SOC Team Lead

6 days ago


Manila, National Capital Region, Philippines Trends Group, Inc. Full time ₱1,200,000 - ₱2,400,000 per year

I. PURPOSEParticipate and support activities that will help improve the existing service operations and operationalize the service portfolio to achieve service excellence, operational efficiency, and retention of customers. II. DUTIES AND RESPONSIBILITIESAccomplish all assigned tasks by the Shift Manager in a timely and effective manner as deemed necessary for the betterment of the organization.Follow effective and efficient processes and comply with escalation protocols. Report significant events to the Shift Manager and participate in shift turnovers.Contribute to the knowledge and information relevant to Service Operations.Collaborate with other team members to improve workflows, documentations, standards, and processes.  Participate in activities promoting a harmonious working environment such as demonstrating trust and respect and practicing open communication.  Comply with company policies, guidelines, standards, and procedures.  Perform all other duties and tasks as assigned by the Shift Manager and MSS Manager.Availability ManagementManage daily shifts and leaves, create operational procedures, and schedule team members' trainings to be taken as compliance to agreed levels of availability of people and processes needed for Service Operations delivery.Monitor daily metrics compliance defined by the management and is accountable for the team's daily operations.Ensure that the tools being used are appropriate for the agreed service level targets for availability such as tools for requesting access and for error/Incident reporting and escalation.Capacity ManagementDetermine and track the capacity and performance of people, processes, and organizational controls, and ensure resolution of issues through operational adjustment of processes, tools, and people.Execute strategies developed by the managers to deliver the service and plans for short, medium, and long-term business requirements.  IT Service Continuity ManagementPerform the role assigned in the Business Continuity Plan (BCP).Lead the team in following and participating in Business Continuity Plan (BCP) activities to ensure continuity of performance of people and processes and that minimum agreed service levels are met in case of a disruptive incident/s. Risk ManagementParticipate in the execution of risk treatment plansto people and processes needed for Service Operations that may impact clients, Sales Groups, and other relevant stakeholders. Service Level ManagementEnsure compliance of Service Level Agreements with clients.Manage the performance of team members in Internal Support Monitor and report on Operational Service Levels. Change Advisory Board  Review Method of Procedures (MOP) to be presented during Managed ICT Services Change Advisory Board meetings.Participate in client Change Advisory Board meetings as needed.Create advisories on the possible impact, risks, and effects of proposed client changes. Provides Method of Procedure/s and other documentation to clients whenever necessary.Configuration ManagementCollects and ensures accurate information of configurations of client assets during Service Operations.Maintains information about Configuration Items (CIs) of client assets as part of Service Operations.Maintains a logical model, containing the components of client CIs and their associations.Handover configuration items and other relevant information to Service Transition for Offboarding.Client Support  Ensure that the team members are:Performing triage received events and incidents.Handling cases assigned to team members.Performing brand monitoring and takedown requests.Processing Service Requests within agreed Service Level Undertaking immediate effort/s to restore a failed service of a Managed Service client as quickly as possible.Handling escalation and follow-ups until resolution.  Create Incident and Root-Cause-Analysis (RCA) Reports. Execute set frameworks, guidelines, and procedures that follow best practices and applicable frameworks for Events Management, Incident Management, and Service Requests.Client Incident Management Create operational playbooks to detect, analyze, eradicate, remediate, and recover from client cybersecurity and quality of service incidents.Lead resolution of Priority-2 escalations.Lead initial triage and resolution of Priority-1 incidents.Escalate incidents that may turn into a problem or disaster.Create RCA Reports and execute Compromise Assessment/Preventive Action (CA/PA).Client Access Management  Ensure team members perform authorization of users' right to access client assets, while preventing access to non-authorized users. Essentially executes Terms and Conditions of the client.Client IT Asset Management  Ensure that clients' managed assets are accounted for, maintained, upgraded if within scope.Monitors the clients' managed assets lifecycle and provides reports and recommendations to the Client, Service Delivery Manager/s, and other relevant stakeholders.Client Problem Management  Provide necessary data and ensure CA/PA is implemented.Ensure team's compliance to contractual problem management deliverables.Process Management  Create, share, use, and manage the documented processes of Service Operations, and ensure that these processes are being followed. Knowledge Management  Responsible in updating the knowledge and information pertaining to existing Clients and clients' Managed ICT assets.Continual Service Improvement Management  Execute improvement plans of the people and processes of Service Operations.Suggest, follow, and deploy new processes, and ensure that the team follows.Review and guarantee quality of data and content of tickets.III. QUALIFICATIONSA.    Minimum EducationMust be a graduate of any IT related bachelor's degree such as:Computer StudiesComputer EngineeringInformation TechnologyElectronics EngineeringB.    Minimum Experience/TrainingHave at least 4 years of working experience in a 24x7x365 Security or Network Operations Center.Trainings and/or certifications on any of the following domains are required:IT Service ManagementIT Infrastructure (Network, Servers, Cloud, etc.)Cybersecurity and/or Information SecurityC.    Competency(F) - Familiar / 0-12 months  (N) - Novice / 1-2 years  (I) - Intermediate / 3-4 years  (A) - Advanced / > 5 years  KNOWLEDGE (I) Knowledge of cybersecurity and privacy principles.  (I) Knowledge of computer networking concepts and protocols, and network security methodologies.  (I) Knowledge of risk management processes (e.g., methods for assessing and mitigating risk).  (I) Knowledge of cyber threats and vulnerabilities.  (I) Knowledge of specific operational impacts of cybersecurity lapses.  (I) Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).  (I) Knowledge of system administration, network, and operating system hardening techniques.  (N) Knowledge of MITRE ATT&CK Framework and NIST SP SKILL (N) Skill in using SIEM (Splunk or McAfee SIEM is a plus) and SOAR (Swimlane or Siemplify is a plus) platforms  (I) Skill of identifying, capturing, containing, and reporting malware.  (I) Skill to design incident response procedures.  (I) Skill to collaborate with different teams and communicate thoughts and ideas.  ABILITY (N) Ability to apply SOAR playbooks and SIEM correlation rules for investigating host and network-based intrusions.  COMMUNICATION SKILLS  (N) Speaks clearly and can be easily understood.  (N) Expresses & speaks ideas in a logical and organized sequence.  (N) Writes clearly, concisely, and effectively.  (N) Expresses ideas in a logical and organized sequence in written form.  IV.  WORKING CONDITIONSReporting to the company's main office in Makati City.Shifting schedule.Collaborate physically and/or virtually with internal and external stakeholders.May travel for company-sponsored conferences and related marketing events.Attend training and acquire certifications that are applicable to the role.


  • SOC Manager

    1 week ago


    Manila, National Capital Region, Philippines HS Hiring Solutions Inc Full time ₱1,200,000 - ₱3,600,000 per year

    Job Summary:The SOC Lead is a senior-level cybersecurity professional responsible for leading and managing the Security Operations Center (SOC).The SOC Lead ensures the effectiveness of threat monitoring, detection, and incident response operations. They lead and coordinate the full lifecycle of Incident Management and Crisis Response, ensuring swift...

  • SOC Analyst

    3 days ago


    Manila, National Capital Region, Philippines Dysrupit Full time ₱900,000 - ₱1,200,000 per year

    JOB DESCRIPTION:As a member of the client's Security Operations Center, the SOC Analyst I provides event analysis and triage, remote support, appliance management and health monitoring to customers.The SOC Analyst will be a part of a Managed Security Services offering which integrates and delivers products as-a-service to our customers. The Security Analyst...

  • SOC Senior Manager

    1 week ago


    Manila, National Capital Region, Philippines HS Hiring Solutions Inc Full time ₱1,500,000 - ₱3,000,000 per year

    Job Summary:Leads the implementation and delivery of Security Services projects, leveraging our global delivery capability (method, tools, training, assets).Required Experience:Minimum 10 years of professional experience in cybersecurity or related fields.At least 2 years in a senior SOC or leadership role.Professional & Technical Skills:In-depth knowledge...

  • Junior SOC Analyst

    2 weeks ago


    Manila, National Capital Region, Philippines Kinettix Full time ₱200,000 - ₱250,000 per year

    Job Summary:Junior SOC (Security Operations Center) or SOC analyst tier 1 will monitoring and analyzing security threats to protect an organization's IT infrastructure. Also SOC Analyst I will assist IT Security Specialist for auditing, process improvement and security reports.Job Responsibilities:Identify, assess, and mitigate security threats in real-time....

  • L1 SOC Analyst

    1 week ago


    Manila, National Capital Region, Philippines Graybox Security Full time ₱300,000 - ₱600,000 per year

    Location: Remote / Anywhere in the PhilippinesEmployment Type: Full-Time | Entry-Level | Flexible Shifts (24x7 Coverage)Industry: Cybersecurity / Managed Security Operations Center (MSOC)About UsGraybox Security is a trusted information security, data privacy, and cybersecurity firm dedicated to protecting organizations from evolving digital threats. We...

  • L2 SOC Analyst

    3 days ago


    Manila, National Capital Region, Philippines Emapta Global Full time ₱60,000 - ₱120,000 per year

    Job Description:As a Level 2 SOC Analyst, you will lead threat detection, investigation, and incident response efforts using tools like Sentinel and Defender. You'll mentor L1 analysts, refine security rules, and contribute to the ongoing evolution of cybersecurity frameworks, making an impact in both day-to-day operations and long-term...


  • Manila, National Capital Region, Philippines Northern Trust Full time $100,000 - $150,000 per year

    About Northern Trust:Northern Trust, a Fortune 500 company, is a globally recognized, award-winning financial institution that has been in continuous operation since 1889.Northern Trust is proud to provide innovative financial services and guidance to the world's most successful individuals, families, and institutions by remaining true to our enduring...


  • Manila, National Capital Region, Philippines Northern Trust Full time $100,000 - $120,000 per year

    About Northern TrustNorthern Trust, a Fortune 500 company, is a globally recognized, award-winning financial institution that has been in continuous operation since 1889.Northern Trust is proud to provide innovative financial services and guidance to the world's most successful individuals, families, and institutions by remaining true to our enduring...

  • SOC Analyst

    1 week ago


    Manila, National Capital Region, Philippines Vurke Inc. (Pvt) Ltd. Full time ₱600,000 - ₱1,200,000 per year

    Role summaryMonitor, triage, and investigate security alerts. Execute playbooks, reduce false positives, and escalate incidents.Key responsibilitiesMonitor SIEM alerts and triage events per SOPs and SLAsPerform basic threat hunting and tune detections with the senior teamCollect and preserve logs, artifacts, and evidence for investigationsCreate tickets,...


  • Manila, National Capital Region, Philippines Northern Trust Full time $100,000 - $150,000 per year

    About Northern Trust:Northern Trust, a Fortune 500 company, is a globally recognized, award-winning financial institution that has been in continuous operation since 1889.Northern Trust is proud to provide innovative financial services and guidance to the world's most successful individuals, families, and institutions by remaining true to our enduring...