SIEM/SOAR Engineer_Hybrid
# SIEM/SOAR Engineer_Hybrid **GSS PH** · Quezon City · `On-site` 🕒 **Статус:** *Опубликовано: 6 дней назад* · *Источник: Indeed* --- ### About the Role Job Overview We are looking for a skilled SIEM/SOAR Engineer to design, implement, and optimize security monitoring platforms and automated incident response solutions. The successful candidate will help strengthen security operations by improving threat detection, developing automation workflows, and integrating security tools across enterprise environments. If you have hands-on experience with SIEM platforms, security automation, and incident response, this opportunity may be for you! Key Responsibilities: SIEM Engineering - Design, configure, maintain, and optimize SIEM platforms such as Google SecOps, Splunk, Microsoft Sentinel, IBM QRadar, ArcSight, or Elastic. - Develop and enhance correlation rules, dashboards, alerts, and reports to improve threat detection and visibility. - Integrate security logs and data from networks, endpoints, cloud environments, and applications. - Improve log parsing, normalization, and data quality to support accurate security monitoring and detection. SOAR and Security Automation: - Develop, implement, and maintain automated security workflows using platforms such as Cortex XSOAR, Splunk SOAR, IBM Resilient, or Google SecOps SOAR. - Build and maintain playbooks for alert triage, incident response, and threat intelligence enrichment. - Automate repetitive Security Operations Center (SOC) tasks and integrate security tools to improve operational efficiency. Security Operations Support: - Support incident response through effective threat detection, alert investigation, and automated response workflows. - Analyze recurring security issues and implement engineering improvements to prevent future incidents. - Collaborate with IT, compliance, and audit teams to strengthen security controls and operational processes. Qualifications and Requirements - At least 3 years of experience in SIEM and/or SOAR engineering or administration . - Experience working in a Security Operations Center (SOC) environment is an advantage. - Hands-on experience with at least one major SIEM platform, such as Google SecOps, Splunk, Microsoft Sentinel, IBM QRadar, ArcSight, or Elastic. - Experience developing SOAR playbooks, automated response workflows, and security tool integrations. - Scripting knowledge in Python, PowerShell, or Bash. - Familiarity with security frameworks and methodologies such as MITRE ATT&CK, NIST, or CIS Controls. - Knowledge of security technologies, including EDR/XDR, IDS/IPS, firewalls, threat intelligence platforms, and cloud security solutions. - Strong analytical, troubleshooting, and problem-solving skills. - Willingness to work on a hybrid setup and accommodate possible shifting schedules. Work Arrangement - Setup: Hybrid - Office Location: Cubao, Quezon City - Schedule: May require shifting schedules Pay: Php100,000.00 - Php150,000.00 per month Work Location: In person
Наблюдалась 2026-10-07, впервые 2026-09-30, источник — Indeed.