L2 SOC Analyst

3 hours ago


Manila, National Capital Region, Philippines Graybox Security Full time ₱1,500,000 - ₱3,000,000 per year

L2 SOC Analyst

Location: Remote / Anywhere in the Philippines

Employment Type: Full-Time | Mid-Level | Flexible Shifts (24x7 Coverage)

Industry: Cybersecurity / Managed Security Operations Center (MSOC)

About Us

Graybox Security is a trusted information security, data privacy, and cybersecurity firm dedicated to protecting organizations from evolving digital threats. We offer expert-driven solutions to help businesses safeguard their assets, maintain compliance, and ensure operational resilience. Specializing in cybersecurity consulting and managed security services, we provide advanced capabilities such as Managed Detection and Response (MDR) and Managed Security Operations Center (MSOC) for 24/7 threat monitoring and protection. Founded by industry professionals with decades of experience and leadership in ISO, OWASP, CIS. Graybox Security supports clients from S&P 500 enterprises to SMEs and government agencies with proactive and scalable security solutions.

Why Join Us?

  • Learn from the best: Work alongside and learn from top-tier cybersecurity specialists from a leading expert security firm.
  • Premium Certifications & Training: Gain access to certifications like CompTIA, EC-Council, and exclusive internal cybersecurity programs.
  • Personalized Mentorship: Receive coaching from some of the Philippines' best security professionals.
  • Flexible, People-First Culture: Experience a work environment that supports your career and personal development.
  • Clear Career Progression: Opportunity to advance your career to   Level 3 SOC Analyst, SOC Manager, DFIR Specialist or Security Consultant roles.
  • Cutting-Edge Technology: Work with AI-driven security technologies in a modern MSOC environment.

Role Overview

The L2 SOC Analyst serves as the second line of defense within the Managed Security Operations Center (MSOC), responsible for advanced security event triage, enrichment, containment, and incident investigation, escalation and communication with customers. This role requires deep technical skills and an ability to collaborate closely with L1 and  L3 analysts and customers for incident escalation and response.

Key Responsibilities

  • Incident Triage and Enrichment: Validate alerts, contact users, and enrich the case with Cyber Threat Intelligence (CTI) and host context.
  • Containment Execution: Oversee  immediate host isolation ,, suspend credentials, block Indicators of Compromise (IOCs), and kill malicious processes, manually or leveraging SOAR automation
  • Deep Investigation and Analysis: Conduct full forensic collection, define the scope of the breach, perform Root Cause Analysis (RCA), and map the attack techniques to the MITRE ATT&CK framework. Assist L3 in threat hunting.
  • Eradication and Recovery Guidance: Guide and support the client's IT team in the removal of persistence mechanisms, patching, and service restoration
  • .War-Room Participation: Lead the war-room initiation for high severity incidents as needed.
  • Engagement/Escalation: Engage within a customer IT admins and management , L3 and SOC Manager under the target SLA  time. Document incidents with detailed context for escalation or closure.

Qualifications & Skills

The role requires strong technical skills in specific security domains and a deep understanding of the core security ecosystem

  • Platform Proficiency: Expertise in utilizing the core security ecosystem tools: SIEM/XDR, log aggregation, and extended detection, Incident Response , workflow management  and case management systems, Endpoint Detection and Response (EDR), deep forensic collection, and real-time host isolation, automated threat intelligence feeds and event enrichment, SOAR Automation: For executing automated playbooks and response actions
  • Forensics and Investigation: Demonstrated ability to perform full forensic collection, build attack timelines, and determine the Root Cause Analysis (RCA)
  • Threat Knowledge: Understanding of the MITRE ATT&CK framework for mapping and classifying adversarial tactics, techniques, and procedures (TTPs)
  • Containment Expertise: Practical skill in executing containment actions such as host isolation, account disabling, and IOC blocking (via FW/WAF/DNS)
  • Incident Response Lifecycle: Comprehensive knowledge of the end-to-end incident lifecycle (triage- contain- eradicate- recovery)
  • Communication and Management: Ability to work flexible shifts supporting 24x7 operations and under pressure, coordinating multiple internal and external  stakeholders


  • Manila, National Capital Region, Philippines CyberMaxx Full time ₱960,000 - ₱1,440,000 per year

    CyberMaxx is looking to add a Security Operations Center (SOC) Analyst to its top-tier team. The SOC Analyst works as part of a 24/7 operational team to perform first-level analysis and triage on incoming network, EDR, and SIEM alerts. The position works closely with the SOC Manager and shift leaders to prevent, detect, and respond to cyberattacks. THIS...

  • Junior SOC Analyst

    3 hours ago


    Manila, National Capital Region, Philippines Kinettix Full time ₱200,000 - ₱250,000 per year

    Job Summary:Junior SOC (Security Operations Center) or SOC analyst tier 1 will monitoring and analyzing security threats to protect an organization's IT infrastructure. Also SOC Analyst I will assist IT Security Specialist for auditing, process improvement and security reports.Job Responsibilities:Identify, assess, and mitigate security threats in real-time....

  • L1 SOC Analyst

    5 hours ago


    Manila, National Capital Region, Philippines Graybox Security Full time ₱300,000 - ₱600,000 per year

    Location: Remote / Anywhere in the PhilippinesEmployment Type: Full-Time | Entry-Level | Flexible Shifts (24x7 Coverage)Industry: Cybersecurity / Managed Security Operations Center (MSOC)About UsGraybox Security is a trusted information security, data privacy, and cybersecurity firm dedicated to protecting organizations from evolving digital threats. We...

  • Senior SOC Analyst

    5 hours ago


    Manila, National Capital Region, Philippines hktservice Full time ₱1,200,000 - ₱1,500,000 per year

    Job TitleSenior Security Operations Center (SOC) AnalystJob DescriptionThe role of this job sits within the security operations department, which is responsible for handling security incidents and supports both the organization and the customer base. Additionally, this role includes supervisor responsibilities for the regional team in Philippines.Duties and...

  • SOC Analyst

    2 weeks ago


    Manila, National Capital Region, Philippines Ciena Full time ₱80,000 - ₱120,000 per year

    As the global leader in high-speed connectivity, Ciena is committed to a people-first approach. Our teams enjoy a culture focused on prioritizing a flexible work environment that empowers individual growth, well-being, and belonging. We're a technology company that leads with our humanity—driving our business priorities alongside meaningful social,...

  • SOC Analyst

    2 weeks ago


    Manila, National Capital Region, Philippines Ciena Full time $60,000 - $120,000 per year

    As the global leader in high-speed connectivity, Ciena is committed to a people-first approach. Our teams enjoy a culture focused on prioritizing a flexible work environment that empowers individual growth, well-being, and belonging. We're a technology company that leads with our humanity—driving our business priorities alongside meaningful social,...

  • SOC Analyst

    4 hours ago


    Manila, National Capital Region, Philippines Vurke Inc. (Pvt) Ltd. Full time ₱600,000 - ₱1,200,000 per year

    Role summaryMonitor, triage, and investigate security alerts. Execute playbooks, reduce false positives, and escalate incidents.Key responsibilitiesMonitor SIEM alerts and triage events per SOPs and SLAsPerform basic threat hunting and tune detections with the senior teamCollect and preserve logs, artifacts, and evidence for investigationsCreate tickets,...


  • Manila, National Capital Region, Philippines UBX Full time ₱1,200,000 - ₱2,400,000 per year

    The SOC Analyst is responsible for monitoring, detecting and responding to security incidents. They will provide cybersecurity incident response support.Responsibilities:L1 to L3 Cybersecurity Incident Response SupportOn-call Incident Response support for Medium to Critical IncidentsDaily Cybersecurity Ticket ManagementDaily Cybersecurity Incident...


  • Manila, National Capital Region, Philippines Melco Resorts & Entertainment Full time ₱1,200,000 - ₱2,400,000 per year

    REQ12454 Senior Analyst, Cyber Security Operations (Open)Position SummaryThe Senior Analyst, Cyber Security Operations acts as a critical escalation point within the Cyber Security Operations Center (CSOC) team. He/she is responsible for advanced analysis, incident handling, and in-depth investigations of security events. The analyst serves as a mentor to...


  • Manila, National Capital Region, Philippines Intelligent Technical Solutions Full time ₱680,320 per year

    Job Description:As a SOC Analyst Level 1at Intelligent Technical Solutions, you will be the first line of defense in monitoring, analyzing, and responding to security threats. This position requires a hands-on approach to security operations, incident response, and threat detection. You will work closely with SOC leadership to ensure that security events...