Security Operations Engineer

3 days ago

Metro Manila, Philippines Cloudstaff Full-time

We’re Hiring: Security Operations Engineer

Looking for a role that fosters collaboration, creativity and career growth in a vibrant office environment? We got you covered

Role

Security Operations Engineer

Work Arrangement

Hybrid

Schedule

Morning shift

The Security Operations Engineer runs the business-as-usual security services stack deployed, working with Microsoft 365 E3 and Microsoft Intune, Rapid7 and the Netskope suite to protect the environment spanning Microsoft 365, Microsoft Azure and Amazon Web Services (AWS). The role works closely with the SOC Analyst to tune metrics and feeds into the Security Information and Event Management (SIEM) platform, and leads vulnerability and patch management.

Key Responsibilities

  • Operate the Nexgen Rapid7 Security Information and Event Management (SIEM) platform, ingesting logs from Microsoft Entra ID, Microsoft 365, AWS CloudTrail and AWS GuardDuty.
  • Tune SIEM alerts, severity classification and incident workflow with the SOC Analyst, feeding refined metrics into the platform.
  • Lead vulnerability management using Rapid7 and Microsoft Defender for Cloud scanning across Azure and AWS.
  • Run patch management through Microsoft Intune for workstations and AWS Systems Manager for the SOHO and Digital applications.
  • Operate CrowdStrike Endpoint Detection and Response or Microsoft Defender (EDR) and application whitelisting, driving full endpoint coverage.
  • Deploy and validate immutable backups with Veeam and AWS Backup covering Microsoft 365 and AWS workloads

Parallel and Cross-Functional Responsibilities

  • Help cover Security Operations Centre (SOC) triage overflow and alert tuning alongside the SOC Analyst.
  • Provide cloud security posture support to the DevSecOps Engineer across AWS and Azure, including Security Hub and Defender for Cloud.
  • Provide endpoint hardening support to the M365 Engineer, applying Essential Eight aligned Intune baselines, and support Data Loss Prevention (DLP) operations across Microsoft Purview and Netskope.

Technical Environment

  • Rapid7 as the Security Information and Event Management (SIEM), vulnerability scanning and tracking platform
  • Microsoft 365 E3 with Microsoft Intune, Microsoft Defender, Microsoft Purview and Microsoft Entra ID, providing native telemetry into the SIEM.
  • The Netskope suite for secure web gateway, Data Loss Prevention (DLP), always-on Virtual Private Network (VPN) and Cloud Access Security Broker (CASB).
  • CrowdStrike or Microsoft Defender for Endpoint Detection and Response (EDR), Cloudflare for Web Application Firewall (WAF) and Distributed Denial of Service (DDoS) protection, LastPass for password management, and Veeam and AWS Backup for backup independence.

Qualifications and requirements

  • Demonstrated experience operating a Security Information and Event Management (SIEM) platform such as Rapid7 or Microsoft Sentinel.
  • Hands-on vulnerability and patch management experience across cloud and endpoint estates.
  • Working knowledge of Endpoint Detection and Response (EDR) and application whitelisting operations.
  • Practical security experience across Amazon Web Services (AWS) and Microsoft Azure, with confidence in Microsoft 365 E3, Microsoft Intune and Microsoft Entra ID administration.

Highly Desirable

  • Experience with Rapid7 for vulnerability scanning and the Netskope suite for secure web gateway and Cloud Access Security Broker (CASB).
  • Familiarity with Microsoft Defender or CrowdStrike Endpoint Detection and Response (EDR) and Cloudflare protection services.
  • Exposure to backup and disaster recovery tooling such as Veeam and AWS Backup, and to the Essential Eight and Centre for Internet Security (CIS) benchmarks.
  • A security certification such as Microsoft Certified: Security Operations Analyst Associate or AWS Certified Security.

Non-negotiable skills and requirements

  • A relevant tertiary qualification in information technology, cyber security or a related field, or equivalent experience.
  • Comprehensive health and life insurance on your 16th day of employment, covering 1 free dependent on the 16th day of employment
  • Flexible leave credits which may be used for vacation, emergency and sick leaves
  • Superb and exciting Mid-Year Parties – with items to give away and cash prizes
  • Endless opportunities for career advancement
  • Exclusive ATM inside the office for employee's convenience
  • Annual Performance Review with Salary Increase
  • We set you up for success with a company-provided PC/Laptop and fiber internet connection
  • Look forward to weekly office perks for work from office staff – Free Coffee, Meals and Beer Fridays
  • Top notch workplace with firs