Threat Intelligence Manager
2 days ago
I. PURPOSEExecute activities that will improve existing operations and operationalize new service portfolio to achieve service excellence, operational efficiency, business profitability, and retention of customers.II. DUTIES AND RESPONSIBILITIESAccomplish all assigned tasks by the management in a timely and effective manner as deemed necessary for the betterment of the organization.Manage teams and ensure accordance with the support and operations' policies, protocols, and procedures.Oversee the 24x7x365 management of teams and overall performance and reliability of the shift.Ensure effective and efficient processes are followed, and that proper escalation protocols are in place and complied with by the teams.Prepare shift hand over report. Hand over open and ongoing events, incidents, and escalations to the next shift.Collaborate and contribute with other managers in improving workflows, documentations, standards, and processes.Accountable for the growth of team members and ensuring succession plan is in place.Evaluate the skill sets of each group member and give recommendations to the MSS Manager for growth.Responsible/Accountable in providing input to training and certifications plan for his direct reports and ensure that the entire group is covered according to business operations need.Conduct performance review of team members.Contribute to the knowledge and information relevant to Operations.Participate in activities promoting a harmonious working environment such as demonstrating trust and respect and practicing open communication.Comply with company policies, guidelines, standards, and procedures.Professionally represent Trends management; enriching client relationships and providing expertise, composure, and competence.Perform all other duties and tasks as assigned by the MSS Manager.Threat IntelligenceMonitor the displayed information on the Threat Intelligence Platform (TIP) related to emerging threats, vulnerabilities, campaigns, etc.Conduct research using the Threat Intelligence Platform (TIP) or any other relevant source of information such as open-source, proprietary or commercial information to gather cyber and IT information about threats, vulnerabilities, and/or any other party that needs to be monitored for awareness.Monitor, utilize the collected data, and report to the client if affected by pre-NVD and zero-day vulnerabilities.Utilize Threat Intelligence Platform's threat intelligence card and advanced queries for deeper and more contextual investigation.Investigate information on the intention to target clients, their industry like major activist campaigns, and indications of activism and all relevant intelligence against the clients.Perform industry peer comparison and determine the trending attack methods.Prepare and submit the following reports based on frequency:Operational Intelligence Report (Weekly Digest)Tactical Intelligence Report (Daily Digest)Incident-related Reports (Adhoc)Other operational report as directed by the businessLead the team in establishing cyber protection programs and activities.Perform as lead researcher, giving guidance to team on where, what, and how to dig information.Review materials prepared and written by the team.Create analyst notes (or validated research documents) and collaborate with other members of the team for verification of reports.Detect, report, and request for takedowns of servers launching phishing attacks, fake applications that impersonate legitimate ones from app stores, malicious websites, or fraudulent social media accounts.Report any brand attack and data leakage detection from the solution with corresponding mitigating actions.Threat HuntingConfigure tools and detect patterns/outliers within client environments matching tactics, techniques, or procedures (TTPs) of known threat actors, malware or other unusual or suspicious behaviors.Conduct cyber hunts in support of identifying emerging threats on behalf of multiple clients, often operating as a lead investigator.Provide expert analytic investigative support for large-scale and complex security incidents across multiple clients and support the TOC team through the investigation, recommendations, response, and post-mortem efforts.Monitor multiple client environments and investigate & report on emerging threats.Work with internal teams on orchestration & tool-based enablement and optimization of team processes supporting overall service delivery.Conduct dynamic and static malware analysis on samples obtained during incident handling or hunt operations to identify IOCs.Contribute to documenting simple and reusable hunt tactics and techniques for the extended and shifting team delivering threat services.Engage with client POCs as necessary to help them truly mature and optimize their security architecture, primarily from a risk management and incident response perspective.Availability ManagementManage monthly shift schedules, create appropriate shift design, manage conflicts within the shift, design operational process guidelines, and ensure cascade and understanding of the shift being managed as compliance to agreed levels of availability of people and processes needed for Operations delivery.Operationalization of management defined metrics and reporting compliance.Ensures that tools being used are appropriate for the agreed service level targets for availability such as tools for role-based access design, availability reporting, and design testing.Capacity ManagementDetermine and report the capacity and performance of people, processes, and organizational controls, and ensure resolution of issues through tactical adjustment of operational processes, people, and platform.Work with other managers to gather data and develop strategies as input to the business plan and execute these strategies to deliver the service and plans for short, medium, and long-term business requirements.IT Service Continuity ManagementPerform the role assigned in the Business Continuity Plan (BCP).Create and perform adjustments in the operational processes in compliance with the Business Continuity Plan (BCP) objectives to ensure service delivery objectives are met in case of a disaster.Provide input to the Operations' Business Impact analysis to reduce risks to an acceptable level and plan for the team's recovery.Risk ManagementExecute risk treatment plans for people and processes needed for Operations.Service Level ManagementEnsure compliance of Service Level Agreements with clients.Manage the performance of team members in Internal SupportMonitor and report on Operational Service Levels.Change Advisory BoardApprove Method of Procedures to be presented during Managed ICT Services Change Advisory Board meetings.Participate in client Change Advisory Board meetings.Advise client during Operational discussions on the possible impact, risks, and effects of proposed client changes.Create advisories on the possible impact, risks, and effects of proposed client changes.Provides Method of Procedure/s and other documentation to clients whenever necessary.Configuration ManagementResponsible for accepting Configuration Items (CI) and other relevant information of Transitions.Sign off CI of client assets and its components as part of Operations, and handover CI and other relevant information to Transitions for Offboarding.Client SupportEnsure that the team members are:Performing triage on received events and incidents.Handling cases assigned.Undertaking immediate effort/s to restore a failed service of a Managed Service client as quickly as possible.Performing brand monitoring and takedown requests.Handling escalation and follow-ups until resolution.Review Incident and Root-Cause-Analysis (RCA) Reports.Client Incident ManagementReview operational playbooks to detect, analyze, eradicate, remediate, and recover from client cybersecurity incidents.Guarantee that quality of service incidents is reviewed and adjusted according to client needs, agreed standards and frameworks.Lead resolution of P1 and P2 incidents.Review RCA Reports and ensure Corrective Actions/Preventive Actions (CA/PA) are executed.Client Access ManagementPerforms authorization of users' right to access client assets, while preventing access to non-authorized users.Essentially executes Terms and Conditions of the client.Client IT Asset ManagementEnsure that clients' managed assets are accounted for, maintained, upgraded (if within scope), and that lifecycle is monitored.Provides reports and recommendations to the Client, Service Delivery Manager/s, and other relevant stakeholders.Client Problem ManagementLeads P1/P2 RCA and ensure CA/PA is implemented on time.Ensure shift compliance with contractual Problem Management deliverables.Acts as the Problem Manager for P1/P2 incidents:Manage the lifecycle of all identified problems.Prevent recurring incidents from happening and minimize the impact of recurring incidents that cannot be prevented.Maintain information or Knowledgebase about Known Errors and Workarounds.Identify Problem records.Attend Problem Management meetings with the MSS Manager.Process ManagementCreate, share, use, and manage the documented processes of Service Operations, and ensure that these processes are being followed.Knowledge ManagementResponsible in updating the knowledge and information pertaining to existing Clients and clients' Managed ICT assets.Continual Service Improvement ManagementExecute improvement plans of the people and processes of Operations at a tactical level.Review and approve tactical and operational changes and ensure its deployment.Ensure the quality of data and content of tickets are reviewed.III. QUALIFICATIONSA. Minimum EducationMust be a graduate of any IT related bachelor's degree such as:Computer StudiesComputer EngineeringInformation TechnologyElectronics EngineeringB. Minimum Experience/TrainingHave at least 5 years of working experience in a 24x7x365 Security Operations Center.Trainings and/or certifications on at least 2 of the following domains are required:IT Service ManagementIT Infrastructure (Network, Servers, Cloud, etc.)Cybersecurity and/or Information SecurityThreat Intelligence Certifications i.e. CTIA, GCTI, CCTIAeCTHPv2 or other related certificationOSINT/Threat Intelligence TrainingsC. Competency(F) - Familiar / 0-12 months(N) - Novice / 1-2 years(I) - Intermediate / 3-4 years(A) - Advanced / > 5 yearsKNOWLEDGE(A) Knowledge of cybersecurity and privacy principles.(A) Knowledge of computer networking concepts and protocols, and network security methodologies.(A) Knowledge of risk management processes (e.g., methods for assessing and mitigating risk).(A) Knowledge of cyber threats and vulnerabilities.(A) Knowledge of specific operational impacts of cybersecurity lapses.(A) Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).(A) Knowledge of system administration, network, and operating system hardening techniques.(A) Knowledge of MITRE ATT&CK Framework and NIST SP800-61TECHNICAL SKILLS(A) ITIL(A) Networking Fundamentals(A) Operating System Fundamentals(A) Application/Web Programming(A) Enterprise Application Architecture(A) Cybersecurity Fundamentals(A) Secure Network Architecture(A) Application Security & Secure Coding Practices(I) Identity & Access Management Principles(A) Cryptography & Encryption Technologies(I) Perimeter Defense Technologies(I) End-Point Protection Technologies(A) Vulnerability Scanning & Ethical Hacking(A) Advanced Persistent Threats & pattern modeling(A) Forensic Investigation(N) Dark web Surfing & Intel GatheringCOMMUNICATION SKILLS(A) Speaks clearly and can be easily understood.(A) Expresses & speaks ideas in a logical and organized sequence.(A) Writes clearly, concisely, and effectively.(A) Expresses ideas in a logical and organized sequence in written form.IV. WORKING CONDITIONSReporting to the company's main office in Makati City.Shifting schedule.Collaborate physically and/or virtually with internal and external stakeholders.May travel for company-sponsored conferences and related marketing events.Attend training and acquire certifications that are applicable to the role.
-
Cyber Threat Intelligence Engineer
2 weeks ago
Makati City, National Capital Region, Philippines AIA Digital+ Full time ₱1,200,000 - ₱2,400,000 per yearThe role of the candidate is to be a part of GIS Cybersecurity team to function as a Senior Manager in the Cyber Threat Intelligence Team.The role requires to proactively investigate security events to identify artifacts of a cyber-attack detect advanced threats that evade traditional security solutions, threat actor-based investigations, creating new...
-
Threat Response Coordinator
6 hours ago
Makati City, National Capital Region, Philippines Genfinity Full time ₱320,000 - ₱480,000 per yearThis position is more than just security—it is the lifeblood of the company. We are looking for someone looking to increase all his or her skills and make a real difference in security.We are seeking awesome experienced people preferably with background in monitoring, loss prevention, emergency dispatch or alarm call centers to join our team.We are looking...
-
Social Intelligence Manager
2 weeks ago
Makati City, National Capital Region, Philippines Ogilvy Full time ₱1,500,000 - ₱2,500,000 per year*About Ogilvy*Ogilvy has been creating impact for brands through iconic, culture-changing, value-driving ideas since the company was founded by David Ogilvy 75 years ago. It builds on that rich legacy through Borderless Creativity – innovating at the intersections of its advertising, public relations, relationship design, consulting, and health...
-
Cyber Resilience and Business Continuity Analyst
3 hours ago
Makati City, National Capital Region, Philippines Page Outsourcing RPO APAC for Sealed Air Full time ₱1,200,000 - ₱2,160,000 per yearThe Cybersecurity & Resilience department is dedicated to safeguarding information assets and mitigating cyber risks. Our focus is on incident response preparedness, operational excellence, and enhancing cyber resilience. As a member of this team, you will engage in readiness assessments, improve incident response processes, and elevate key performance...
-
IT Security Senior Analyst
1 week ago
Makati City, National Capital Region, Philippines Nezda Technologies Inc Full time ₱1,200,000 - ₱3,600,000 per yearThis position calls for a Senior SOC Analyst with proven expertise in cybersecurity monitoring, threat detection, and incident response across complex enterprise environments. The Senior SOC Analyst is responsible for leading the analysis of security events, proactively identifying and mitigating threats, and mentoring junior analysts within a 24x7x365 SOC...
-
Cybersecurity Operations Lead
6 hours ago
Makati City, National Capital Region, Philippines PLDT GLOBAL INC. Full time ₱1,500,000 - ₱2,500,000 per yearCybersecurity Operation Lead Responsibilities:Deep understanding of cybersecurity best practices and threat landscapesLead and manage the Red and Blue specialists, ensuring all members are trained, motivated, and working effectively togetherProficiency in threat intelligence, incident detection, analysis, and responseOversee incident response efforts,...
-
Security Analyst
1 week ago
Makati City, National Capital Region, Philippines Wordtext Systems Incorporated Full time ₱900,000 - ₱1,200,000 per yearJob SummaryMonitor, investigate and analyze security alerts. Performs in-depth analysis of network traffic and logs, and manages incident response, often requiring advanced technical skills and a deep understanding of cybersecurity frameworks and tools like SIEM, EDR, MDR. Key responsibilities include advanced incident handling, root cause analysis, triage,...
-
Business Intelligence Analyst
1 week ago
Makati City, National Capital Region, Philippines Asia Brewery Incorporated Full time ₱900,000 - ₱1,200,000 per yearQualifications & experienceBachelor's Degree in Business Administration, Economics, Accounting, Computer or Information Science or any related courseAt least One (1) year experience in a local or multinational FMCG companyAt least one (3) Year of Trade Marketing, Sales Information experience in a local or Multinational FMCG companyTasks &...
-
Business Intelligence Engineer
2 weeks ago
Makati City, National Capital Region, Philippines Metrobank Full time ₱900,000 - ₱1,200,000 per yearBe #InGoodHands with MetrobankHere at Metrobank, we don't simply hire employees—we hone future leaders. We provide opportunities that enhance your skills and unlock your talents, helping you evolve into a well-rounded individual. We supply you with all the pieces you need to do your best work, unleashing your full potential to help you secure your future...
-
Portfolio Intelligence and Controls Officer
6 days ago
Makati City, National Capital Region, Philippines Atram Full time ₱2,000,000 - ₱2,500,000 per yearRole SummaryThe Portfolio Intelligence and Controls role is a strategic and cross-functional position responsible for delivering advanced analytics, supporting risk consultancy projects, and ensuring mandate rule governance and compliance documentation. The role collaborates closely with internal teams-including Risk, Compliance, Client Solutions,...