AI Jobs Map

Chargeblast · Philippines

Security Operations Engineer (SOC / Incident Response)

entry_levelcontractPosted 9 days ago
Apply on LinkedInLinkedInOpens the original posting. AI Jobs Map never asks for your details.

Stack mentioned

incident-responsesiemapi-designnetwork-securitysplunkawsgcpcisspcrowdstrikedevops

As a Security Operations Engineer at Chargeblast, you will monitor, detect, analyze, and respond to threats and incidents in real time to protect our systems and our merchants’ data. You will tune detections, lead investigations, and build automation that shrinks our response times and, at the senior end, act as Incident Commander for major incidents and shape our detection and threat-hunting strategy.

Daily Duties & Responsibilities

- Monitor SIEM dashboards, tune detection rules to reduce noise, and write custom queries.

- Help Design and Implement SIEM

- Lead investigations for complex incidents, perform root-cause analysis, and keep response playbooks current.

- Proactively threat-hunt for anomalies using hypotheses grounded in the MITRE ATT&CK framework.

- Analyze memory and disk artifacts and reconstruct attack timelines from system logs, preserving chain of custody.

- Build SOAR playbooks and API integrations (firewalls/EDR) to automate response and reduce Mean Time to Respond (MTTR).

- Serve as Incident Commander for major breaches, coordinate with Legal/PR/law enforcement, and architect SIEM ingestion and behavioral-analytics strategy.

Required Qualifications

- 3+ years in a SOC, incident response, or security operations role.

- Hands-on experience with a SIEM (Wazuh, Splunk, Sentinel, Elastic, or similar) including writing custom queries.

- Demonstrated experience leading or co-leading incident investigations and root-cause analysis.

- Working knowledge of the MITRE ATT&CK framework and common attacker techniques.

- Comfort with EDR tooling and safe evidence handling / chain of custody.

Preferred Skills

- Experience building SOAR automations and API integrations across security tooling.

- Threat-hunting experience driven by hypotheses rather than only IoC feeds.

- Cloud security monitoring experience (AWS/GCP) and familiarity with payments environments.

- Ability to mentor junior analysts and improve playbooks over time.

Good to Have (Technical & Certifications)

None of the below are required. They help us place stronger candidates at the Senior Threat Analyst level.

Technical — Good to Have

- Advanced digital forensics: malware reverse-engineering and network packet forensics.

- TryHackMe and HackTheBox Accomplishments

- Experience developing custom threat-hunting methodologies and detecting advanced persistent threats (APTs).

- Designing enterprise-wide security automation strategy to drive down MTTR.

Certifications — Good to Have

- GCIH, GCFA, or GNFA.

- CISSP or GCED.

- Vendor SIEM/EDR certifications (e.g., Splunk, Microsoft Sentinel, CrowdStrike).

Working Conditions

- Full-Remote Work (US Timezone)

- Standard full-time schedule with flexible hours. Security Operations roles participate in a shared on-call rotation for incident response.

- Primarily computer-based work in a fast-paced startup environment. You will collaborate asynchronously across Engineering, DevOps, Legal, and business teams.

More jobs at Chargeblast