
Work Authorization: Philippine Citizenship Required
BlueVoyant is seeking a SOC Security Analyst L3 to join our Security Operations Center, defending our global customers against constant and evolving adversary activity. As the senior technical expert and escalation point for your team, you will handle active intrusions, lead complex investigations, and ensure attacks against our clients are handled with urgency, accuracy, and clear communication. You will mentor junior analysts, act as a trusted voice for clients, and contribute directly to technology strategy and process improvement. This role reports into BlueVoyant SOC leadership and operates under BlueVoyant processes, tooling, and supervision at all times, including when working within client environments.
What You’ll Do:
- Monitor and analyze security events and alerts from multiple sources, including SIEM logs, endpoint logs, and EDR telemetry.
- Act as the technical escalation point for active intrusions and escalations from junior analysts.
- Execute complex investigations, handle incident declaration, and perform live response analysis of compromised endpoints.
- Research indicators and activities to determine reputation and suspicious attributes.
- Perform analysis of malware, attacker network infrastructure, and forensic artifacts.
- Hunt for suspicious activity based on anomalous behavior and curated threat intelligence.
- Ensure events are properly identified, analyzed, and escalated to incidents.
- Participate in the response, investigation, and resolution of security incidents, and engage BlueVoyant Incident Response teams for active intrusions.
- Deliver clear incident investigation, handling, and response documentation that leaves clients with defined remediation actions.
- Communicate regularly with clients to inform them of incidents and support remediation.
- Identify and tune false-positive or benign detections.
- Perform peer review and QA of junior analyst investigations, and mentor lower-level analysts.
- Assist in the advancement of security policies, procedures, and automation.
- Support the Customer Success team with client engagements when required.
- Operate across BlueVoyant-managed systems and client-provided environments in accordance with client-approved access controls, logging, and BlueVoyant operating procedures, maintaining strict separation and adherence to security policies.
What You’ll Bring
- Ability to handle high-pressure situations in a productive and professional manner.
- Advanced written and verbal communication skills, with the ability to present complex technical topics in clear, easy-to-understand language.
- Strong teamwork and interpersonal skills, including working effectively within a globally distributed team.
- Ability to work directly with clients to understand requirements and gather feedback on security services.
- Knowledge and experience with SIEM solutions, Cloud App Security tools, and EDR.
- Experience with SIEM/EDR detection creation.
- Expertise in endpoint, web, and authentication log analysis.
- Advanced knowledge of network protocols, network telemetry, and commonly abused protocols.
- Experience responding to modern authentication attacks against Active Directory, Entra ID, OAuth, and SSO.
- Expert knowledge of common attack paths, including LOLBin use, common adversary tools, business email compromise (BEC), and AiTM attacks, including identification and response.
- Strong knowledge of:
- SIEM workflows (preferably Microsoft Sentinel and Splunk)
- Malware detection, including dynamic and light static analysis, and Windows PE and maldoc analysis
- Network monitoring metadata (web logs, firewall logs, WAF/IDS)
- Email security and common BEC attacks
- Windows and Unix forensic artifacts (e.g. registry analysis, wtmp/btmp)
- Remote access solutions (both legitimate and inherently malicious)
- Lateral movement methodologies and tools for Windows and Unix-based operating systems
- Microsoft 365 attack paths and common attacker methodologies
- Credential harvesting tools and methodologies
Nice to Have:
- Background in intrusion analysis, incident response, digital forensics, penetration testing, or related areas.
- 5+ years of hands-on SOC/TOC/NOC experience.
- Experience countering ransomware threat actors and operations.
- Familiarity with Microsoft Sentinel, Splunk, Microsoft Defender suite, CrowdStrike Falcon, and