ScalableOS is a premium offshoring solutions provider based in the Philippines.
Cybersecurity Analyst
Location
Philippines
Posted
15 days ago
Salary
0
Seniority
Mid Level
Job Description
Cybersecurity Analyst
ScalableOS
Role Description The Cybersecurity Analyst is a frontline operational role responsible for monitoring, investigating, and responding to security alerts and incidents across the organization’s security tool stack, with a primary focus on Cisco Secure Workload, Cisco Secure Endpoint, and Cisco Umbrella. This position is centered on alert triage, investigation, and execution of incident response activities, leveraging established detections, playbooks, and procedures to identify threats, assess impact, and drive timely remediation. - Monitor, analyze, and respond to security events and incidents utilizing Cisco Secure Workload, Cisco Secure Endpoint, and Cisco Umbrella. - Conduct thorough investigations of security alerts to identify root causes, assess impact, and coordinate effective remediation. - Leverage Cisco Secure Workload (CSW), Cisco Secure Endpoint (CSE), and Cisco Umbrella to enforce network, endpoint, and DNS-layer security controls and mitigate threats. - Perform detailed investigation of security alerts, correlate events across multiple sources, and drive timely incident response. - Collaborate with cross-functional teams (IT, Network, and Application owners) to identify and remediate security risks and vulnerabilities. - Develop and maintain incident response documentation, procedures, and runbooks. - Contribute to the continuous improvement of security monitoring, detection, and response capabilities. - Stay abreast of evolving cyber threats, tactics, techniques, and procedures (TTPs), and emerging industry trends. Qualifications - Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent experience). - Minimum of 5+ years of hands-on experience in cybersecurity operations, preferably within a Security Operations Center (SOC). - Demonstrated expertise with Cisco security technologies, specifically: - Cisco Secure Workload (CSW) - Cisco Secure Endpoint (CSE) - Cisco Umbrella - Strong knowledge of endpoint security, workload security, network security, and threat detection methodologies. - Solid understanding of networking protocols, DNS, and security architecture principles. - Preferred Qualifications - Experience with CrowdStrike Falcon platform for endpoint detection and response. - Proficiency in ServiceNow (SNOW) for incident, problem, and change management. - Relevant industry certifications such as CyberOps, Security+, CySA+, GCIH, CCNA or equivalent. - Experience integrating security tools with SIEM platforms and ticketing systems. Requirements - Should be willing to accept a long-term work-from-home arrangement. - Should be amenable to a permanent night shift schedule.
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
Junior Security Analyst
PartnerOneWe are the leaders in Big Data management through hyper-automation, virtualized cloud tiering, metadata and AI
• Partner One is a leading investment group with a 30-year history of acquiring and growing successful software companies. • Proactive and detail-oriented Junior Security Analyst for our fast-paced security team. • First line of defense across diverse and evolving landscapes of internal environments. • Responsible for triaging alerts, maintaining security posture, and ensuring software resilience. • Ideal for someone thriving on variety and wanting deep, hands-on experience across multiple infrastructures.
Level 2 Cyber Security Analyst
Lyra Technology GroupThe trusted leader in IT services for small and medium-sized organizations.
Role Description Lyra Technology Group is looking for L2 Cyber Security Analyst for one of their operating companies, VirtualArmour. The primary role of our L2 Cyber Security Analyst is to work with customers for our Managed Security Services (MSS) department. The Cyber Security Analyst’s role will help protect our customer networks against cybersecurity threats such as hackers, cyber-terrorists and malware that can steal or corrupt sensitive customer data. This role will be monitoring and analyzing customer networks, servers, databases, and end-point equipment for key indicators of compromise. Once a possible threat is detected, the analyst must investigate, respond to, and report to our customers with any recommended remediation. Cyber Analysts should have the experience and knowledge desired below and will also be enrolled in the VirtualArmour Academy, where students will be trained in other aspects of the role. Your work as the Level 2 - Cyber Security Analyst includes several components: - Monitor and triage security alerts from EDR/XDR, SIEM, and related security tooling; prioritize incidents based on risk and business impact. - Investigate endpoint threats (malware, ransomware, credential theft, persistence, lateral movement) using Microsoft Defender for Endpoint (MDE), CrowdStrike EDR, SentinelOne EDR, and Stellar Cyber XDR. - Perform incident response activities: evidence collection, scoping, containment, eradication, recovery, and post-incident reporting. - Conduct endpoint and host-based analysis (process trees, command-line execution, registry changes, scheduled tasks, persistence mechanisms, network connections). - Correlate telemetry across endpoint, identity, network, and cloud sources to confirm malicious activity and reduce false positives. - Execute response actions (e.g., isolate host, kill/quarantine process, block indicators, remove persistence, enforce policy changes) in accordance with playbooks and approvals. - Develop and maintain detection and response playbooks/runbooks for common attack scenarios (phishing, suspicious PowerShell, credential dumping, suspicious service creation, etc.). - Create and tune alerting rules, exclusions, and detections to improve signal quality and reduce noise while maintaining security coverage. - Document investigations thoroughly: timelines, IOCs, impacted assets/users, actions taken, and recommendations for prevention. - Support threat hunting activities using EDR/XDR telemetry and threat intelligence to identify suspicious patterns and proactively reduce risk. - Participate in on-call rotation and shift-based SOC coverage as required. - Research security enhancements and make recommendations for management. - Stay up to date on information technology trends and security standards. - Train, mentor, and guide teammates through direct comms and by hosting knowledge transfer calls. Qualifications - 2–4 years of experience in a SOC, incident response, cyber analyst or security operations role. - 2–4 years of hands-on experience working with at least one (1) of the following: - Microsoft Defender for Endpoint (MDE) - CrowdStrike EDR - SentinelOne EDR - Stellar Cyber XDR - Strong knowledge of attacker tactics and techniques aligned to MITRE ATT&CK, NIST, Lockhead Martin (e.g., persistence, privilege escalation, lateral movement, exfiltration). - Solid understanding of Windows security fundamentals (event logs, authentication, common persistence locations) and basic Linux/macOS concepts. - Familiarity with common security log sources and workflows (SIEM concepts, ticketing/case management, escalation processes). - Ability to write clear incident documentation and communicate findings to both technical and non-technical stakeholders. - Experience handling sensitive information and following documented procedures and change controls. - Strong knowledge of the Windows and Linux operating systems. - Ability to establish and maintain a strong level of customer trust and confidence. Preferred Qualifications - Experience with Microsoft security ecosystem (e.g., Defender for Identity, Defender for Cloud, Entra ID/Azure AD sign-in logs). - Basic scripting/automation skills (PowerShell, Python, or Bash) for investigation and enrichment tasks. - Familiarity with network security concepts, protocols (TCP/UDP, DNS, HTTP/S, TLS, proxies, VPNs), and packet/log analysis. - Threat hunting experience and building detections based on behavioral analytics. - Experience with vulnerability management and remediation tracking. - MSSP experience. - A bachelor’s/master's degree in cyber security or related field, or equivalent level of experience within IT. - Security certifications (nice-to-have): Security+, CySA+, GCIH, GCIA, SC-200, or equivalent. Benefits - The target salary for this role is $100,000 per year. - This position will operate in a fully remote model.
Security Analyst
Placer.aiPlacer.ai, also known as Placer Labs, Inc., helps provide retailers with actionable analytics and insights into their competition and their audience. The compan
Role Description We are seeking a detail-oriented, self-driven Security Analyst, based in Israel, to join the Risk and Compliance team and operate Placer’s ISO-aligned Event Management Process end-to-end. This role is the front door for security events at Placer — the person who makes sure that every reported security event (from employees, vendors, and automated monitoring) is triaged, classified, escalated where required, and closed with documented evidence. The Security Analyst is both an operator and a process owner. This is an excellent entry-point role for a Computer Science graduate or similar background person looking to build a foundation in security operations and compliance. You will run the daily flow of events, partner with Corporate IT, R&D/DevOps, and the CISO to drive down events, implement improvements and take corrective and preventive actions. You will report directly to the Chief Information Security Officer and work closely with the broader employee base engaging them directly. This role covers five primary pillars: - Security Event Intake and Triage - Classification, Escalation and Coordination - Process Operations and Continuous Improvement - AI Automation This is a temporary position with an hourly pay. Responsibilities - Own the front door for all reported security events — internal security hotline, IT services alerts, employee reports, and automated monitoring. - Triage security events within defined SLAs; gather context from logs, endpoints, identity systems, and SaaS admin telemetry. - Maintain the Security Event Register as the single source of truth for every reported event — timeline, evidence, classification, owner, status, root cause, and corrective actions. - Review mail service admin holds that require review and investigation, user engagement, and follow-up. - Classify security events against the defined severity matrix; distinguish security events from incidents and apply the agreed escalation criteria consistently. - Notify the CISO when escalation criteria are met, evidence collection, and timeline capture during incidents. - Own and operate Placer’s ISO-aligned Event Management Process end-to-end. - Maintain the Security Event Management Process documentation (playbook). - Coordinate with the CISO on security event detail enrichment, false positive reduction, detection rule tuning, and playbook updates. - Continuously raise the bar on the process — automate intake, reduce mean time to triage and closure, and remove repeat security events. - Design and implement automation/AI enhancements to reporting and security event handling. - Assist the broader Risk and Compliance team with audits, control reviews, and reporting on standardization of systems security, applications. - Respond to security event escalations in a timely manner. - Prioritize responsibilities as they evolve on a day-to-day basis, and escalate appropriately. Qualifications - Computer science graduate or equivalent. - Hands-on experience in a fast-paced SaaS, cloud, or AI-first technology company is beneficial. - Demonstrated ability to apply theoretical CS concepts and logical process-driven thinking to real-world security and operations challenges. - Strong computer and SaaS services experience – business productivity tools. - AI basics or more would be of benefit. - Similar experience would be of significant value. Requirements - Working knowledge of Mac and Windows endpoints, and related security events end-to-end. - Familiarity with ticketing/case management tools (e.g., Jira) and comfort with structured data management. - Highly committed, ownership-driven, and self-motivated. - Excellent written English communication. - Strong cross-functional partner — comfortable working across Corporate IT, R&D/DevOps, Legal, and HR. - Customer-oriented mindset toward internal reporters. - Comfortable operating across U.S. and Israel time zones in a globally distributed company. Benefits - Join a rocketship! We are pioneers of a new market that we are creating. - Take a central and critical role at Placer.ai. - Work with, and learn from, top-notch talent. - Competitive salary. - Excellent benefits.
Associate Cyber Security Analyst
ICFFounded in 1969, ICF is a global advisory and technology services company headquartered in Reston, Virginia. It delivers data-driven solutions across energy, environment, infrastru
Role Description This is an entry-level position expected to begin Summer 2026, and is fully-remote from any U.S. location. Travel 1-2 times per year may be required. This is a non-exempt position. The Associate Cyber Security Analyst supports the day‑to‑day operation of ICF’s information security program under the guidance of senior security staff and the Cyber Security Manager. This role assists with monitoring, maintaining, and documenting security controls and technologies, including: - Endpoint protection - Access controls - Vulnerability management - Security event monitoring Working closely with experienced analysts and internal stakeholders, the Associate Cyber Security Analyst helps: - Identify, document, and escalate security issues - Support routine security operations - Contribute to security assessments and reporting The role provides hands‑on exposure to and guidance with: - Incident response - Compliance activities - Security tooling Performance Objectives: - Detail‑oriented with a strong analytical mindset and a willingness to learn - Ability to clearly document work and communicate effectively in writing and verbally - Collaborate with technical and business stakeholders to support vulnerability remediation and security event response - Learn, follow, and document common security processes under guidance from senior team members - Assist with security request and incident ticket intake, triage, and escalation - Support the collection and creation of artifacts for audit and compliance activities - Analyze security log data to identify emerging or unusual patterns - Review and help validate vulnerability findings using established processes - Assist with the operation of infrastructure and application vulnerability scanning tools - Research and test emerging threats, vulnerabilities, and security techniques - Working knowledge of Windows, macOS, and/or Linux operating systems - Foundational understanding of networking concepts, including the OSI model, TCP/IP, routing, and switching - Familiarity with scripting or query languages such as PowerShell, Python, Java, or SQL - Assist in modifying or proposing security alerts for events of interest - Participate in on‑call rotations as part of a team, with guidance and escalation support - Assist with disaster recovery and incident response testing and exercises Qualifications - Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field or equivalent practical experience Requirements - 1–2 years of general technology experience (including internships, academic projects, or relevant hands‑on work) - Foundational knowledge of information security principles, common security practices, and log monitoring/analysis concepts - Familiarity with cloud platforms (Azure and/or AWS) and common security tools through coursework, labs, or hands‑on experience (e.g., vulnerability scanners, network analysis tools, penetration testing frameworks) - Exposure to security monitoring and incident response fundamentals, including network traffic analysis - Basic scripting or automation experience (e.g., simple scripts or academic projects) - Awareness of emerging technologies, including the use of generative or agentic AI in security contexts - Strong interest in learning and developing cybersecurity skills - Ability to manage multiple tasks, adapt to changing priorities, and operate effectively in time‑sensitive situations - Demonstrated professionalism and discretion in handling sensitive information - Flexibility to support extended hours or incident response activities, as needed - Entry‑level cybersecurity certifications (e.g., CompTIA Security+ or equivalent) a plus Benefits - Reasonable Accommodations are available, including, but not limited to, for disabled veterans, individuals with disabilities, and individuals with sincerely held religious beliefs, in all phases of the application and employment process. - Pay Range: $61,232.00 - $104,094.00 based on full-time employment.




