Deskripsi Pekerjaan
Are you ready to take ownership of the detection engineering lifecycle at a rapidly growing MSSP? We are seeking a highly skilled Senior Security Analyst, Threat Detection Engineering to join our elite team in Metro Manila. In this critical role, you will be at the forefront of our security operations, responsible for researching emerging threats, building and maintaining advanced YAML detection rules, and tuning for maximum signal-to-noise ratio. Your contributions will directly support SOC excellence and ensure our clients remain protected against evolving cyber threats.
As a Senior Security Analyst, you will leverage your deep expertise in threat detection and analysis to drive continuous improvement of our security monitoring capabilities. You'll collaborate with cross-functional teams to refine detection methodologies, perform in-depth analysis of security incidents, and provide mentorship to junior analysts. This is a unique opportunity to shape the security posture of multiple organizations while working in a dynamic and supportive environment.
We offer a competitive salary package of ₱120,000 – ₱160,000 per month, along with opportunities for professional growth and development. If you are passionate about threat detection and ready to make a significant impact, we encourage you to apply.
Tanggung Jawab
- Own and manage the entire detection engineering lifecycle, from research and development to deployment and tuning.
- Research and analyze current and emerging cyber threats, attack vectors, and TTPs to develop timely detection strategies.
- Design, build, and implement YAML-based detection rules (e.g., Sigma, Splunk, or custom) to identify malicious activities.
- Continuously tune and optimize detection rules to reduce false positives and enhance signal-to-noise ratio.
- Collaborate with SOC analysts to investigate security incidents and provide expert guidance on threat detection.
- Mentor junior security analysts and contribute to the team's knowledge base and best practices.
- Develop and maintain detection documentation, runbooks, and playbooks to support operational excellence.
- Stay abreast of industry trends, tools, and technologies to ensure our detection capabilities remain cutting-edge.
Kualifikasi
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field (or equivalent experience).
- Minimum 5 years of experience in security operations, threat detection, or incident response.
- Proven experience building and managing detection rules using YAML or similar languages (e.g., Sigma, Suricata, YARA).
- Strong understanding of MITRE ATT&CK framework, TTPs, and threat intelligence.
- Hands-on experience with SIEM platforms (e.g., Splunk, Elastic, QRadar) and security analytics.
- Excellent analytical and problem-solving skills with a keen attention to detail.
- Relevant certifications such as CISSP, GCIA, GCIH, or SANS are highly desirable.
- Strong communication skills and ability to work effectively in a team-oriented environment.