L2 SOC Analyst
2 weeks ago
L2 SOC Analyst
Location: Remote / Anywhere in the Philippines
Employment Type: Full-Time | Mid-Level | Flexible Shifts (24x7 Coverage)
Industry: Cybersecurity / Managed Security Operations Center (MSOC)
About Us
Graybox Security is a trusted information security, data privacy, and cybersecurity firm dedicated to protecting organizations from evolving digital threats. We offer expert-driven solutions to help businesses safeguard their assets, maintain compliance, and ensure operational resilience. Specializing in cybersecurity consulting and managed security services, we provide advanced capabilities such as Managed Detection and Response (MDR) and Managed Security Operations Center (MSOC) for 24/7 threat monitoring and protection. Founded by industry professionals with decades of experience and leadership in ISO, OWASP, CIS. Graybox Security supports clients from S&P 500 enterprises to SMEs and government agencies with proactive and scalable security solutions.
Why Join Us?
- Learn from the best: Work alongside and learn from top-tier cybersecurity specialists from a leading expert security firm.
- Premium Certifications & Training: Gain access to certifications like CompTIA, EC-Council, and exclusive internal cybersecurity programs.
- Personalized Mentorship: Receive coaching from some of the Philippines' best security professionals.
- Flexible, People-First Culture: Experience a work environment that supports your career and personal development.
- Clear Career Progression: Opportunity to advance your career to Level 3 SOC Analyst, SOC Manager, DFIR Specialist or Security Consultant roles.
- Cutting-Edge Technology: Work with AI-driven security technologies in a modern MSOC environment.
Role Overview
The L2 SOC Analyst serves as the second line of defense within the Managed Security Operations Center (MSOC), responsible for advanced security event triage, enrichment, containment, and incident investigation, escalation and communication with customers. This role requires deep technical skills and an ability to collaborate closely with L1 and L3 analysts and customers for incident escalation and response.
Key Responsibilities
- Incident Triage and Enrichment: Validate alerts, contact users, and enrich the case with Cyber Threat Intelligence (CTI) and host context.
- Containment Execution: Oversee immediate host isolation ,, suspend credentials, block Indicators of Compromise (IOCs), and kill malicious processes, manually or leveraging SOAR automation
- Deep Investigation and Analysis: Conduct full forensic collection, define the scope of the breach, perform Root Cause Analysis (RCA), and map the attack techniques to the MITRE ATT&CK framework. Assist L3 in threat hunting.
- Eradication and Recovery Guidance: Guide and support the client's IT team in the removal of persistence mechanisms, patching, and service restoration
- .War-Room Participation: Lead the war-room initiation for high severity incidents as needed.
- Engagement/Escalation: Engage within a customer IT admins and management , L3 and SOC Manager under the target SLA time. Document incidents with detailed context for escalation or closure.
Qualifications & Skills
The role requires strong technical skills in specific security domains and a deep understanding of the core security ecosystem
- Platform Proficiency: Expertise in utilizing the core security ecosystem tools: SIEM/XDR, log aggregation, and extended detection, Incident Response , workflow management and case management systems, Endpoint Detection and Response (EDR), deep forensic collection, and real-time host isolation, automated threat intelligence feeds and event enrichment, SOAR Automation: For executing automated playbooks and response actions
- Forensics and Investigation: Demonstrated ability to perform full forensic collection, build attack timelines, and determine the Root Cause Analysis (RCA)
- Threat Knowledge: Understanding of the MITRE ATT&CK framework for mapping and classifying adversarial tactics, techniques, and procedures (TTPs)
- Containment Expertise: Practical skill in executing containment actions such as host isolation, account disabling, and IOC blocking (via FW/WAF/DNS)
- Incident Response Lifecycle: Comprehensive knowledge of the end-to-end incident lifecycle (triage- contain- eradicate- recovery)
- Communication and Management: Ability to work flexible shifts supporting 24x7 operations and under pressure, coordinating multiple internal and external stakeholders
-
SOC Frontline Analyst
2 weeks ago
Manila, National Capital Region, Philippines POWER IT SERVICES Full timeSummary:Monitor and triage cybersecurity alerts for Teleperformance's enterprise security clients.Responsibilities:• Analyze SIEM alerts (Splunk, QRadar, Sentinel)• Perform initial threat validation• Escalate potential incidents to L2 analysts• Document findings in incident reports• Follow SOC playbooks consistentlyRequirements:• 2 years SOC,...
-
L2 SOC Analyst
2 weeks ago
Manila, National Capital Region, Philippines Emapta Global Full timeJob Description:As a Level 2 SOC Analyst, you will lead threat detection, investigation, and incident response efforts using tools like Sentinel and Defender. You'll mentor L1 analysts, refine security rules, and contribute to the ongoing evolution of cybersecurity frameworks, making an impact in both day-to-day operations and long-term...
-
SOC Analyst- Philippines
2 weeks ago
Manila, National Capital Region, Philippines CyberMaxx Full timeCyberMaxx is looking to add a Security Operations Center (SOC) Analyst to its top-tier team. The SOC Analyst works as part of a 24/7 operational team to perform first-level analysis and triage on incoming network, EDR, and SIEM alerts. The position works closely with the SOC Manager and shift leaders to prevent, detect, and respond to cyberattacks. THIS...
-
Junior SOC Analyst
2 weeks ago
Manila, National Capital Region, Philippines Kinettix Full timeJob Summary:Junior SOC (Security Operations Center) or SOC analyst tier 1 will monitoring and analyzing security threats to protect an organization's IT infrastructure. Also SOC Analyst I will assist IT Security Specialist for auditing, process improvement and security reports.Job Responsibilities:Identify, assess, and mitigate security threats in real-time....
-
Manila, National Capital Region, Philippines Emapta Global Full timeAutomate. Detect. Defend.Take cybersecurity to the next level. Use your Sentinel and Defender expertise to sharpen detection rules, automate playbooks, and lead investigations that keep global businesses secure. This is your chance to grow your SOC career while enjoying balance and purpose in your every day.Be at the Core of Cyber DefenseBe part of our...
-
SOC analyst
5 days ago
Manila, National Capital Region, Philippines CommandLink Full timeJob Description*About Command|Link*Command|Link is a global SaaS Platform providing network, voice services, and IT security solutions, helping corporations consolidate their core infrastructure into a single vendor and layering on a proprietary single pane of glass platform. Command|Link has revolutionized the IT industry by tackling the problems our...
-
L1 SOC Analyst
2 weeks ago
Manila, National Capital Region, Philippines Graybox Security Full timeLocation: Remote / Anywhere in the PhilippinesEmployment Type: Full-Time | Entry-Level | Flexible Shifts (24x7 Coverage)Industry: Cybersecurity / Managed Security Operations Center (MSOC)About UsGraybox Security is a trusted information security, data privacy, and cybersecurity firm dedicated to protecting organizations from evolving digital threats. We...
-
Senior SOC Analyst
2 weeks ago
Manila, National Capital Region, Philippines hktservice Full timeJob TitleSenior Security Operations Center (SOC) AnalystJob DescriptionThe role of this job sits within the security operations department, which is responsible for handling security incidents and supports both the organization and the customer base. Additionally, this role includes supervisor responsibilities for the regional team in Philippines.Duties and...
-
SOC Analyst
2 weeks ago
Manila, National Capital Region, Philippines Cato Networks Full timeWelcome to the future of cloud networking and security Cato Networks is the first company to converge enterprise networking and security into one centralized and global service that is delivered by cloud. It is led by networking and security pioneer Shlomo Kramer (Check Point, Imperva) and early investor (Palo Alto Networks, Exabeem, Trusteer and more). ...
-
SOC Analyst
1 week ago
Manila, National Capital Region, Philippines Cato Networks Full timeWelcome to the future of cloud networking and securityCato Networks is the first company to converge enterprise networking and security into one centralized and global service that is delivered by cloud. It is led by networking and security pioneer Shlomo Kramer (Check Point, Imperva) and early investor (Palo Alto Networks, Exabeem, Trusteer and more)....