Overview
Cyber Security Analyst Jobs in Metro Manila at OttoMate
Title: Cyber Security Analyst
Company: OttoMate
Location: Metro Manila
Cyber Security Analyst
Department: Optimization Engineering & Analytics
Reports To: Director, Global Cyber Operations
Employment Type: Full-Time, Exempt (40+ hours/week)
Work Setup: Remote (until further notice)
Schedule: 11pm – 8am MNL
We are seeking a Cyber Security Analyst to join a global Security Operations team supporting 24×7 managed security services.
In this role, you will monitor, analyze, escalate, and support the remediation of security incidents across enterprise client environments. You will work closely with cross-functional security teams to ensure threats are identified, validated, and resolved in a timely and effective manner.
This position requires strong foundational experience in network security and systems administration, along with hands-on exposure to endpoint security tools, SIEM platforms, incident response processes, and security automation.
- Provide 24×7 SOC support, following established operational frameworks and shift processes
- Monitor, analyze, and triage security alerts from SIEM, endpoint, network, and threat intelligence sources
- Investigate, escalate, and support remediation of security incidents
- Assist in incident response activities and provide technical guidance during active security events
- Support onboarding and integration of endpoint security and attack surface management solutions
- Develop and maintain automation playbooks to improve detection, triage, and response efficiency
- Assist in SIEM tuning, including detection rule creation, optimization, and false-positive reduction
- Collaborate with engineering teams to enhance SOC tooling, automation, and platform integrations
- Perform health checks and optimization of security tools and monitored environments
- Maintain clear and well-documented procedures, runbooks, scripts, and technical documentation
- Identify opportunities for continuous improvement to reduce MTTR and improve SOC efficiency
- Stay current with emerging threats, malware trends, and cybersecurity technologies
Qualifications:
- 4+ years of IT experience
- 3+ years of cybersecurity experience
- Strong knowledge of Windows, Linux, or macOS (at least two operating systems)
- Solid understanding of network protocols (TCP/IP, DNS, HTTP/HTTPS, FTP, SSH, SSL/TLS)
- Experience in security monitoring, incident response, and malware analysis
- Foundational scripting skills (PowerShell, Python, or Bash preferred)
- Ability to analyze logs and security event data from multiple sources
- Strong troubleshooting and analytical skills in security or network environments
- Ability to work independently with minimal supervision
- Strong interest in cybersecurity threats, tools, and emerging attack techniques
- Experience with endpoint security tools (CrowdStrike, Microsoft Defender, SentinelOne, Trellix ePO/ENS/EDR, or similar)
- Experience operating SIEM platforms (Splunk, Microsoft Sentinel, Elastic SIEM, Devo, or similar)
- Experience with SIEM detection engineering and rule tuning
- Exposure to patch management or vulnerability management tools (SCCM, Automox, SolarWinds, GFI LanGuard, etc.)
- Familiarity with MITRE ATT&CK, Cyber Kill Chain, or Diamond Model frameworks
- Industry certifications such as CEH, CISSP, GCIH, GMON, CISA, or similar
- Bachelor’s degree in Computer Science, Engineering, Mathematics, or related field (preferred)
Core Accountabilities:
- Real-Time Threat Monitoring & Triage: Ensure timely detection, validation, and escalation of security alerts
- Incident Response Support: Assist in investigation and remediation of security incidents with structured guidance
- Detection Engineering & Optimization: Improve SIEM rules and reduce noise through tuning and refinement
- SOC Process Excellence: Maintain consistent operational procedures and documentation across shifts
- Continuous Improvement: Drive efficiency gains by reducing MTTR and improving automation coverage
Performance Metrics
- Mean Time to Respond / Resolve (MTTR)
- Percentage of alerts covered by automated playbooks
- False positive rate reduction
- SLA compliance for alert triage and response