SOC Analyst – Splunk ES
1 week ago
Pasay Metro Manila, 00, Philippines
Outsourcea Services Incorporated
Remote
Full-time
Free with email or Google
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
Free with email or Google
About the role
We are seeking an experienced SOC Analyst to join our Cybersecurity team and support security monitoring, threat detection, and incident response activities. The ideal candidate has strong hands-on experience with Splunk Enterprise Security (ES) and advanced SPL query development, along with practical experience investigating security incidents across endpoint and email security platforms. You will play an important role in identifying and responding to potential threats, improving security detections, and helping maintain a strong security posture for our clients.
Key responsibilities
- Monitor and investigate security alerts, events, and potential threats within the SOC.
- Perform alert triage, incident investigation, containment, escalation, and follow-up.
- Create and optimize advanced Splunk SPL queries for threat detection and investigation.
- Develop and maintain correlation searches, dashboards, and other Splunk-based security content.
- Review and tune detection rules to improve alert quality and minimize false positives.
- Investigate security incidents involving endpoints and email using CrowdStrike Falcon and Proofpoint TAP/TRAP or comparable platforms.
- Conduct security event analysis and identify indicators of compromise and potential threats.
- Support threat hunting and proactive detection activities.
- Maintain accurate documentation of incidents, investigations, findings, and remediation actions.
- Work closely with Security Engineers, IT teams, and clients during investigations and response activities. About you
- 3–5 years of experience in cybersecurity, with at least 2 years of hands-on SOC experience.
- Strong practical experience in security monitoring, incident response, alert triage, and threat detection.
- Advanced experience using Splunk Enterprise Security (ES) and/or Splunk Core.
- Strong ability to write and troubleshoot complex SPL queries.
- Hands-on experience with CrowdStrike Falcon.
- Experience with Proofpoint TAP/TRAP or similar email security solutions.
- Good understanding of SIEM, endpoint security, threat detection, and incident response processes.
- Familiarity with MITRE ATT&CK and common cybersecurity frameworks and practices.
- Strong analytical and problem-solving skills.
- Good written and verbal communication skills.